Skip to content
You can now search across every topic, entity and event.What's new
NIS2
LegislationEU

NIS2

EU Directive 2022/2555 mandating cybersecurity obligations across essential and important entities in 18 sectors.

ENISA's NIS360 report placed water, waste water and railway in its cyber risk zone for the first time on 28 May 2026, giving national regulators a documented capability gap to enforce against under NIS2.

Last refreshed: 3 August 2026 · Appears in 2 active topics

Key Question

Does ENISA's NIS360 risk-zone data give regulators their first direct enforcement target?

Timeline for NIS2

#12 29 Jul
#10 14 Jul
#7 10 Jun

Mentioned in: UK cyber bill drops payment regime

Cybersecurity: Threats and Defences
#8 3 Jun

Identified as a sector caught by CADA Level 2-4 obligations per Wilson Sonsini analysis

European Tech Sovereignty: Brussels adopts CADA, narrows its scope
#7 1 Jun

Reached full personal-liability enforcement force on 1 June 2026 in transposed member states

Cybersecurity: Threats and Defences: NIS2 fines now reach directors personally
View full timeline →

Background

The Network and Information Security Directive 2 (NIS2, Directive (EU) 2022/2555) entered into force on 16 January 2023, replacing the 2016 NIS Directive with a substantially wider scope. It covers essential entities (energy, transport, banking, health, drinking water, waste water, digital infrastructure, public administration, space) and important entities (postal, waste management, chemicals, food, manufacturing) above 50 employees or EUR10m turnover.

Key obligations include 24-hour Early Warning and 72-hour full notification of significant incidents, board-level accountability with individual liability, supply-chain risk-management duties, and minimum technical controls. Fine ceilings reach EUR10m or 2% of global turnover for essential entities, EUR7m or 1.4% for important ones, materially above the original Directive's maxima.

NIS2's transposition has lagged badly: only 14 of 27 states had fully implemented it by mid-2025, prompting Commission infringement proceedings that had reached reasoned opinions against 19 states by April 2026. ENISA's NCAF 2.0 (April 2026) and NIS360 (May 2026) reports have converted that political pressure into named, sector-level maturity scores, making NIS2 compliance an active audit cycle rather than a missed 2024 Deadline.

Key Issues
NIS2 enforcement

Enforcement gap narrows on paper

NIS2 (Directive (EU) 2022/2555) has been in force since January 2023, but only 14 of 27 member states had fully transposed it by mid-2025, and the European Commission had escalated infringement action to reasoned opinions against 19 states by April 2026 . From 1 June 2026, directors in transposing states face personal fines for serious failures, and the Commission has begun referring non-transposing states to the Court of Justice.

ENISA's 28 May NIS360 report sharpened the picture further, putting railway, drinking water and waste water into its risk zone for the first time, with one in three water entities never having run a risk assessment . That gives national competent authorities a named, sector-specific audit target well before every member state has even finished transposing the underlying law.

Common Questions

Reference

How long do organisations have to report a cyber incident under NIS2?
Organisations must send an Early Warning to their national competent authority within 24 hours of becoming aware of a significant incident, followed by a full notification within 72 hours, and a final report within one month.Source: Directive (EU) 2022/2555 Article 23
How does NIS2 affect company boards and executives?
NIS2 introduces individual liability for senior management: boards must approve cybersecurity risk-management measures and can be held personally liable for violations. Executives may face temporary bans from management roles if an essential entity breaches its obligations.Source: Directive (EU) 2022/2555 Article 20
What are the NIS2 fines for non-compliance?
Essential entities face fines of up to €10m or 2% of global annual turnover, whichever is higher. Important entities face up to €7m or 1.4% of global annual turnover.Source: Directive (EU) 2022/2555 Article 34
What is the NIS2 Directive and who does it apply to?
NIS2 (Directive (EU) 2022/2555) is the EU's core cybersecurity law. It applies to essential entities (energy, transport, health, digital infrastructure, etc.) and important entities (manufacturing, postal, chemicals, food, etc.) above 50 employees or €10m turnover in 27 EU member states.Source: EUR-Lex
Which EU countries have not yet implemented NIS2?
As of April 2026, 19 member states remain under European Commission reasoned opinions for partial or no transposition. Only 14 of 27 had fully transposed by mid-2025; Germany, the Netherlands, and Croatia were among the early movers.Source: ENISA
Source Material