Regulation explainerRisk & Resilience
NIS2 compliance requirements: scope, Article 21 measures and reporting clocks
NIS2, Directive (EU) 2022/2555, applies to medium-sized and larger organizations in the sectors listed in its two annexes, plus some smaller ones regardless of size. In-scope entities must have management approve and oversee cybersecurity risk-management measures, implement the minimum measures in Article 21, and report significant incidents on a fixed clock that starts with an early warning. National laws transpose the details, so the rules you follow are your member state's.
On this page
- Where NIS2 transposition and amendment stand today
- Working through the NIS2 scope test
- Essential and important entities compared
- The ten Article 21(2) measures and the evidence each needs
- The Article 23 reporting clock after a significant incident
- What Article 20 asks of management bodies personally
- How NIS2 sits alongside DORA, the Cyber Resilience Act and GDPR
- A ninety-day NIS2 gap-assessment sequence
- Questions and answers
- Sources
Where NIS2 transposition and amendment stand today
Working through the NIS2 scope test
- If
You operate in a sector listed in Annex I or II and are a medium-sized enterprise or larger, providing services in the EU.
ThenAssume you are in scope and confirm whether you are an essential or important entity under national law.
The Directive applies to such entities through its size-cap rule1.
- If
You are smaller, but are, for example, the sole provider of an essential service in a member state, a qualified trust service provider, a top-level domain registry or a DNS service provider.
ThenCheck the size-independent categories; you may be in scope regardless of size.
Article 2(2) and Article 3 bring certain entities in whatever their size1.
- If
You are a financial entity subject to DORA.
ThenFollow DORA for ICT risk management and incident reporting, and check what national NIS2 law still asks of you.
Where a sector-specific act imposes at least equivalent duties, the corresponding NIS2 provisions do not apply, and DORA is treated as such an act for financial entities1.
- If
You are outside the annexes or below the thresholds, but supply in-scope entities.
ThenExpect NIS2-driven security clauses, questionnaires and audit requests from customers.
In-scope customers must manage supply chain security under Article 21(2)(d)1.
Essential and important entities compared
| Aspect | Essential entities | Important entities |
|---|---|---|
| Typical members | Large entities in Annex I sectors and certain size-independent categories | Other in-scope entities in Annex I or II |
| Risk-management measures | Article 21 measures in full | Article 21 measures in full |
| Incident reporting | Article 23 clock applies | Article 23 clock applies |
| Supervision | Proactive: inspections and audits without prior evidence of breach | Reactive: ex post measures when evidence of non-compliance arises |
| Fine ceiling set by the Directive | At least EUR 10 million or 2% of worldwide turnover, whichever is higher1 | At least EUR 7 million or 1.4% of worldwide turnover, whichever is higher1 |
The Directive sets minimum maximum fines; national law can set higher ceilings.
The ten Article 21(2) measures and the evidence each needs
Measures must be appropriate and proportionate to the risk, so the depth of each varies; the topics do not.
The Article 23 reporting clock after a significant incident
An incident is significant if it has caused, or could cause, severe operational disruption or financial loss to the entity, or considerable damage to others1.
Decide significance quickly
Have pre-agreed criteria and a named decision-maker, because the clock runs from awareness of a significant incident, not from the end of the investigation.
Send the early warning
Notify the CSIRT or competent authority without undue delay and within 24 hours, indicating whether unlawful or malicious action is suspected or cross-border impact is possible1.
Submit the incident notification
Within 72 hours of awareness, update the early warning with an initial assessment of severity and impact and any indicators of compromise1.
Provide intermediate reports on request
The CSIRT or authority can ask for status updates while the incident is being handled1.
File the final report
No later than one month after the incident notification, describe the incident, root cause, mitigation applied and any cross-border impact1.
What Article 20 asks of management bodies personally
NIS2 makes cybersecurity a board-level duty. Management bodies must approve the risk-management measures, oversee their implementation and can be held liable for infringements; their members must also follow training so they can identify risks and assess management practices1. Member states are encouraged to offer similar training to staff.
In practice, this means minutes that show measures were approved, a reporting rhythm that lets the board oversee them, and training records for every member. A risk register summary presented once a year is unlikely to satisfy a supervisor looking for active oversight.
How NIS2 sits alongside DORA, the Cyber Resilience Act and GDPR
Directive (EU) 2022/2555 (NIS2 Directive)
EU, through national transpositionApplies whenAn entity in an Annex I or II sector meets the size test or a size-independent category1.
Regulation (EU) 2022/2554 (Digital Operational Resilience Act)
EU financial entitiesApplies whenThe entity is a financial entity in DORA's scope; DORA then acts as the sector-specific act for these duties3.
- ICT risk management, major incident reporting, resilience testing and ICT third-party risk under DORA rather than NIS23.
Regulation (EU) 2024/2847 (Cyber Resilience Act)
EU single marketApplies whenA manufacturer places products with digital elements on the EU market4.
- Product security requirements and manufacturer reporting of actively exploited vulnerabilities and severe incidents4.
Regulation (EU) 2016/679 (General Data Protection Regulation)
EU and EEAApplies whenAn incident is also a personal data breach5.
- Notify the supervisory authority and, where risk to individuals is high, the people affected, on GDPR's own timelines5.
A ninety-day NIS2 gap-assessment sequence
- Confirm scope
Entity classification, member states involved, main establishment and registration status.
- Assess against Article 21
Rate each of the ten measures for design and evidence, by business service.
- Test reporting readiness
Walk a scenario through the early warning and notification steps.
- Prioritize gaps
Rank by exposure and supervisory attention, with owners and dates.
- Brief the board
Approval of measures, oversight rhythm and management training plan.
Questions and answers
Does NIS2 apply to companies based outside the EU?
It can. The Directive applies to in-scope entities that provide services or carry out activities in the EU, wherever they are headquartered. Certain digital providers not established in the EU but offering services there must designate a representative in a member state. Non-EU groups should map which subsidiaries operate in Annex I or II sectors, where each has its main establishment, and which national laws therefore apply.
Why do NIS2 obligations differ between EU countries?
NIS2 is a directive, so each member state writes its own law to implement it. National laws can add sectors, set higher fines, choose different authorities and registration portals, and phrase the measures more specifically. Organizations operating in several member states should identify which jurisdiction supervises them, generally linked to the main establishment for certain digital providers, and track each relevant national law.
Can managers be held personally liable under NIS2?
Article 20 says management bodies can be held liable for infringements of their duties to approve and oversee the risk-management measures, and Article 32 lets authorities of essential entities seek temporary bans on management functions in some circumstances. How liability works depends on national law. Directors should expect to show that they approved the measures, oversaw them and completed the required training.
Is a small supplier affected if it is not in scope itself?
Usually, yes, indirectly. In-scope customers must secure their supply chains, so they will push security clauses, assessments and incident notification terms into contracts with their suppliers. A small software or managed service provider may therefore need much of the same evidence, such as access control, vulnerability handling and incident response, to keep selling to regulated customers.
Sources
- Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive) — EUR-Lex · checked 10 October 2026
- NIS2 Directive: securing network and information systems — European Commission · checked 10 October 2026
- Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA) — EUR-Lex · checked 10 October 2026
- Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act) — EUR-Lex · checked 10 October 2026
- Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex · checked 10 October 2026