temnir/

NIS2

NIS2, explained without the legalese.

NIS2 pulled thousands of mid-sized European companies into cybersecurity regulation for the first time, most of them without a security team. Here is what it is, whether it applies to you, and what you actually have to do.

What NIS2 actually is

NIS2 is Directive (EU) 2022/2555. It replaced the original 2016 NIS directive, entered into force on 16 January 2023, and member states had to write it into national law by 17 October 2024 and apply it from 18 October 2024.

One thing matters more than anything else on this page: NIS2 is a directive, not a regulation. It does not bind your company directly. Your obligations come from your own country’s transposing law, and those laws diverge in real ways: different names for the categories, different reporting routes, different deadlines. Always work from your national act, not from the directive alone.

Transposition has been slow. In July 2026 the Commission referred four member states to the Court of Justice for still not having transposed it.

Does it apply to you?

Two questions decide it: your sector and your size.

Sector. Annex I lists 11 "high criticality" sectors: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management (managed service and managed security providers), public administration, and space. Annex II adds 7 "other critical" sectors: postal and courier services, waste management, chemicals, food, manufacturing (medical devices, electronics, electrical equipment, machinery, motor vehicles, other transport equipment), digital providers (online marketplaces, search engines, social platforms), and research.

Size. Broadly you are in scope from medium-sized upward: at least 50 staff, or turnover above EUR 10 million and a balance sheet above EUR 10 million. You count as large at 250 staff or more, or turnover above EUR 50 million and a balance sheet above EUR 43 million. Partner and linked companies count toward your size, so a small subsidiary of a large group is often in scope.

Essential or important. Annex I entities above the size threshold are "essential". Everything else in scope is "important". The difference shows up in how you are supervised and in how large the fines can get.

Size does not always save you. Some entities are in scope whatever their size: DNS and TLD providers, trust service providers, providers of public electronic communications, public administration, and any company that is the sole provider in its country of a service that society or the economy depends on.

What it asks you to do

Governance. Your management body has to approve the risk-management measures, oversee them, and can be held liable for failures. Management must take training, and you have to offer training to staff regularly.

Risk management. Article 21 sets ten minimum measures: risk-analysis and information-system security policies; incident handling; business continuity and crisis management; supply-chain security; secure acquisition, development and maintenance, including vulnerability handling; procedures to assess whether your measures actually work; basic cyber hygiene and training; cryptography and encryption; human-resources security, access control and asset management; and multi-factor authentication and secured communications.

Incident reporting. This is the tightest clock: an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month. An incident is significant if it has caused, or could cause, severe operational disruption or financial loss, or considerable damage to others. Reporting does not by itself increase your liability.

Registration. Member states keep a list of the entities in scope, and most run a self-registration portal. Registration is usually what starts every other clock, which makes it the first thing to do rather than the last.

What happens if you ignore it

Essential entities face fines up to EUR 10 million or 2% of worldwide annual turnover, whichever is higher. Important entities face up to EUR 7 million or 1.4%. Those ceilings attach specifically to failures on risk management (Article 21) and reporting (Article 23).

Management can be held personally liable. You may also have read that directors can be banned from managing the company. That is real, but much narrower than the marketing usually suggests: it applies to essential entities only, and only as a last resort, after other enforcement has failed and a remediation deadline has been missed. If you are an important entity, it does not apply to you at all.

Where to start

  1. 01Check scope against your national law, not the directive, and count partner and linked companies toward your size.
  2. 02Register or notify. In most countries the initial deadline has already passed, so if you are in scope and unregistered, this is your first move. Filing late beats not filing.
  3. 03Know what you expose. You cannot do asset management, risk analysis or vulnerability handling on things you have not found yet.
  4. 04Get the 24-hour clock ready. The early warning is the binding constraint, and it needs an on-call path and a decision rule, not a policy document.
  5. 05Keep the evidence. An audit asks what you monitored and when, so the log matters as much as the fix.

Where we come in

Start with a free passive scan: we map what your company exposes to the internet and send you the short list of risks worth acting on. That is the raw material for the asset management, risk analysis and vulnerability handling Article 21 asks for. Module scry, module hex and module sigil then keep that surface watched, test it, and turn the monitoring into audit-ready evidence.

*Passive scan only. We never touch your systems. Free, no credit card, EU-hosted.

This page is general information, not legal advice. Your obligations come from your country’s transposing law. If you are near a threshold, check with your national authority or a lawyer.