
NIS2
EU Directive 2022/2555 mandating cybersecurity obligations across essential and important entities in 18 sectors.
ENISA's NIS360 report placed water, waste water and railway in its cyber risk zone for the first time on 28 May 2026, giving national regulators a documented capability gap to enforce against under NIS2.
Last refreshed: 3 August 2026 · Appears in 2 active topics
Does ENISA's NIS360 risk-zone data give regulators their first direct enforcement target?
Timeline for NIS2
Mentioned in: Water plants told to unplug controllers
Cybersecurity: Threats and DefencesMentioned in: UK cyber bill hits Lords with £17m cap
Cybersecurity: Threats and DefencesMentioned in: UK cyber bill drops payment regime
Cybersecurity: Threats and DefencesIdentified as a sector caught by CADA Level 2-4 obligations per Wilson Sonsini analysis
European Tech Sovereignty: Brussels adopts CADA, narrows its scopeReached full personal-liability enforcement force on 1 June 2026 in transposed member states
Cybersecurity: Threats and Defences: NIS2 fines now reach directors personallyBackground
The Network and Information Security Directive 2 (NIS2, Directive (EU) 2022/2555) entered into force on 16 January 2023, replacing the 2016 NIS Directive with a substantially wider scope. It covers essential entities (energy, transport, banking, health, drinking water, waste water, digital infrastructure, public administration, space) and important entities (postal, waste management, chemicals, food, manufacturing) above 50 employees or EUR10m turnover.
Key obligations include 24-hour Early Warning and 72-hour full notification of significant incidents, board-level accountability with individual liability, supply-chain risk-management duties, and minimum technical controls. Fine ceilings reach EUR10m or 2% of global turnover for essential entities, EUR7m or 1.4% for important ones, materially above the original Directive's maxima.
NIS2's transposition has lagged badly: only 14 of 27 states had fully implemented it by mid-2025, prompting Commission infringement proceedings that had reached reasoned opinions against 19 states by April 2026. ENISA's NCAF 2.0 (April 2026) and NIS360 (May 2026) reports have converted that political pressure into named, sector-level maturity scores, making NIS2 compliance an active audit cycle rather than a missed 2024 Deadline.
Enforcement gap narrows on paper
NIS2 (Directive (EU) 2022/2555) has been in force since January 2023, but only 14 of 27 member states had fully transposed it by mid-2025, and the European Commission had escalated infringement action to reasoned opinions against 19 states by April 2026 . From 1 June 2026, directors in transposing states face personal fines for serious failures, and the Commission has begun referring non-transposing states to the Court of Justice.
ENISA's 28 May NIS360 report sharpened the picture further, putting railway, drinking water and waste water into its risk zone for the first time, with one in three water entities never having run a risk assessment . That gives national competent authorities a named, sector-specific audit target well before every member state has even finished transposing the underlying law.