
Network and Information Systems
EU cybersecurity law framework requiring critical-service operators to secure networks and report incidents to regulators.
From 1 June 2026, company directors in EU states that have transposed NIS2 can be fined personally for serious cybersecurity failures, even as the UK's own NIS-derived Cyber Security and Resilience Bill reached House of Lords committee stage on 23 July with several amendments still unresolved.
Last refreshed: 3 August 2026
How many EU countries actually implemented the NIS2 cybersecurity rules on time?
Timeline for Network and Information Systems
Mentioned in: Cyber resilience bill at Lords committee
Cybersecurity: Threats and DefencesMentioned in: NIS2 fines now reach directors personally
Cybersecurity: Threats and DefencesMentioned in: UK 24-hour reporting bill at Report
Cybersecurity: Threats and DefencesBackground
The Network and Information Systems Directive is the EU's foundational cybersecurity legislation requiring operators of essential services and digital service providers to implement security measures and report incidents. Its 2022 revision, NIS2, significantly expanded scope and raised the fine ceiling to EUR15 million or 2.5 per cent of worldwide annual turnover. As of June 2025, only 14 of 27 EU member states had fully transposed NIS2; Germany published its transposition law on 5 December 2025 and required covered entities to register by 6 March 2026, with approximately one-third having actually registered by that date.
NIS was adopted in 2016 as the EU's first binding cybersecurity directive. NIS2 replaced it in December 2022, with a transposition Deadline of 17 October 2024 that most member states missed. It introduces new obligations including supply-chain risk management, vulnerability disclosure programmes, and executive accountability for cybersecurity governance. The Cyber Resilience Act operates in parallel with NIS2, covering product security requirements rather than operator obligations.
Its fines now reach directors personally
From 1 June 2026, company directors in EU countries that have transposed NIS2 can be fined personally at the full statutory rate for serious cybersecurity failures, a sharper enforcement edge than the corporate-only fines the directive originally carried. The European Commission also referred non-transposing member states to the EU Court of Justice the same month.
The timing is not coincidental: the EU's cybersecurity agency had already placed water, rail and waste water utilities in its highest-risk category, giving regulators a documented maturity gap in exactly the sectors where personal director liability is likely to see its earliest test cases.
Its UK cousin moves through the Lords
The UK Cyber Security and Resilience Bill, which extends the Network and Information Systems Regulations 2018 with wider incident-reporting duties, reached Report Stage on 2 March 2026, introducing a 24-hour initial incident-reporting window, a 72-hour full-report requirement, and classing data centres as essential services.
By 23 July the Bill had reached committee stage in the House of Lords, with a running amendment paper dated that day. Whether Lord Alton's proposed transnational-repression amendment was tabled, debated or adopted could not be confirmed from the published record, leaving that specific question open even as the Bill's core reporting duties continue their passage.