1. Digital Policy
  2. Instruments
  3. NIS2

Directive · requires national transposition · CELEX 32022L2555

NIS2

Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union

Official text: Directive (EU) 2022/2555 (NIS 2 Directive)Tier 1 · primary law

Status
Transposition overdue as of 26 September 2026
Competent authority
National competent authoritiesand 2 more — see below
Sanction ceiling
2% of global turnover / EUR 10m

In force since 2023, but a directive: obligations bite at national dates. The transposition deadline of 17 October 2024 has passed and transposition is still materially incomplete: the Commission sent letters of formal notice to 23 Member States in November 2024 and referred Ireland, Spain, France and the Netherlands to the Court of Justice in July 2026.

What it does

A high common level of cybersecurity across the Union.

How it allocates obligations

Sectoral criticality plus entity size.

Regulated actor
Essential entity · Important entity
Protected party
End user
Territorial reach
Established in the EU
Implementation model
Requires national transposition
Enforcement mechanism
National competent authorities, following national transposition.

Key dates

Entry into force, application and transposition are different events and are kept apart. A date at month precision is shown as a month rather than invented as a day.

  1. 14 December 2022AdoptionAdoption
  2. 27 December 2022Publication in the Official JournalPublication in the Official Journal
  3. 16 January 2023Entry into forceEntry into force
  4. 17 October 2024Transposition deadlineMember States must have transposed NIS2 into national law.What it requires: For entities: the operative compliance date is the national one, which varies by Member State and in several cases has not yet arrived.
  5. 28 November 2024Enforcement actionThe Commission sends letters of formal notice to 23 Member States for failure to fully transpose NIS2.
  6. 8 July 2026Judicial eventThe Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose NIS2, requesting financial sanctions consisting of a lump sum and daily penalties until complete transposition is notified.

The whole compliance calendar, filterable →

Who it applies to

3 rules in the dataset turn on this instrument. They are conditions, not a test: the engine ranks them against what you actually answer, and downgrades rather than excludes where a question is left blank.

Potentially applicable

actor Critical-sector organisation or Essential entity or Important entityactivity Critical cybersecurity / essential infrastructure

NIS2 sets ten baseline risk-management measures and a reporting cascade of 24 hours, 72 hours and one month. Article 20 makes management bodies approve and oversee the measures and liable for the entity's infringements, and Article 32(6) adds personal liability for those responsible at essential entities — the provision that actually changes boardroom behaviour. Whether an organisation is an essential or an important entity turns on its sector and size.

Last verified 27 August 2026

Potentially applicable

actor Provider of data processing servicesactivity Cloud or data processing services or Critical cybersecurity / essential infrastructure

Cloud computing service providers and data centre service providers sit within the digital infrastructure sector, which NIS2 treats as essential. The size thresholds still determine whether an entity is essential or important.

Exemptions: Micro and small enterprises are generally outside NIS2, subject to sector-specific exceptions.

Last verified 27 August 2026

Potentially applicable

actor Public authorityactivity Critical cybersecurity / essential infrastructure

Public administration entities are within NIS2's sectoral scope, but Member States retain latitude in how far down the administrative hierarchy the Directive is transposed. This is precisely where the transposition patchwork bites hardest.

Last verified 27 August 2026

Run these against your situation →

Key provisions

5 provisions recorded. This is what the dataset holds, not the whole instrument — an article that is not here has not been entered, which is a different statement from its not existing.

ArticleHeadingBindsApplies
Art. 3Essential and important entitiesClassifies entities of the types listed in Annexes I and II as essential or important. Annex I entities above the medium-sized-enterprise ceilings, and the special cases the Article lists, are essential; any Annex I or II entity that does not qualify as essential is important. The classification determines the supervisory regime that applies.Essential entity · Important entityApplies from 17 October 2024the instrument’s general date; nothing specific to this article is recorded
Art. 20load-bearingGovernanceManagement bodies must approve and oversee the cybersecurity risk-management measures and can be held liable for the entity's infringements (Art. 20(1)); at essential entities, the natural persons responsible can also be held liable (Art. 32(6)). The provision that actually changes boardroom behaviour.Essential entity · Important entityApplies from 17 October 2024the instrument’s general date; nothing specific to this article is recorded
Art. 21load-bearingCybersecurity risk-management measuresTen baseline measures including risk analysis, incident handling, business continuity, supply chain security, cyber hygiene, cryptography policy and multi-factor authentication.Essential entity · Important entityApplies from 17 October 2024the instrument’s general date; nothing specific to this article is recorded
Art. 23load-bearingReporting obligationsEarly warning within 24 hours, incident notification within 72 hours, final report within one month.Essential entity · Important entityApplies from 17 October 2024the instrument’s general date; nothing specific to this article is recorded
Art. 31General aspects concerning supervision and enforcementnot recordedApplies from 17 October 2024the instrument’s general date; nothing specific to this article is recorded

Enforcement

No enforcement recorded

This dataset holds no enforcement action under this instrument. That is what the record says; it is not a finding that none has been taken.

The whole enforcement observatory →

Evidence and sources

Every statement this site makes about NIS2, graded by what actually carries it. The grade is derived from the claim type and its sources, never stored, so it cannot drift from what it describes.

The instrument record itself was last verified on 27 August 2026; every claim below carries its own date.

5 Primary law2 Official source1 Derived by this site1 Interpretation1 Unresolved
Primary lawlaw

NIS2 Article 20(1) requires management bodies to approve and oversee the cybersecurity risk-management measures and provides that they can be held liable for the entity's infringements; for essential entities, Article 32(6) additionally requires that the natural persons responsible can be held liable for breaching their duties.

Tier 1 · primary lawstates this

Directive (EU) 2022/2555 (NIS 2 Directive) — EUR-Lex 27 December 2022 Art. 20

Tier 4 · press / advocacysupports in part

The NIS 2 Directive — Article 20 (Governance) and Article 32 (Supervisory and enforcement measures in relation to essential entities) — nis-2-directive.com (unofficial reproduction of the NIS2 text) Arts. 20(1), 32(6)

Read it in the brief →Last verified 26 September 2026
Primary lawlaw

Article 21(2) NIS2 lists ten minimum cybersecurity risk-management measures, including risk analysis, incident handling, business continuity, supply-chain security, basic cyber hygiene, cryptography and multi-factor authentication.

Tier 1 · primary lawstates this

Directive (EU) 2022/2555 (NIS 2 Directive) — EUR-Lex 27 December 2022 Art. 21(2)(a)–(j)

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

Article 23 NIS2 requires an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours and a final report within one month of the notification.

Tier 1 · primary lawstates this

Directive (EU) 2022/2555 (NIS 2 Directive) — EUR-Lex 27 December 2022 Art. 23(4)(a), (b), (d)

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

For essential entities, Article 32(6) NIS2 requires that the natural persons responsible for or representing the entity can be held liable for breach of their duties to ensure compliance.

Tier 1 · primary lawstates this

Directive (EU) 2022/2555 (NIS 2 Directive) — EUR-Lex 27 December 2022 Art. 32(6)

Read it in the brief →Last verified 27 September 2026
Primary lawlaw

For essential entities infringing Article 21 or 23, NIS2 requires Member States to provide for administrative fines with a maximum of at least EUR 10 million or at least 2% of total worldwide annual turnover, whichever is higher.

Tier 1 · primary lawstates this

Directive (EU) 2022/2555 (NIS 2 Directive) — EUR-Lex 27 December 2022 Art. 34(4)

Read it in the brief →Last verified 27 September 2026
Official sourcefact

On 20 January 2026 the Commission proposed a cybersecurity package comprising a revised Cybersecurity Act and amendments to the NIS2 Directive; these are proposals, not law.

Tier 2 · regulatorstates this

Cybersecurity Package — Questions & Answers — European Commission 20 January 2026 opening line: "On 20 January 2026, the Commission has proposed a new cybersecurity package ... including amendments to the NIS2 Directive"; Q1: "the Commission has proposed to revise the Cybersecurity Act"

Read it in the brief →Last verified 27 September 2026
Official sourcefact

The Commission sent letters of formal notice to twenty-three Member States in November 2024, reasoned opinions to nineteen in May 2025, and on 8 July 2026 referred Ireland, Spain, France and the Netherlands to the Court of Justice requesting financial sanctions.

Tier 2 · regulatorstates this

Commission calls on 23 Member States to fully transpose the NIS2 Directive — European Commission 28 November 2024 "sending letters of formal notice to the other 23 Member States"

Tier 2 · regulatorstates this

Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose NIS2 — European Commission 8 July 2026 "letters of formal notice on 28 November 2024 and reasoned opinions on 7 May 2025"; "Spain, France, Ireland and the Netherlands"; "a request to the Court to impose financial sanctions"

Read it in the brief →Last verified 27 September 2026
Derived by this sitederived

Only four of twenty-seven Member States met the NIS2 transposition deadline of 17 October 2024.

Tier 2 · regulatorsupports in part

Commission calls on 23 Member States to fully transpose the NIS2 Directive — European Commission 28 November 2024 First paragraph: letters of formal notice to 23 named Member States; 'sending letters of formal notice to the other 23 Member States'

Read it in the brief →Last verified 27 September 2026
Interpretationinterpretation

The EU's directive-based instruments underperform its regulation-based ones badly — the strongest single argument for the regulation-first drafting approach used elsewhere in the rulebook.

Unverified · the brief itselfstates this

Original source document underlying this siteno link — The European Legal Framework for the Digital World (this brief) 19 August 2026 Part VII

Read it in the brief →Last verified 27 August 2026
Unresolvedfact

Supervision under NIS2 has begun regardless of the transposition failure, but no officially published NIS2 fine decision has been located for this brief; figures circulating for Belgium, Italy and Hungary come from commercial trackers that describe their own numbers as indicative.

Tier 4 · press / advocacysupports in part

NIS2 Enforcement Tracker 2026: Fines, Audits, Status — Legiscope 10 July 2026

Read it in the brief →Last verified 26 September 2026

The full bibliography and the evidence method →

How it interacts

4 recorded interactions with other instruments — each with a direction, the provisions that carry it and its own sources. Direction is preserved as recorded: an instrument that amends another is not the same as one amended by it.