Skip to content
You can now search across every topic, entity and event.What's new
Network and Information Systems
Technology

Network and Information Systems

EU cybersecurity law framework requiring critical-service operators to secure networks and report incidents to regulators.

From 1 June 2026, company directors in EU states that have transposed NIS2 can be fined personally for serious cybersecurity failures, even as the UK's own NIS-derived Cyber Security and Resilience Bill reached House of Lords committee stage on 23 July with several amendments still unresolved.

Last refreshed: 3 August 2026

Key Question

How many EU countries actually implemented the NIS2 cybersecurity rules on time?

Timeline for Network and Information Systems

#12 22 Jul
#7 1 Jun
#1 2 Mar

Mentioned in: UK 24-hour reporting bill at Report

Cybersecurity: Threats and Defences
View full timeline →

Background

The Network and Information Systems Directive is the EU's foundational cybersecurity legislation requiring operators of essential services and digital service providers to implement security measures and report incidents. Its 2022 revision, NIS2, significantly expanded scope and raised the fine ceiling to EUR15 million or 2.5 per cent of worldwide annual turnover. As of June 2025, only 14 of 27 EU member states had fully transposed NIS2; Germany published its transposition law on 5 December 2025 and required covered entities to register by 6 March 2026, with approximately one-third having actually registered by that date.

NIS was adopted in 2016 as the EU's first binding cybersecurity directive. NIS2 replaced it in December 2022, with a transposition Deadline of 17 October 2024 that most member states missed. It introduces new obligations including supply-chain risk management, vulnerability disclosure programmes, and executive accountability for cybersecurity governance. The Cyber Resilience Act operates in parallel with NIS2, covering product security requirements rather than operator obligations.

Key Issues
Personal liability

Its fines now reach directors personally

From 1 June 2026, company directors in EU countries that have transposed NIS2 can be fined personally at the full statutory rate for serious cybersecurity failures, a sharper enforcement edge than the corporate-only fines the directive originally carried. The European Commission also referred non-transposing member states to the EU Court of Justice the same month.

The timing is not coincidental: the EU's cybersecurity agency had already placed water, rail and waste water utilities in its highest-risk category, giving regulators a documented maturity gap in exactly the sectors where personal director liability is likely to see its earliest test cases.

UK Bill progress

Its UK cousin moves through the Lords

The UK Cyber Security and Resilience Bill, which extends the Network and Information Systems Regulations 2018 with wider incident-reporting duties, reached Report Stage on 2 March 2026, introducing a 24-hour initial incident-reporting window, a 72-hour full-report requirement, and classing data centres as essential services.

By 23 July the Bill had reached committee stage in the House of Lords, with a running amendment paper dated that day. Whether Lord Alton's proposed transnational-repression amendment was tabled, debated or adopted could not be confirmed from the published record, leaving that specific question open even as the Bill's core reporting duties continue their passage.

Common Questions

Reference

What is NIS2 and does it apply to my company?
NIS2 is the EU's 2022 cybersecurity directive requiring operators of essential services and digital service providers to implement security measures and report incidents. It applies to medium and large organisations in sectors including energy, transport, health, digital infrastructure and ICT services across EU member states.Source: European Commission
Which EU countries have actually implemented NIS2?
As of June 2025, only 14 of 27 EU member states had fully transposed NIS2. Germany's own transposition law took effect on 5 December 2025, requiring covered entities to register by 6 March 2026; roughly a third had registered by that date. The European Commission continues to run infringement proceedings against member states that have still not transposed the directive.Source: European Commission / briefing
Is NIS2 the same as the original NIS Directive?
No. NIS2, adopted in December 2022, replaced the 2016 NIS Directive with wider scope, higher fines of up to EUR15m or 2.5% of global turnover, and personal liability for management. NIS is the umbrella term for the overall EU framework; NIS2 is its current revision.Source: European Commission
What happens to EU member states that miss the NIS2 transposition deadline?
The European Commission refers under-transposing member states to the Court of Justice of the EU. As of 1 June 2026, more than 19 months after the October 2024 Deadline, member states still not transposed had been referred to the CJEU.Source: European Commission