National competent authoritiesand 2 more — see below
Sanction ceiling
2% of global turnover / EUR 10m
In force since 2023, but a directive: obligations bite at national dates. The transposition deadline of 17 October 2024 has passed and transposition is still materially incomplete: the Commission sent letters of formal notice to 23 Member States in November 2024 and referred Ireland, Spain, France and the Netherlands to the Court of Justice in July 2026.
What it does
A high common level of cybersecurity across the Union.
How it allocates obligations
Sectoral criticality plus entity size.
Regulated actor
Essential entity · Important entity
Protected party
End user
Territorial reach
Established in the EU
Implementation model
Requires national transposition
Enforcement mechanism
National competent authorities, following national transposition.
Key dates
Entry into force, application and transposition are different events and are kept apart. A date at month precision is shown as a month rather than invented as a day.
14 December 2022AdoptionAdoption
27 December 2022Publication in the Official JournalPublication in the Official Journal
16 January 2023Entry into forceEntry into force
17 October 2024Transposition deadlineMember States must have transposed NIS2 into national law.What it requires: For entities: the operative compliance date is the national one, which varies by Member State and in several cases has not yet arrived.
28 November 2024Enforcement actionThe Commission sends letters of formal notice to 23 Member States for failure to fully transpose NIS2.
8 July 2026Judicial eventThe Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose NIS2, requesting financial sanctions consisting of a lump sum and daily penalties until complete transposition is notified.
3 rules in the dataset turn on this instrument. They are conditions, not a test: the engine ranks them against what you actually answer, and downgrades rather than excludes where a question is left blank.
Potentially applicable
actor Critical-sector organisation or Essential entity or Important entityactivity Critical cybersecurity / essential infrastructure
NIS2 sets ten baseline risk-management measures and a reporting cascade of 24 hours, 72 hours and one month. Article 20 makes management bodies approve and oversee the measures and liable for the entity's infringements, and Article 32(6) adds personal liability for those responsible at essential entities — the provision that actually changes boardroom behaviour. Whether an organisation is an essential or an important entity turns on its sector and size.
Last verified 27 August 2026
Potentially applicable
actor Provider of data processing servicesactivity Cloud or data processing services or Critical cybersecurity / essential infrastructure
Cloud computing service providers and data centre service providers sit within the digital infrastructure sector, which NIS2 treats as essential. The size thresholds still determine whether an entity is essential or important.
Exemptions: Micro and small enterprises are generally outside NIS2, subject to sector-specific exceptions.
Last verified 27 August 2026
Potentially applicable
actor Public authorityactivity Critical cybersecurity / essential infrastructure
Public administration entities are within NIS2's sectoral scope, but Member States retain latitude in how far down the administrative hierarchy the Directive is transposed. This is precisely where the transposition patchwork bites hardest.
5 provisions recorded. This is what the dataset holds, not the whole instrument — an article that is not here has not been entered, which is a different statement from its not existing.
Article
Heading
Binds
Applies
Art. 3
Essential and important entitiesClassifies entities of the types listed in Annexes I and II as essential or important. Annex I entities above the medium-sized-enterprise ceilings, and the special cases the Article lists, are essential; any Annex I or II entity that does not qualify as essential is important. The classification determines the supervisory regime that applies.
Essential entity · Important entity
Applies from 17 October 2024the instrument’s general date; nothing specific to this article is recorded
Art. 20load-bearing
GovernanceManagement bodies must approve and oversee the cybersecurity risk-management measures and can be held liable for the entity's infringements (Art. 20(1)); at essential entities, the natural persons responsible can also be held liable (Art. 32(6)). The provision that actually changes boardroom behaviour.
Essential entity · Important entity
Applies from 17 October 2024the instrument’s general date; nothing specific to this article is recorded
Art. 21load-bearing
Cybersecurity risk-management measuresTen baseline measures including risk analysis, incident handling, business continuity, supply chain security, cyber hygiene, cryptography policy and multi-factor authentication.
Essential entity · Important entity
Applies from 17 October 2024the instrument’s general date; nothing specific to this article is recorded
Art. 23load-bearing
Reporting obligationsEarly warning within 24 hours, incident notification within 72 hours, final report within one month.
Essential entity · Important entity
Applies from 17 October 2024the instrument’s general date; nothing specific to this article is recorded
Art. 31
General aspects concerning supervision and enforcement
not recorded
Applies from 17 October 2024the instrument’s general date; nothing specific to this article is recorded
Enforcement
No enforcement recorded
This dataset holds no enforcement action under this instrument. That is what the record says; it is not a finding that none has been taken.
Every statement this site makes about NIS2, graded by what actually carries it. The grade is derived from the claim type and its sources, never stored, so it cannot drift from what it describes.
The instrument record itself was last verified on 27 August 2026; every claim below carries its own date.
5 Primary law2 Official source1 Derived by this site1 Interpretation1 Unresolved
Primary lawlaw
NIS2 Article 20(1) requires management bodies to approve and oversee the cybersecurity risk-management measures and provides that they can be held liable for the entity's infringements; for essential entities, Article 32(6) additionally requires that the natural persons responsible can be held liable for breaching their duties.
Article 23 NIS2 requires an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours and a final report within one month of the notification.
For essential entities, Article 32(6) NIS2 requires that the natural persons responsible for or representing the entity can be held liable for breach of their duties to ensure compliance.
For essential entities infringing Article 21 or 23, NIS2 requires Member States to provide for administrative fines with a maximum of at least EUR 10 million or at least 2% of total worldwide annual turnover, whichever is higher.
On 20 January 2026 the Commission proposed a cybersecurity package comprising a revised Cybersecurity Act and amendments to the NIS2 Directive; these are proposals, not law.
Tier 2 · regulatorstates this
Cybersecurity Package — Questions & Answers — European Commission 20 January 2026opening line: "On 20 January 2026, the Commission has proposed a new cybersecurity package ... including amendments to the NIS2 Directive"; Q1: "the Commission has proposed to revise the Cybersecurity Act"
The Commission sent letters of formal notice to twenty-three Member States in November 2024, reasoned opinions to nineteen in May 2025, and on 8 July 2026 referred Ireland, Spain, France and the Netherlands to the Court of Justice requesting financial sanctions.
The EU's directive-based instruments underperform its regulation-based ones badly — the strongest single argument for the regulation-first drafting approach used elsewhere in the rulebook.
Supervision under NIS2 has begun regardless of the transposition failure, but no officially published NIS2 fine decision has been located for this brief; figures circulating for Belgium, Italy and Hungary come from commercial trackers that describe their own numbers as indicative.
4 recorded interactions with other instruments — each with a direction, the provisions that carry it and its own sources. Direction is preserved as recorded: an instrument that amends another is not the same as one amended by it.
Companion directives sharing a transposition deadline: NIS2 on cyber resilience, CER on the physical and organisational resilience of critical entities.