NIS2 compliance:
who is in, and what it takes.
The NIS2 Directive widened EU cybersecurity law from a few critical operators to a large part of the economy, including many SaaS, cloud and managed service providers, and US companies selling into the EU. This guide covers scope, the Article 21 measures, reporting deadlines, fines and transposition as of October 2026. General guidance, not legal advice: the national law is what applies to you.
Last updated Published by TryTrustableNot legal advice
NIS2 compliance means meeting the EU's NIS2 Directive (Directive (EU) 2022/2555) as your member state has written it into national law. If you are a medium or large organisation in one of the sectors in its Annexes and you provide services in the EU, you are probably an essential or important entity. You must then take the risk-management measures in Article 21, have your management body approve and oversee them, register with the national authority, and report significant incidents: an early warning within 24 hours, a notification within 72 hours and a final report within one month.
What is the NIS2 Directive?
NIS2 is the EU's second Network and Information Security Directive, Directive (EU) 2022/2555. It replaced the 2016 NIS Directive and greatly widened its scope. Because it is a directive, it does not apply directly: each member state had to transpose it into national law by 17 October 2024 and apply those measures from 18 October 2024. The obligations that bind a company are therefore in its national law, which can go further than the Directive.
NIS2 applies to entities that provide services or carry out activities in the EU, so a US or UK company with EU customers in a covered sector can be in scope. The UK is outside NIS2 and has its own NIS Regulations 2018.
Who does NIS2 apply to? Essential vs important entities
As a rule, NIS2 covers public or private entities of a type listed in Annex I or Annex II that are at least medium-sized. Some, such as DNS service providers, TLD registries and trust service providers, are in scope regardless of size, and member states can designate smaller entities that are critical. Member states had to draw up a list of essential and important entities by 17 April 2025, and entities must register with the competent authority. Use our NIS2 applicability checker for a first answer.
| Essential entities | Important entities | |
|---|---|---|
| Who | Large entities (above the EU medium-sized enterprise ceilings) in Annex I sectors; qualified trust service providers, TLD registries and DNS service providers of any size; medium-sized or larger public electronic communications providers; certain public administration bodies; entities a member state designates as essential | Every other medium or large entity in an Annex I or Annex II sector, plus entities a member state designates as important |
| Supervision | Ex ante and ex post: authorities can audit and inspect without waiting for an incident | Ex post: authorities act when they have evidence or indication of non-compliance |
| Maximum fine (Article 34) | At least EUR 10 million or 2% of total worldwide annual turnover, whichever is higher | At least EUR 7 million or 1.4% of total worldwide annual turnover, whichever is higher |
| Management | Members of management can be temporarily banned from managerial functions if enforcement measures are ineffective (Article 32(5)) | Management bodies approve, oversee and can be held liable (Article 20), as for essential entities |
"At least" is deliberate: the Directive sets the minimum for the maximum fine; national law can set it higher.
Which sectors are covered by NIS2?
| Annex I: sectors of high criticality | Annex II: other critical sectors |
|---|---|
| Energy; transport; banking; financial market infrastructures; health; drinking water; waste water; digital infrastructure (including cloud computing, data centres, content delivery networks, DNS, TLD registries, trust services, public electronic communications); ICT service management, business to business (managed service providers and managed security service providers); public administration; space | Postal and courier services; waste management; chemicals; food; manufacturing (including medical devices, computers and electronics, machinery, motor vehicles); digital providers (online marketplaces, online search engines, social networking platforms); research |
Size counts under the EU SME Recommendation 2003/361/EC: medium-sized means 50 or more staff, or more than EUR 10 million annual turnover and balance sheet. Some entities are in scope regardless of size.
NIS2 requirements: the Article 21 measures
Article 21 is the core of NIS2 compliance. It requires an all-hazards approach and lists ten minimum measures. For cloud, data centre, managed service and other digital infrastructure providers, the Commission has adopted an implementing regulation (Implementing Regulation (EU) 2024/2690) setting more detailed technical requirements.
| Article 21(2) | Measure | What auditors and authorities will look for |
|---|---|---|
| (a) | Policies on risk analysis and information system security | A risk assessment and an approved security policy |
| (b) | Incident handling | An incident response plan that has been used or exercised |
| (c) | Business continuity: backup management, disaster recovery, crisis management | Tested restores and a continuity plan |
| (d) | Supply chain security, including relationships with direct suppliers | A supplier register, risk tiers, contract terms |
| (e) | Security in acquisition, development and maintenance, including vulnerability handling and disclosure | Secure development practice, vulnerability management, a disclosure route |
| (f) | Policies and procedures to assess the effectiveness of the measures | Internal audit, control testing, metrics |
| (g) | Basic cyber hygiene practices and cybersecurity training | Training records, hardening baselines |
| (h) | Cryptography and, where appropriate, encryption | An encryption policy and evidence it is applied |
| (i) | Human resources security, access control policies and asset management | Joiner-mover-leaver process, access reviews, asset inventory |
| (j) | Multi-factor or continuous authentication, secured voice, video and text, secured emergency communications | MFA coverage, approved communication tools |
Article 21(1) requires measures that are appropriate and proportionate to the risk, taking account of the state of the art, relevant standards and cost.
Management accountability under Article 20
The management body must approve the Article 21 measures, oversee their implementation and can be held liable for infringements. Its members must also follow cybersecurity training. In practice this means minuted approval of the security programme, regular reporting to the board, and training records for directors, not just for staff.
NIS2 incident reporting: 24 hours, 72 hours, one month
| Deadline | What | Article |
|---|---|---|
| Within 24 hours of becoming aware | Early warning: whether the incident is suspected to be malicious or could have cross-border impact | 23(4)(a) |
| Within 72 hours of becoming aware | Incident notification: an update, an initial assessment of severity and impact, indicators of compromise where available | 23(4)(b) |
| On request | Intermediate report on status updates | 23(4)(c) |
| Within one month of the notification | Final report: detailed description, root cause, mitigation, cross-border impact (a progress report instead if the incident is still ongoing) | 23(4)(d) and (e) |
Reports go to the national CSIRT or competent authority. A significant incident is one that has caused or can cause severe operational disruption or financial loss, or considerable damage to others (Article 23(3)). Service recipients may also need to be told.
If the incident also involves personal data, the GDPR's 72-hour notice to the data protection authority under Article 33 runs alongside. Our breach deadline calculator and incident response plan template help you plan both.
NIS2 fines and enforcement
For breaches of Article 21 or 23, essential entities face a maximum fine of at least EUR 10 million or 2% of total worldwide annual turnover, and important entities at least EUR 7 million or 1.4%, whichever is higher in each case. Authorities can also issue binding instructions, order audits, require public disclosure of an infringement and, for essential entities whose enforcement measures have failed, seek a temporary suspension of certifications or a temporary ban on a chief executive or legal representative.
NIS2 transposition status by member state (October 2026)
The deadline was 17 October 2024 and most member states missed it. On 7 May 2025 the European Commission sent reasoned opinions to 19 member states for failing to notify full transposition. On 8 July 2026 it referred four of them, Ireland, Spain, France and the Netherlands, to the Court of Justice of the EU for failing to notify transposition measures, and said most member states had complied.
What we could and could not confirm on 6 October 2026:
- Ireland, Spain, France, the Netherlands: not transposed as of the 8 July 2026 referral. France's cybersecurity agency ANSSI still refers to a draft law; we could not confirm whether any of the four has adopted its law since July.
- The other 23 member states: the Commission indicates they have notified transposition measures, but we have not verified each national law, its entry into force or its registration deadlines one by one.
- Where your entity sits: generally the member state where you are established; many digital infrastructure and digital providers fall under the member state of their main establishment in the EU, and those based outside the EU must designate a representative.
Check the Commission's NIS2 transposition page and your national authority before relying on any date. Where a national law is not yet in force, the Directive's requirements are still the best guide to what will be asked.
NIS2 compliance checklist
- Confirm whether you are in scope, and whether as essential or important, in each member state you serve.
- Register with the competent authority where your national law requires it.
- Run a risk assessment and get the management body to approve the security measures.
- Gap-assess against Article 21(2)(a) to (j), and the implementing regulation if you are a digital provider.
- Put the 24-hour, 72-hour and one-month reporting into your incident plan, with named people and the CSIRT contact.
- Tier your suppliers and add security terms to critical contracts.
- Train the management body and staff, and keep the records.
- Test effectiveness: internal audit, control monitoring, exercises.
If you already hold ISO 27001 or a SOC 2 report, much of Article 21 is covered by controls you run; the gaps are usually management accountability, the reporting timelines and registration. Financial entities should read our DORA guide: where DORA applies, its ICT risk and reporting rules take precedence over NIS2's.
NIS2 compliance with TryTrustable
NIS2 is one of the frameworks with requirements modelled in the platform. Here is what it does today and what it leaves to you.
| In TryTrustable | What it does today |
|---|---|
| NIS2 modelled | Requirements for Article 20 governance, each Article 21(2) measure (a) to (j), Article 23 reporting, registration and coordinated vulnerability disclosure |
| Shared controls | Each requirement maps to controls in the same library as ISO 27001, SOC 2 and GDPR, so work you have done for those counts. See cross-framework mapping |
| Incident clocks | Incident management shows the NIS2 24-hour early warning and 72-hour notification deadlines, marked as applying only if the incident is significant and you are in scope |
| Supply chain | A vendor register with tiers, reviews and evidence on file, for Article 21(2)(d) |
| Evidence | Automatic, read-only evidence from GitHub, AWS and GCP into a hash-chained evidence ledger; the rest is uploaded by your team |
| Not done | The platform does not decide whether you are in scope, register you with an authority or file reports with a CSIRT |
NIS2 requirements are modelled at the level of the Directive. Your national law may add detail; check it.
The things people ask us
Does NIS2 apply to US companies?
It can. NIS2 applies to entities that provide services or carry out activities in the EU. A US company of medium size or larger in a covered sector with EU customers may be in scope, and certain digital providers established outside the EU must designate a representative in a member state.
What is the difference between essential and important entities?
Essential entities are mainly large organisations in the Annex I sectors plus some providers in scope regardless of size. Other medium and large entities in Annex I or II are important. Essential entities face proactive supervision and higher maximum fines; important entities are supervised after the fact.
What are the NIS2 reporting deadlines?
An early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month of the notification.
What are the NIS2 fines?
At least EUR 10 million or 2% of worldwide annual turnover for essential entities, and at least EUR 7 million or 1.4% for important entities, whichever is higher. National law can set higher maximums.
Has every EU country transposed NIS2?
No. In July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify transposition measures. Check your national authority for the current status.
Is ISO 27001 enough for NIS2?
It covers much of Article 21, but not everything: NIS2 adds management body approval and training, registration, and fixed incident reporting deadlines to the CSIRT.
Does TryTrustable support NIS2?
Yes. NIS2 requirements are modelled and mapped to the shared control library, and incident management shows the 24-hour and 72-hour clocks. The platform does not determine scope or file reports for you.
See your NIS2 gaps on the controls you already run.
Thirty minutes: Article 21 against your ISO 27001 or SOC 2 controls, and the reporting clocks in your incident plan.