The scale of expansion relative to the original directive is significant. Where NIS1 covered approximately seven sectors, NIS2 extends across 18 sectors. It is estimated to bring over 100,000 organisations across the EU within scope for the first time. It also introduces personal management liability for compliance failures, which represents a materially different accountability structure from what most organisations have previously faced for cybersecurity obligations.
Understanding NIS2 accurately is important for organisations that may be in scope, for those assessing whether their suppliers are in scope, and for boards whose members may face direct personal obligations under the directive's management accountability provisions.
NIS2 introduces a size-based threshold that determines which organisations fall within scope. In general, medium and large enterprises operating in the covered sectors are in scope. A medium enterprise is defined as one with at least 50 employees and annual turnover or balance sheet total exceeding 10 million euros. A large enterprise has at least 250 employees and annual turnover exceeding 50 million euros or a balance sheet total exceeding 43 million euros.
This size threshold means that smaller organisations in covered sectors may not face direct NIS2 obligations, though they may face indirect pressure through supply chain requirements imposed by larger in-scope entities.
Some categories of entity are in scope regardless of size because of the critical nature of their services. These include providers of public electronic communications networks and services, trust service providers, top-level domain name registries, and DNS service providers.
NIS2 organises covered sectors into two annexes.
Annex I covers sectors of high criticality: energy (covering electricity, oil, gas, hydrogen, and district heating), transport (air, rail, water, and road), banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure (including internet exchange points, DNS service providers, cloud computing service providers, data centre service providers, and content delivery networks), ICT service management in a business-to-business context, public administration, and space.
Annex II covers other critical sectors: postal and courier services, waste management, manufacture, production, and distribution of chemicals, production, processing, and distribution of food, manufacturing of medical devices, computers, electronics, machinery, motor vehicles, and other transport equipment, digital providers (online marketplaces, online search engines, and social networking platforms), and research organisations.
Organisations in Annex I sectors that meet the large enterprise threshold are generally classified as essential entities. Medium enterprises in Annex I sectors, and both large and medium enterprises in Annex II sectors, are generally classified as important entities. The classification affects supervisory intensity.
The distinction between essential and important entities primarily affects how they are supervised rather than what they are required to do. The security measures required under Article 21 apply to both categories. The differences lie in the supervision model.
Essential entities are subject to proactive, ex ante supervision. National competent authorities can conduct regular audits, targeted security audits, and on-site inspections without waiting for a specific incident or complaint to trigger action.
Important entities are subject to reactive, ex post supervision. They face supervisory scrutiny primarily when they are suspected of breaching their NIS2 obligations, following a significant incident, or when a complaint is received. This does not mean important entities are unsupervised; it means the trigger for formal supervisory action differs.
Essential entities face maximum administrative fines of at least 10 million euros or 2% of total worldwide annual turnover, whichever is higher. Important entities face maximum fines of at least 7 million euros or 1.4% of total worldwide annual turnover.
The management liability provisions apply to both categories. Senior management of both essential and important entities can be held personally liable where non-compliance results from their failure to implement adequate security measures or to adequately oversee the organisation's NIS2 compliance. Member States may allow competent authorities to temporarily ban individuals from management positions in the case of repeated or severe NIS2 breaches.
Article 21 of NIS2 requires in-scope entities to implement appropriate and proportionate technical, operational, and organisational measures to manage the risks posed to the security of their network and information systems. The measures must be based on a risk assessment approach and must cover at least ten specified areas.
Entities must have documented policies covering risk analysis and information security. This includes having a current assessment of the risks to network and information systems and policies that define how those risks are managed. The policies cannot be static documents. They must be kept current and must genuinely reflect the organisation's actual security practices.
Entities must have established processes for handling security incidents, including detection, response, recovery, and communication. The incident handling process must be capable of operating under the NIS2 notification timelines described below. Processes designed after an incident occurs will not meet this requirement.
Entities must implement business continuity management covering backup management, disaster recovery, and crisis management. The NIS2 requirements here connect directly to the operational resilience disciplines: continuity plans must address how the important services the entity provides would be maintained or restored following a significant security incident.
Supply chain security is one of the most practically significant requirements in Article 21. Entities must address security in the relationships with direct suppliers and service providers. This includes considering the specific vulnerabilities of each supplier, the overall quality of products and security practices of the supplier, and where relevant, the availability of secure products and cybersecurity practices.
The supply chain security requirement does not extend automatically to fourth-party risk, but where suppliers use sub-processors or sub-contractors that support critical services, those relationships should be within scope of the entity's supply chain security assessment.
The remaining Article 21 requirements cover: security in network and systems acquisition, development, and maintenance; policies and procedures to assess the effectiveness of cybersecurity risk management measures; basic cyber hygiene practices and cybersecurity training; policies and procedures for the use of cryptography and, where appropriate, encryption; human resources security, access control policies, and asset management; and the use of multi-factor authentication or continuous authentication solutions, secured voice, video, and text communications, and secured emergency communication systems.
The principle of proportionality applies throughout. Measures should be appropriate to the organisation's size, the nature of its activities, and the risks it faces. A small entity in a less critical sector is not expected to implement the same level of technical measures as a major financial infrastructure provider.
NIS2 requires entities to notify competent authorities of significant incidents. An incident is significant if it causes, or has the potential to cause, severe operational disruption of the services or financial loss for the entity, or where it has caused or could cause considerable material or non-material damage to other natural or legal persons.
National transpositions may define additional criteria. The key practical point is that the determination of whether an incident meets the significance threshold must be made promptly after detection, because the notification timelines run from that determination.
An early warning must be provided to the competent authority without undue delay and in any event within 24 hours of becoming aware of the significant incident. This early warning should indicate whether the incident is suspected to result from unlawful or malicious acts and whether it is likely to have cross-border impact.
A full incident notification must be provided within 72 hours of becoming aware of the incident. This notification should update the information in the early warning and provide an initial assessment of the incident including its severity and impact, and where available, indicators of compromise.
A final report must be submitted within one month of the full notification. The final report should provide a detailed description of the incident including its severity and impact, the type of threat or root cause that is likely to have triggered the incident, the applied and ongoing mitigation measures, and where applicable, the cross-border impact.
For significant incidents that are ongoing at the time of the one-month deadline, entities should provide a progress report at that stage and a final report within one month of the incident being handled.
Unlike DORA, which is an EU regulation applying directly and uniformly across all Member States, NIS2 is a directive that each Member State transposes into its own national legislation. This means that while the core framework is consistent across the EU, there may be variation in specific definitions, penalty levels, enforcement approaches, and additional requirements introduced by individual Member States.
Organisations operating across multiple EU Member States need to understand the national transposition in each jurisdiction rather than assuming uniform application of the NIS2 text. National cybersecurity authorities (NCAs) publish their national transposition legislation and, typically, accompanying guidance.
For financial entities, NIS2 sits alongside DORA rather than superseding it. DORA is the lex specialis for the financial sector, meaning that where DORA sets more specific or more demanding requirements than NIS2, DORA takes precedence for financial entities within its scope. Financial entities are not required to comply with NIS2 separately where DORA covers the same ground more specifically.
However, NIS2 remains relevant for financial sector organisations in areas not covered by DORA, and the two frameworks cover substantially overlapping ground. Building cybersecurity and resilience governance that satisfies the more demanding of the two frameworks, where they differ, is generally more efficient than maintaining separate compliance programmes for each.