Regulation explainerRisk & Resilience

NIS2 compliance requirements: scope, Article 21 measures and reporting clocks

NIS2, Directive (EU) 2022/2555, applies to medium-sized and larger organizations in the sectors listed in its two annexes, plus some smaller ones regardless of size. In-scope entities must have management approve and oversee cybersecurity risk-management measures, implement the minimum measures in Article 21, and report significant incidents on a fixed clock that starts with an early warning. National laws transpose the details, so the rules you follow are your member state's.

Reviewed 7 min read

On this page
  1. Where NIS2 transposition and amendment stand today
  2. Working through the NIS2 scope test
  3. Essential and important entities compared
  4. The ten Article 21(2) measures and the evidence each needs
  5. The Article 23 reporting clock after a significant incident
  6. What Article 20 asks of management bodies personally
  7. How NIS2 sits alongside DORA, the Cyber Resilience Act and GDPR
  8. A ninety-day NIS2 gap-assessment sequence
  9. Questions and answers
  10. Sources

Where NIS2 transposition and amendment stand today

Working through the NIS2 scope test

  • If

    You operate in a sector listed in Annex I or II and are a medium-sized enterprise or larger, providing services in the EU.

    Then

    Assume you are in scope and confirm whether you are an essential or important entity under national law.

    The Directive applies to such entities through its size-cap rule1.

  • If

    You are smaller, but are, for example, the sole provider of an essential service in a member state, a qualified trust service provider, a top-level domain registry or a DNS service provider.

    Then

    Check the size-independent categories; you may be in scope regardless of size.

    Article 2(2) and Article 3 bring certain entities in whatever their size1.

  • If

    You are a financial entity subject to DORA.

    Then

    Follow DORA for ICT risk management and incident reporting, and check what national NIS2 law still asks of you.

    Where a sector-specific act imposes at least equivalent duties, the corresponding NIS2 provisions do not apply, and DORA is treated as such an act for financial entities1.

  • If

    You are outside the annexes or below the thresholds, but supply in-scope entities.

    Then

    Expect NIS2-driven security clauses, questionnaires and audit requests from customers.

    In-scope customers must manage supply chain security under Article 21(2)(d)1.

Essential and important entities compared

AspectEssential entitiesImportant entities
Typical membersLarge entities in Annex I sectors and certain size-independent categoriesOther in-scope entities in Annex I or II
Risk-management measuresArticle 21 measures in fullArticle 21 measures in full
Incident reportingArticle 23 clock appliesArticle 23 clock applies
SupervisionProactive: inspections and audits without prior evidence of breachReactive: ex post measures when evidence of non-compliance arises
Fine ceiling set by the DirectiveAt least EUR 10 million or 2% of worldwide turnover, whichever is higher1At least EUR 7 million or 1.4% of worldwide turnover, whichever is higher1

The Directive sets minimum maximum fines; national law can set higher ceilings.

The ten Article 21(2) measures and the evidence each needs

Measures must be appropriate and proportionate to the risk, so the depth of each varies; the topics do not.

0 of 10 checked

The Article 23 reporting clock after a significant incident

An incident is significant if it has caused, or could cause, severe operational disruption or financial loss to the entity, or considerable damage to others1.

  1. Decide significance quickly

    Have pre-agreed criteria and a named decision-maker, because the clock runs from awareness of a significant incident, not from the end of the investigation.

    Owner
    Incident commander
  2. Send the early warning

    Notify the CSIRT or competent authority without undue delay and within 24 hours, indicating whether unlawful or malicious action is suspected or cross-border impact is possible1.

    Output
    Early warning
  3. Submit the incident notification

    Within 72 hours of awareness, update the early warning with an initial assessment of severity and impact and any indicators of compromise1.

    Output
    Incident notification
  4. Provide intermediate reports on request

    The CSIRT or authority can ask for status updates while the incident is being handled1.

    Output
    Intermediate report
  5. File the final report

    No later than one month after the incident notification, describe the incident, root cause, mitigation applied and any cross-border impact1.

    Output
    Final report

What Article 20 asks of management bodies personally

NIS2 makes cybersecurity a board-level duty. Management bodies must approve the risk-management measures, oversee their implementation and can be held liable for infringements; their members must also follow training so they can identify risks and assess management practices1. Member states are encouraged to offer similar training to staff.

In practice, this means minutes that show measures were approved, a reporting rhythm that lets the board oversee them, and training records for every member. A risk register summary presented once a year is unlikely to satisfy a supervisor looking for active oversight.

How NIS2 sits alongside DORA, the Cyber Resilience Act and GDPR

Directive (EU) 2022/2555 (NIS2 Directive)

EU, through national transposition

Applies whenAn entity in an Annex I or II sector meets the size test or a size-independent category1.

  • Management approval and training under Article 201.
  • Article 21 measures and Article 23 incident reporting1.

Regulation (EU) 2022/2554 (Digital Operational Resilience Act)

EU financial entities

Applies whenThe entity is a financial entity in DORA's scope; DORA then acts as the sector-specific act for these duties3.

  • ICT risk management, major incident reporting, resilience testing and ICT third-party risk under DORA rather than NIS23.

Regulation (EU) 2024/2847 (Cyber Resilience Act)

EU single market

Applies whenA manufacturer places products with digital elements on the EU market4.

  • Product security requirements and manufacturer reporting of actively exploited vulnerabilities and severe incidents4.

Regulation (EU) 2016/679 (General Data Protection Regulation)

EU and EEA

Applies whenAn incident is also a personal data breach5.

  • Notify the supervisory authority and, where risk to individuals is high, the people affected, on GDPR's own timelines5.

A ninety-day NIS2 gap-assessment sequence

01Confirm scope02Assess against Article 2103Test reporting readiness04Prioritize gaps05Brief the board
  1. Confirm scope

    Entity classification, member states involved, main establishment and registration status.

  2. Assess against Article 21

    Rate each of the ten measures for design and evidence, by business service.

  3. Test reporting readiness

    Walk a scenario through the early warning and notification steps.

  4. Prioritize gaps

    Rank by exposure and supervisory attention, with owners and dates.

  5. Brief the board

    Approval of measures, oversight rhythm and management training plan.

Conceptual sequence of a gap assessment that ColdAI's regulatory compliance and cyber risk work supports. Durations vary with size and scope; it is not a measured result.

Questions and answers

Does NIS2 apply to companies based outside the EU?

It can. The Directive applies to in-scope entities that provide services or carry out activities in the EU, wherever they are headquartered. Certain digital providers not established in the EU but offering services there must designate a representative in a member state. Non-EU groups should map which subsidiaries operate in Annex I or II sectors, where each has its main establishment, and which national laws therefore apply.

Why do NIS2 obligations differ between EU countries?

NIS2 is a directive, so each member state writes its own law to implement it. National laws can add sectors, set higher fines, choose different authorities and registration portals, and phrase the measures more specifically. Organizations operating in several member states should identify which jurisdiction supervises them, generally linked to the main establishment for certain digital providers, and track each relevant national law.

Can managers be held personally liable under NIS2?

Article 20 says management bodies can be held liable for infringements of their duties to approve and oversee the risk-management measures, and Article 32 lets authorities of essential entities seek temporary bans on management functions in some circumstances. How liability works depends on national law. Directors should expect to show that they approved the measures, oversaw them and completed the required training.

Is a small supplier affected if it is not in scope itself?

Usually, yes, indirectly. In-scope customers must secure their supply chains, so they will push security clauses, assessments and incident notification terms into contracts with their suppliers. A small software or managed service provider may therefore need much of the same evidence, such as access control, vulnerability handling and incident response, to keep selling to regulated customers.

Sources

  1. Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive) — EUR-Lex · checked 10 October 2026
  2. NIS2 Directive: securing network and information systems — European Commission · checked 10 October 2026
  3. Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA) — EUR-Lex · checked 10 October 2026
  4. Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act) — EUR-Lex · checked 10 October 2026
  5. Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex · checked 10 October 2026

More in Risk & Resilience

Back to Risk & Resilience

Next step

Run a NIS2 gap assessment against your national law

Tell us which member states you operate in, your sectors and how your incident process works today. We will outline the scope questions to settle first and a gap-assessment plan, working alongside your counsel.

Plan a NIS2 assessment