Guide · Regulation

What NIS2 covers, and who it binds.

Regulation · 8 min read · Updated July 2026

What is NIS2? The NIS2 Directive is the EU's expanded cybersecurity law for essential and important entities — a far wider net than the 2016 rules it replaces, reaching deep into supply chains and carrying real accountability for company boards. Because it is a directive, it lives in national law, so the specifics depend on where you operate. This guide covers who it binds, the duties it imposes, and how it sits alongside DORA.

In one sentence

NIS2 — Directive (EU) 2022/2555 — is the EU's updated cybersecurity directive requiring essential and important entities across a broad range of sectors to manage cyber risk, secure their supply chains, and report significant incidents on a strict clock.

What NIS2 is

NIS2 is Directive (EU) 2022/2555 — the European Union's second, much broader, network-and-information-security law. It entered into force in January 2023 and replaces the original 2016 NIS Directive, whose scope proved too narrow and whose implementation varied too much between countries. NIS2 widens the net, tightens the duties, and adds real teeth in the form of penalties and management accountability.

Being a directive matters. Unlike a regulation, a directive is not law by itself: each member state must transpose it into national legislation, which is where the binding detail lives. The EU text is the floor — national law can go further and differs in specifics. So the honest answer to "what does NIS2 require of me?" always has a second half: "and where are you established?"

Essential vs important entities

NIS2 sorts organisations into two tiers — essential and important entities — based mainly on sector and size.

Essential entities are typically larger organisations in the highest-criticality sectors: energy, transport, banking and financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, and space. Important entities cover other in-scope sectors and medium-sized firms: postal and courier services, waste management, chemicals, food, manufacturing, digital providers such as online marketplaces and search engines, and research. Some entities — certain DNS and domain-registry providers, for instance — are in scope regardless of size.

The practical difference is supervision. Essential entities face proactive, ex-ante oversight — regulators can inspect without waiting for something to go wrong. Important entities face lighter, ex-post oversight that engages when there is evidence of a problem. Both must meet the same core security duties; they differ in how hard the regulator leans in, and in the ceiling on penalties: fines can reach up to 10 million euro or 2% of global annual turnover for essential entities, and up to 7 million euro or 1.4% for important ones.

The security and supply-chain duties

In-scope entities owe a baseline of cybersecurity risk-management measures. The directive lists ten — an "all-hazards" set covering:

  • Risk analysis and information-system security policies
  • Incident handling
  • Business continuity, backups, and crisis management
  • Supply-chain security, including the security of relationships with direct suppliers and service providers
  • Security in acquisition, development, and maintenance of systems, including vulnerability handling
  • Policies to assess the effectiveness of the measures, plus basic cyber hygiene and training
  • Cryptography; human-resources security, access control, and asset management; and multi-factor authentication

The supply-chain clause is the one that reaches beyond your own perimeter. NIS2 makes each entity responsible for the security of its direct suppliers — a duty that only works if you know which suppliers matter and what they can reach, which is the everyday business of managing supplier risk under the directive. At EU level, the Cooperation Group can run coordinated risk assessments of critical supply chains.

NIS2 also pushes accountability upward. Management bodies must approve the risk-management measures and oversee their implementation, must take cybersecurity training, and can be held personally liable for failures. Cyber risk stops being something the board hears about and becomes something the board signs off on. In several member states that liability is personal and specific — directors can face fines or temporary bans from management roles for serious, unremedied failures.

The incident-reporting clock

When a significant incident hits, NIS2 sets a staged reporting clock to the national CSIRT or competent authority. The EU baseline:

  • Early warning within 24 hours of becoming aware — flagging whether the incident looks malicious or could have cross-border effects
  • Incident notification within 72 hours, with an initial assessment of severity and impact
  • Final report within one month, covering root cause, mitigations, and impact

The detail — what counts as "significant," the exact national channel, the required format — is set by each country's transposition. We work through it in the NIS2 incident reporting guide. The clock starts from awareness, not from when the attack began, so fast, accurate classification is what protects the deadline.

Transposition, and where DORA fits

NIS2 set a transposition deadline of 17 October 2024 — the date by which member states were meant to have national laws in place. In practice, transposition has run late and uneven; several countries missed the deadline, and the specifics continue to differ country by country. If you operate across borders, you are not complying with "NIS2" so much as with each national implementation of it. The European Commission has pressed late member states to finish transposing, but until national law is in force and applied, the precise obligations in a given country can still be shifting.

NIS2 also sits next to DORA. Where DORA is a directly-applicable regulation aimed squarely at financial entities' ICT resilience, NIS2 is a directive spanning many sectors. Financial entities in scope of both generally follow DORA for the ICT-specific obligations it covers, under the lex specialis principle — the two are built to complement, not duplicate.

This is an informational overview, not legal advice. NIS2 is an EU baseline; national transposition varies, and your obligations depend on the law of the member states where you operate. Verify the current national text that applies to you with qualified counsel. Last reviewed July 2026.

NIS2, without the guesswork
Polestead covers every significant supplier.

It classifies your entire register by your own exposure so no significant supplier goes unassessed, and scopes assessment depth to risk. On a significant incident, CIIC schedules NIS2's 24h / 72h / 1-month clock and drafts each submission.

How Polestead handles NIS2 →
FAQ

Common questions.

What is NIS2?+

NIS2 — Directive (EU) 2022/2555 — is the EU's updated cybersecurity directive. It requires essential and important entities across many sectors to manage cyber risk, secure their supply chains, and report significant incidents on a staged clock.

What is the difference between essential and important entities?+

Both meet the same core security duties. Essential entities — larger firms in the highest-criticality sectors — face proactive, ex-ante supervision and higher penalty ceilings; important entities face lighter, ex-post supervision that engages when a problem surfaces.

When did NIS2 take effect?+

NIS2 entered into force in January 2023 with a transposition deadline of 17 October 2024. It applies through each member state's national law, and because transposition has run late and uneven, the exact obligations depend on where you operate.

What are the NIS2 reporting deadlines?+

As an EU baseline: an early warning within 24 hours of awareness, an incident notification within 72 hours, and a final report within one month. National transposition sets the precise thresholds and channels.

Keep reading
What is DORA?
The EU's directly-applicable resilience regulation.
NIS2 incident reporting
The 24h / 72h / 1-month clock, in detail.
NIS2 on Polestead →
Supply-chain duties and incident clocks.