Resources › Legislation › NIS2
LEGISLATION

NIS2 Directive

The Network and Information Security Directive

The NIS2 Directive (Directive (EU) 2022/2555) establishes a common cybersecurity framework across the European Union. It replaced the original NIS Directive and significantly expanded the number of sectors and organisations subject to cybersecurity risk management, incident reporting, governance, and supervisory requirements.

NIS2 covers entities across 18 critical sectors, including energy, transport, health, digital infrastructure, ICT service management, public administration, manufacturing, and other critical activities.

ZInfV-1

NIS2 is an EU directive rather than a single compliance law applied identically in every Member State. Each country must transpose it into national legislation, and Article 5 expressly allows Member States to adopt or maintain rules that provide a higher level of cybersecurity than the Directive itself. Organisations therefore need to understand both the EU framework and the national law that applies to them.

Publication date 6 October 2026
Legal reference Directive (EU) 2022/2555
Transposition deadline 17 October 2024
01

What is NIS2 and why is it important?

The objective of NIS2 is to achieve a high common level of cybersecurity across the EU. To do this, the Directive requires Member States to establish national cybersecurity strategies, competent authorities, single points of contact and CSIRTs, while imposing cybersecurity risk-management and incident-reporting obligations on essential and important entities.

It also introduces rules for supervision, enforcement, and cybersecurity information sharing.  

KEY POINT

NIS2 makes cybersecurity a management responsibility, not just an IT issue.

Under Article 20, management bodies of essential and important entities must approve cybersecurity risk-management measures, oversee their implementation and receive cybersecurity training. Compliance therefore requires clear responsibilities and active management involvement.

Compared with its predecessor, NIS2 has a broader scope and applies to more sectors and organisations. The European Commission describes the framework as covering 18 critical sectors and, generally, medium-sized and large entities operating in those sectors. The Directive also contains exceptions that bring certain organisations into scope regardless of size.  

Cybersecurity under NIS2 is not limited to the IT department. Article 20 requires the management bodies of essential and important entities to approve cybersecurity risk-management measures and oversee their implementation. Members of management bodies must also receive cybersecurity training, while Member States are required to encourage regular training for employees.  

The enforcement framework is also significant. For infringements of Articles 21 or 23, Member States must ensure that essential entities can face maximum administrative fines of at least €10 million or 2% of worldwide annual turnover, whichever is higher. For important entities, the maximum administrative fine must be at least €7 million or 1.4% of worldwide annual turnover, whichever is higher. The precise enforcement process is implemented through national law.  

Member States were required to transpose NIS2 by 17 October 2024. Implementation has not progressed at exactly the same pace across the EU. On 8 July 2026, the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice of the EU for failing to notify full transposition at that time. This illustrates why organisations operating internationally should verify the current national position rather than relying only on the text of the Directive.

02

Does NIS2 apply to your organisation?

The first question is not simply whether your organisation “does cybersecurity”. Applicability depends on the type of activity, size of the entity, and specific exceptions or national rules.

1
Check your sector
NIS2 applies to entity types listed in Annex I and Annex II. Annex I covers sectors of high criticality such as energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration and space. Annex II covers additional critical sectors including postal and courier services, waste management, chemicals, food, certain manufacturing activities, digital providers, and research.
2
Check the size criteria
Under Article 2, NIS2 generally applies to entities in Annex I or II that qualify as medium-sized enterprises or exceed the ceilings for medium-sized enterprises under the EU SME rules. This is more precise than simply saying that NIS2 applies to every company with a particular number of employees, because the EU SME classification also takes financial and organisational factors into account.
3
Check the exceptions
Some organisations fall within the Directive regardless of size. Examples include certain providers of public electronic communications networks or services, trust service providers, top-level domain registries, and DNS service providers. Member States can also identify entities as critical because of their importance to public safety, public health, systemic risk or essential economic and societal activities.
4
Essential or important entity?
NIS2 distinguishes between essential and important entities. Classification depends on the sector, size, and several special rules. For example, Article 3 treats certain larger Annex I entities as essential, while qualified trust service providers, TLD registries and DNS service providers can be essential regardless of size. Other in-scope entities that do not meet the criteria for essential status are generally classified as important. The distinction matters particularly for supervision and enforcement, but both categories are subject to the core cybersecurity risk-management and incident-reporting requirements.
5
Finally, check the national law
This step is essential. NIS2 is a minimum-harmonisation directive, so Member States may introduce stricter cybersecurity provisions. Registration procedures, competent authorities, national reporting systems, supervisory practices, and other implementation details can therefore differ. For a group operating in several EU countries, applicability should be assessed for the relevant entities against the relevant national implementing legislation in each applicable jurisdiction.
03

Key requirements of NIS2

Management responsibility and training

Cybersecurity governance starts at management level. Management bodies of essential and important entities must approve cybersecurity risk-management measures and oversee their implementation. Members of management bodies must receive training so that they can understand cybersecurity risks and assess their possible impact on the organisation’s services.  

Approval
management approval and oversight of cybersecurity measures
Training
required for management bodies
21
Article

Cybersecurity risk management

Article 21 requires essential and important entities to implement appropriate and proportionate technical, operational and organisational measures to manage risks affecting their network and information systems and to prevent or minimise the impact of incidents. Measures must reflect the organisation’s exposure to risk and the potential consequences of incidents.

Incident handling and business continuity

Risk-management measures must include incident handling as well as business continuity. The Directive specifically refers to backup management, disaster recovery, and crisis management. Organisations therefore need to define responsibilities, escalation procedures and recovery arrangements rather than relying only on preventive controls.

Supply chain security

NIS2 explicitly includes supply chain security, which covers cybersecurity aspects of relationships with direct suppliers and service providers. An organisation’s assessment should therefore extend beyond its internal environment to dependencies that could affect the security or continuity of its services.

Secure acquisition, development and vulnerability management 

Article 21 also covers security in the acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure. This connects cybersecurity requirements with procurement, software development, maintenance, and vulnerability management processes. 

Cyber hygiene, access control and authentication 

The Directive requires measures covering basic cyber hygiene and cybersecurity training, policies and procedures regarding cryptography and encryption, human resources security, access control policies and asset management. It also includes the use of multi-factor authentication or continuous authentication solutions where appropriate.  

23
Article

Significant incident reporting 

NIS2 does not require the full regulatory reporting process for every minor security event. Under Article 23, an incident is significant if it has caused or is capable of causing severe operational disruption or financial loss, or if it has affected or could affect other persons by causing considerable material or non-material damage.  

For a significant incident, the Directive establishes a staged process: an early warning within 24 hours of becoming aware of the incident, an incident notification within 72 hours, and a final report no later than one month after the incident notification. Intermediate reports may also be requested.

Additional requirements for certain digital entities

For certain digital infrastructure, ICT service management and digital provider entities, Commission Implementing Regulation (EU) 2024/2690 provides more detailed technical and methodological requirements and further criteria for determining when an incident is significant.  

04

Path to compliance

A practical implementation programme can follow eight steps.

SCOPE

Determine scope and applicable national law

Identify the relevant legal entity, sector and services, assess size and special exceptions, and determine whether the entity is essential or important. Then identify the national legislation implementing NIS2 and the competent authority.

GOVERNANCE

Establish governance and ownership

Define which management body approves cybersecurity measures, who owns individual risks and controls, and who is responsible for regulatory and incident reporting.

ASSETS

Map assets, services, and dependencies

Identify the systems, information, applications, infrastructure, business processes and external providers required to deliver in-scope services.

RISKS

Perform risk and business impact assessments

Assess threats, vulnerabilities, potential disruption, and dependencies. Use the results to prioritise controls and continuity requirements rather than treating every system identically.

CONTROLS

Assess controls against Article 21

Review existing practices for incident management, business continuity, backups, supply chain security, vulnerability management, access control, cryptography, training, and other required areas. Article 21 requires measures to be appropriate and proportionate to risk.

REPORTING

Establish the incident-reporting process

Organisations should know who decides whether an incident is significant, who contacts the relevant CSIRT or authority, which information must be collected and how the 24-hour and 72-hour deadlines will be met.

TESTING

Test continuity and response

Plans should be tested so that backups, recovery, crisis roles, and internal and external communication procedures work in practice.

REVIEW

Review effectiveness and retain evidence

Maintain risk assessments, decisions, assigned responsibilities, completed actions, tests, training records, and other evidence that demonstrates how cybersecurity measures are managed.

For entities covered by Implementing Regulation 2024/2690, ENISA’s NIS2 Technical Implementation Guidance provides additional practical support, including examples of evidence and mappings to relevant standards and frameworks. ENISA published the guidance in June 2025.

05

How can Blue Octopus help?

Blue Octopus does not replace technical cybersecurity controls, a legal assessment, a competent authority, or an independent audit. Its role is in helping organisations structure the management layer around risks, analyses, responsibilities, and supporting documentation.

NIS2 area
How Blue Octopus can support it
Risk management
Structure, assess and prioritise risks
Ownership
Assign risks and actions to responsible owners
Analysis
Connect findings with risks and priorities
Documentation
Organise relevant documentation alongside analyses and risks
Management overview
Maintain visibility of priorities, responsibilities and open actions
Improvement actions
Track findings and corrective actions over time

Using a management platform does not demonstrate NIS2 compliance. The underlying risk assessments, cybersecurity measures, procedures and evidence still need to satisfy the applicable EU and national requirements.

06
FAQ

Frequently asked questions

Short answers to the most common questions about the scope and requirements of NIS2.

No. Medium-sized and larger organisations in covered sectors form the general scope, but Article 2 includes several situations in which entities can be covered regardless of size.

Both are subject to core NIS2 requirements, but the Directive distinguishes them for classification, supervision and enforcement. Article 3 sets out the detailed classification rules.

Not by itself. ISO/IEC 27001 can provide a useful framework for an information security management system (ISMS), but NIS2 contains specific legal obligations relating to governance, risk-management measures, reporting, and supervision. Compliance must therefore be assessed against the applicable NIS2 requirements and national law.

A supplier may or may not independently fall within NIS2. However, in-scope organisations must address supply chain security and their relationships with direct suppliers and service providers, so cybersecurity requirements can also affect suppliers contractually.

No. The staged Article 23 reporting process applies to significant incidents. The Directive defines the general significance criteria, while Implementing Regulation 2024/2690 provides more detailed criteria for specified categories of digital entities.

No. NIS2 is a minimum-harmonisation directive. Member States may impose a higher level of cybersecurity and implement national procedures, authorities, and enforcement arrangements. Organisations should therefore verify the applicable national transposition law.

07

Official sources

08

Next step

NIS2 readiness requires more than a cybersecurity policy. Organisations need a repeatable process that connects risks, critical services, responsible owners, suppliers, controls, incident response and evidence of implementation. 

Blue Octopus can help organisations structure risks, analyses, responsibilities and supporting documentation in one place, providing a clearer management view of what needs to be addressed and who is responsible.