What Is the NIS2 Directive? EU Cybersecurity Legislation, Explained

Connected globe illustrating OT security across industrial networks

The NIS2 Directive (Network and Information Security Directive 2) is the European Union’s primary cybersecurity legislation. It came into force on 16 January 2023 and required transposition into national law by 17 October 2024.

For many organisations across Europe, NIS2 represents the most significant mandatory cybersecurity obligation of the past decade. It is broader in scope, stricter in requirements, and more personal in accountability than anything that preceded it.

NIS2 sets binding cybersecurity and incident reporting requirements for organisations operating in critical and important sectors across EU member states, replacing the original NIS Directive of 2016.

What is the purpose of NIS2?

The original NIS Directive established a baseline for network and information security across the EU. In practice, its implementation was fragmented. Member states transposed it differently, thresholds for who counted as an operator of essential services varied, and enforcement was inconsistent.

NIS2 was introduced to address those gaps directly. Its core objectives are to:

  • Establish a high common level of cybersecurity across the EU.
  • Harmonise requirements so that organisations operating in multiple member states face consistent obligations.
  • Broaden the scope of regulated entities significantly beyond the original directive.
  • Impose personal accountability on senior management for cybersecurity failures.

The European Union Agency for Cybersecurity (ENISA) plays a central role in supporting implementation and coordinating cross-border incident response under NIS2.

Alongside NIS2 sits a wider legislative architecture. The Digital Operational Resilience Act (DORA) governs digital operational resilience in the financial sector. The Cyber Resilience Act governs product security for connected devices. The Critical Entities Resilience Directive addresses physical infrastructure. NIS2 is the horizontal framework across which these more targeted instruments operate.

Who does NIS2 apply to? 

NIS2 significantly expanded the number of organisations in scope. Where the original directive covered seven high-criticality sectors, NIS2 covers 18. Estimates from the EU suggest that more than 150,000 organisations across Europe fall within scope, compared to a fraction of that under NIS1.
The directive divides in-scope organisations into two categories, each with different supervisory regimes and penalty exposure.

Essential entities

Essential entities are larger organisations in the highest-criticality sectors:


  • Energy
  • Transport
  • Banking
  • Financial market infrastructure
  • Health
  • Drinking water
  • Wastewater
  • Digital infrastructure
  • ICT service management
  • Public administration
  • Space 


They are subject to proactive supervision, meaning regulators can audit and inspect them without waiting for an incident to occur. Non-compliance penalties for essential entities can reach €10 million or 2% of global annual turnover, whichever is higher.

One important note on financial entities: DORA is lex specialis for banks, payment institutions, insurance firms, and their ICT providers. Where both NIS2 and DORA apply, DORA’s requirements generally take precedence for those organisations.

Important entities

Important entities are organisations in additional critical sectors:

  • Postal and courier services
  • Waste management
  • Chemicals
  • Food production
  • Manufacturing of certain products (medical devices, electronics, machinery)
  • Digital providers
  • Research institutions

They face reactive rather than proactive supervision, meaning regulators act in response to incidents or complaints rather than conducting routine audits. Penalties for important entities reach €7 million or 1.4% of global annual turnover.

Supply chain and ICT providers

Even organisations not directly classified as essential or important may be affected if they supply services or technology to in-scope entities. NIS2 explicitly strengthens third-party risk requirements, and essential and important entities must now manage the cybersecurity of their suppliers as part of their compliance obligations.

ICT vendors, software providers, and managed service providers are frequently in scope as a result.

Size matters for scope determination. The general threshold is medium-sized enterprises and above: 50 or more employees, or €10 million or more in annual turnover. Smaller organisations may still be captured if they operate in specific high-criticality sub-sectors, particularly in energy, digital infrastructure, or public administration.
Member states set final thresholds in their national legislation.
The attack surface has expanded significantly, and a breach in IT may become a pathway into OT if they are not properly segmented or adequately controlled.

Key differences between NIS1 and NIS2

The NIS2 update is structural:

Scope

NIS1 covered 7 sectors. NIS2 covers 18, adding manufacturing, food production, postal services, waste management, chemicals, research, and several others. The estimated number of in-scope organisations increased by more than 100,000 across the EU.

Security requirements

NIS1 required proportionate security measures. NIS2 specifies minimum mandatory measures, including multi-factor authentication, encryption, supply chain security assessments, and business continuity planning. Proportionality still applies, but within a defined floor.

Incident reporting

NIS1 required incident notification to authorities ‘without undue delay’. NIS2 specifies a 24-hour early warning to the national CSIRT (Computer Security Incident Response Team), followed by a full incident notification within 72 hours, and a final report within one month.

Management accountability

NIS2 introduces personal liability for senior management. Executives who fail to comply with cybersecurity obligations or approve inadequate security measures can face individual sanctions, including temporary removal from their positions.

Enforcement and penalties

NIS1 left enforcement to member states, resulting in inconsistency. NIS2 mandates minimum penalty levels and requires national authorities to actively supervise essential entities.

Supply chain

NIS1 was largely silent on supply chain risk. NIS2 requires organisations to assess and manage the cybersecurity of their suppliers and service providers as part of their risk management measures.

Core requirements of the NIS2 Directive

NIS2 requires organisations to implement a risk-based approach to cybersecurity. The measures required must be proportionate to risk and the size of the organisation, but the following areas are explicitly mandated under Article 21 of the Directive (EU) 2022/2555:

Risk analysis and information system security

Organisations must document and maintain a cybersecurity risk management policy covering their networks and information systems. This includes identifying assets, assessing vulnerabilities, and implementing controls appropriate to the identified risk level.

Incident handling and reporting

Organisations must have documented procedures for detecting, classifying, and responding to security incidents. The reporting timeline under NIS2 is specific:

  • 24-hour early warning to the national CSIRT where the incident is suspected to be significant.
  • Full notification within 72 hours confirming the incident classification and initial assessment.
  • Final report within one month detailing root cause, impact, and remediation.

Business continuity and crisis management

Organisations must maintain plans covering backup management, disaster recovery, and crisis management. The objective is the continuity of essential services during and after a cybersecurity incident.

Supply chain security

Organisations must assess the security practices of their direct suppliers and service providers, taking into account the quality of the products and cybersecurity practices of those suppliers. This requirement has significant practical implications for procurement, contracting, and vendor management.

Access control and authentication

NIS2 requires policies governing user access to network and information systems, including multi-factor authentication (MFA) and privileged access management. Encryption of data in transit and at rest is also required where appropriate to the risk.

Cybersecurity training

Organisations must ensure that personnel with access to systems and management responsibilities have appropriate cybersecurity training. Senior management must understand their personal obligations under the Directive.

NIS2 compliance deadlines and enforcement

Member states had until 17 April 2025 to identify and register essential and important entities within their jurisdictions. Croatia was the first EU member state to complete transposition, having enacted its Law on Cybersecurity in February 2024.

If your organisation operates in a country that has already transposed NIS2, obligations are active now. If transposition is incomplete in your member state, the Directive has direct effect for essential entities in the sectors specifically listed in Annexes I and II, meaning you cannot rely on delayed national legislation as grounds for non-compliance.

Enforcement is the responsibility of national competent authorities designated by each member state. For essential entities, regulators can conduct proactive on-site inspections, request security audit documentation, and issue binding instructions. Personal liability for senior management makes non-compliance a board-level issue, not just an IT or security concern.

Benefits and challenges of NIS2 compliance

Compliance with NIS2 carries genuine operational benefits beyond avoiding penalties. A formal risk management programme, documented incident response procedures, and tested business continuity plans reduce the likelihood and impact of a disruptive security incident.

Demonstrable compliance also builds confidence with customers, partners, and regulators in markets where trust is a commercial differentiator.

The challenges are equally real. NIS2 compliance requires cross-functional effort across IT, legal, procurement, HR, and senior management. Supply chain assessment adds significant scope, particularly for organisations with large or complex supplier bases.

For those who have not previously operated under a formal cybersecurity framework, the gap analysis, policy development, and implementation work involved can be substantial.

The supply chain requirement in particular often catches organisations by surprise. You are also responsible for understanding the security posture of your direct suppliers and for managing the risk they introduce. That work begins with clarity on who is in your supplier base and what access they have to your systems.

How does NIS2 relate to GDPR?

NIS2 and GDPR are distinct but closely related. GDPR governs the processing of personal data. NIS2 governs the security of networks and information systems. They have different objectives, different supervisory authorities, and different compliance obligations.

Where they overlap is in the handling of security incidents that involve personal data. A ransomware attack on a health organisation may simultaneously trigger a NIS2 incident report to the national CSIRT and a GDPR personal data breach notification to the data protection authority.
NIS2 and GDPR timelines differ:

  • NIS2 requires an early warning within 24 hours.
  • GDPR requires notification of the supervisory authority within 72 hours where the breach is likely to result in risk to individuals.

Managing both concurrently requires coordinated incident response procedures.

Practically, the security measures required by NIS2 (access controls, encryption, business continuity, risk management) overlap substantially with the technical and organisational measures required under GDPR Article 32. Organisations compliant with one are often well positioned for the other, though the formal governance and reporting requirements of each remain separate.

Preparing for NIS2 compliance: initial steps

For organisations beginning their NIS2 compliance journey, the following steps provide a structured starting point.

Determine applicability

Assess whether your organisation falls within the essential or important entity categories based on sector, size, and your member state’s national legislation. Supplier organisations should also assess whether their clients’ in-scope status creates indirect obligations.

Conduct a gap analysis

Compare your current cybersecurity controls, policies, and procedures against NIS2’s Article 21 requirements. Identify where documented policies are absent, where controls are inadequate for the risk, and where reporting procedures do not meet the required timelines.

Assess your supply chain

Map your direct suppliers and service providers with access to your systems. Begin gathering evidence of their security practices and identify where contractual provisions need strengthening.

Review incident response procedures

Ensure your detection, classification, and reporting procedures are documented and that relevant staff understand the 24-hour and 72-hour reporting obligations.

Brief senior management

The personal liability provisions of NIS2 require boards and executive leadership to be informed and engaged. Compliance is a governance obligation as much as an IT function.

Infinum’s NIS2 compliance services are designed for organisations at this stage, combining technical depth with experience across DORA, ISO 27001, PCI DSS, and the Cyber Resilience Act.

NIS2 compliance is complex, and the combination of expanded scope, mandatory measures, and management accountability makes it unlike previous cybersecurity frameworks in its governance demands. Working with a consultancy experienced in regulated-sector compliance reduces the risk of underestimating the scope of what is required.

Frequently asked questions about the NIS2 Directive

Make security proactive, not reactive

Don’t risk getting compromised.

What services do you need?