Skip to content
CyberNIS2
EU Directive 2022/2555

NIS and NIS 2 — What is it?

Everything you need to know about the European directive on the security of network and information systems, and its evolution into NIS 2.

Am I affected? Take the testPersonalised diagnosis · 2 minutes

1The NIS directive (2016)

The NIS (Network and Information Security) directive, adopted in July 2016, was the first European legislation dedicated to cybersecurity. It aimed to achieve a common high level of security of network and information systems across the European Union.

It required Operators of Essential Services (OES) and Digital Service Providers (DSPs) to implement security measures and report major incidents.

Limitations of NIS 1: too narrow scope, heterogeneous transpositions across Member States, insufficient security requirements in the face of rising cyber threats.

2The NIS 2 directive (2022)

The NIS 2 directive (EU 2022/2555), published on 27 December 2022 and entering into force on 16 January 2023, repeals and replaces NIS 1. Member States had until 17 October 2024 to transpose it into national law.

NIS 2 marks a major qualitative leap: broader scope, stronger obligations, stricter penalties, and direct accountability for management bodies.

Broader scope

From a few hundred OES to several thousand entities covered across 18 sectors.

Stricter penalties

Up to €10 M or 2% of global turnover for essential entities; €7 M or 1.4% for important entities.

Strict deadlines

Incident notification: 24h (early warning), 72h (initial notification), 1 month (final report).

Who is affected?

NIS 2 distinguishes two categories of entities based on their size and sector. The main criterion is exceeding thresholds of 250 employees or €50 M turnover / €43 M balance sheet for essential entities, and 50 employees or €10 M for important entities.

Essential entities
  • Energy (electricity, gas, oil, hydrogen)
  • Transport (air, rail, maritime, road)
  • Banking sector
  • Financial market infrastructures
  • Health (hospitals, laboratories, R&D)
  • Drinking water
  • Wastewater
  • Digital infrastructure (DNS, IXP, cloud, datacentres…)
  • ICT service management (B2B)
  • Public administrations
  • Space
Important entities
  • Postal and courier services
  • Waste management
  • Manufacture, production and distribution of chemicals
  • Production, processing and distribution of food
  • Manufacturing (medical devices, machinery, vehicles…)
  • Digital providers (online marketplaces, social networks, search engines…)
  • Research

Exception: certain entities are covered regardless of their size (e.g.: providers of public electronic communications networks, public administrations, entities critical under other EU regulations).

Key obligations

NIS 2 imposes a minimum baseline of cybersecurity measures for all covered entities.

Cyber risk management

Implement proportionate technical and organisational measures to manage the risks to the security of networks and information systems.

Incident notification

Report any significant incident to the competent authority within strict deadlines: early warning within 24h, notification within 72h, final report within one month.

Supply chain security

Assess and manage risks related to suppliers and service providers who have access to your systems or data.

Management accountability

Governing bodies must approve cyber risk management measures and can be held personally liable for failures.

Business continuity

Maintain business continuity and recovery plans to keep essential services running in the event of a cyber crisis.

Training and awareness

Regularly train all members of the organisation, including management, on cybersecurity best practices.

NIS 1 vs NIS 2 — Key differences

CriterionNIS 1NIS 2
Sectors covered7 sectors18 sectors
Entities targetedA few hundred (OES)Several thousand
Management liabilityNot providedYes, mandatory engagement
Supply chainNot providedObligation to secure
Notification deadline"Without undue delay"24h / 72h / 1 month
Max. penaltyVaries by State€10 M or 2% of global turnover
EU harmonisationWeakStrengthened

Are you affected by NIS 2?

Answer a few questions to get a personalised diagnosis of your regulatory situation.