AuditXYZ

Compliance Framework

Directive (EU) 2022/2555 — Network and Information Security Directive 2 (NIS2) (NIS2)

NIS2 is the EU directive expanding cybersecurity obligations to more sectors and introducing stricter incident reporting. Learn who it affects and what compliance requires.

$30,000–$250,0006–18 monthsAudit Required2022
Issuing BodyEuropean Parliament and Council of the European Union
First Published2022-12-27
Latest Version2022
Typical Cost$30,000–$250,000
Typical Timeline6–18 months
Audit RequiredYes
Audit FrequencyEssential entities subject to proactive supervisory audits. Important entities subject to reactive supervision upon evidence of non-compliance.
Geographyeuropean-union, eea

NIS2 Directive: EU Cybersecurity Regulation Guide

The NIS2 Directive is the European Union's updated cybersecurity legislation, significantly expanding the scope and stringency of the original 2016 NIS Directive. It establishes cybersecurity risk management and incident reporting obligations for organizations across a wide range of critical and important sectors.

What NIS2 Covers

NIS2 mandates that covered entities implement appropriate and proportionate cybersecurity risk management measures. Specific requirements include risk analysis policies, incident handling procedures, business continuity management, supply chain security, vulnerability management, cybersecurity testing, cryptography policies, human resource security, access control, and asset management.

The directive introduces a tiered incident reporting regime: a 24-hour early warning to the relevant CSIRT, a 72-hour incident notification with initial assessment, and a final report within one month.

Who NIS2 Affects

NIS2 dramatically expanded its scope compared to the original directive. It covers two categories:

Essential entities — Large organizations in high-criticality sectors including energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space.

Important entities — Medium and large organizations in sectors such as postal services, waste management, chemicals manufacturing, food production, medical device manufacturing, digital providers, and research organizations.

Organizations with 50+ employees or EUR 10M+ turnover in covered sectors are generally in scope. Member states may also designate smaller entities as in scope based on criticality.

Compliance Requirements

  1. Self-assessment — Determine if your organization falls under NIS2 scope
  2. Register — Essential and important entities must register with relevant national authorities
  3. Risk management measures — Implement the cybersecurity measures specified in Article 21
  4. Incident reporting — Establish processes for the 24-hour/72-hour/1-month reporting regime
  5. Supply chain security — Assess and manage risks from suppliers and service providers
  6. Management accountability — Ensure management bodies approve and oversee cybersecurity measures
  7. Training — Provide regular cybersecurity training including for management bodies

Enforcement and Penalties

NIS2 introduced significant penalties: up to EUR 10 million or 2% of worldwide annual turnover for essential entities, and EUR 7 million or 1.4% of turnover for important entities. Management bodies can be held personally liable for compliance failures, marking a notable escalation from the original directive.

National Transpositions and Current Status

NIS2 required EU member states to transpose it into national law by October 17, 2024. National transposition is now substantially complete across EU member states, though implementation details and enforcement approaches vary. France, Germany, the Netherlands, and most northern European states have active national frameworks. Some southern European member states completed later transpositions into early 2025.

This means NIS2 obligations are active. Organizations that have been waiting for national clarity should be implementing now, not planning to start when the dust settles.

Key Requirements Under Article 21 Explained

Risk analysis and information security policies — Covered entities must have documented risk management processes and security policies approved at management body level. Risk assessments should be reviewed at least annually and following significant incidents or changes.

Incident handling — The three-tier reporting timeline is a hard requirement: a 24-hour early warning to your national CSIRT, a 72-hour incident notification with initial assessment and severity evaluation, and a final report within one month. Missing these deadlines is itself a compliance violation separate from the underlying incident.

Business continuity and crisis management — Entities must have documented plans for maintaining services during significant incidents, including backup management, disaster recovery, and crisis management procedures. For essential entities, these plans must be tested.

Supply chain security — Article 21 explicitly requires management of security risks in supplier and service provider relationships. This is one of the most operationally demanding requirements — you must assess the security posture of your ICT supply chain and document your risk management approach.

Vulnerability handling and disclosure — Covered entities must have processes for identifying, assessing, and remediating vulnerabilities. Coordinated vulnerability disclosure programs (CVD) are encouraged and increasingly expected.

Cybersecurity training — Both staff and management bodies must receive cybersecurity training appropriate to their roles. NIS2 makes management body cybersecurity knowledge a governance expectation, not just an operational one.

Cryptography and encryption — Policies on the use of cryptography, including encryption of data in transit and at rest, must be documented and implemented.

Multi-factor authentication and secure communications — MFA must be implemented for access to networks and information systems. Secure communications (encrypted channels) must be used for sensitive internal communications.

The Management Body Liability Dimension

NIS2 introduced a significant escalation in personal accountability. Management bodies (boards of directors, executive management) can be held personally liable for non-compliance. This means that directors who were unaware of or failed to oversee NIS2 compliance may face personal sanctions.

Practically, this requires:

  • Board-level awareness training on NIS2 obligations
  • Formal board approval of cybersecurity risk management policies
  • Regular board reporting on cybersecurity posture and incident status
  • Documentation showing board oversight of the compliance program

This is a material change from the original NIS Directive and should trigger escalation of NIS2 compliance to the board agenda if it has not already happened.

How to Determine Your Entity Classification

Step 1 — Identify whether your sector is listed in Annex I (high criticality) or Annex II (other critical sectors) of the NIS2 Directive.

Step 2 — Apply the size thresholds. Essential entities are generally large organizations (250-plus employees or EUR 50M-plus annual turnover) in high-criticality sectors. Important entities include medium organizations (50 to 249 employees or EUR 10M to EUR 50M turnover) in covered sectors.

Step 3 — Check national transposition for sector-specific rules. Some member states have designated smaller organizations as essential entities based on criticality assessments, overriding the general size thresholds.

Step 4 — Register with your national competent authority as required by your member state's implementing legislation.

Costs and Timeline

ComponentLow EstimateHigh Estimate
Scoping and classification assessment$5,000$20,000
Gap assessment against Article 21$10,000$30,000
Risk management and policy implementation$20,000$80,000
Incident response process development$10,000$30,000
Supply chain security program$10,000$50,000
Ongoing compliance management$15,000$60,000
Total first-year$70,000$270,000

Timeline: 6 to 18 months for initial implementation. Organizations with mature ISO 27001 programs trend significantly lower.

NIS2 vs. ISO 27001 — Approximately 70% overlap. ISO 27001 is the most commonly referenced implementation framework for NIS2 Article 21 measures. ENISA explicitly acknowledges ISO 27001 as an appropriate framework for NIS2 compliance. Organizations with ISO 27001 certification have the strongest foundation for demonstrating NIS2 compliance.

NIS2 vs. DORADORA is a sector-specific EU regulation for financial entities that operates in parallel with NIS2. Financial entities subject to both must address DORA's more detailed requirements while also satisfying the NIS2 framework. Where requirements conflict, DORA's more specific requirements typically take precedence.

NIS2 vs. GDPR — NIS2 addresses cybersecurity of networks and information systems; GDPR addresses personal data protection. They are complementary EU regulations with some overlap in incident notification requirements. Organizations subject to both must manage NIS2 incident reports to national CSIRTs alongside GDPR breach notifications to supervisory authorities.

How Automation Helps

NIS2's ongoing monitoring and reporting requirements — continuous risk assessment updates, supply chain security tracking, and the strict incident notification timelines — are extremely difficult to manage without tooling. Manual processes are too slow to meet 24-hour early warning requirements.

LowerPlane supports NIS2 compliance monitoring across its 50-plus framework library, providing continuous control monitoring, incident tracking workflows, and supply chain risk management features. At $4,000/year entry pricing with a free tier, it is accessible for important entities as well as essential entities. AuditXYZ rates it 9.4/10. Compare at Best Compliance Automation Platforms.

Frequently Asked Questions

Does NIS2 apply to non-EU companies? NIS2 applies to entities providing services within the EU, regardless of where they are headquartered. A U.S. SaaS company operating in EU markets in covered sectors may be subject to NIS2 obligations. The directive requires non-EU entities without an EU establishment to designate an EU representative.

What counts as a "significant incident" requiring reporting? NIS2 and its implementing guidance define significant incidents by impact thresholds — typically incidents causing significant service disruption, financial loss, or affecting many users. Each member state's national law provides more specific criteria. When in doubt, the early warning within 24 hours is low-cost insurance.

How does NIS2 interact with DORA for financial entities? Financial entities subject to DORA are subject to DORA's more specific requirements for digital operational resilience. Where DORA requirements overlap with NIS2, DORA's lex specialis (more specific rule) applies. Entities should build their compliance program around DORA first, then identify any NIS2 gaps remaining.

Can ISO 27001 certification satisfy NIS2 requirements? ISO 27001 certification demonstrates implementation of security controls that address many NIS2 Article 21 requirements, but it is not a NIS2 compliance certification. National competent authorities assess NIS2 compliance independently. ISO 27001 provides strong evidence of security management maturity that regulators consider favorably, but it does not automatically satisfy all NIS2 obligations.

Request a NIS2 consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

ISO 27001Medium70%
NIST CSFMedium65%

Get matched with a NIS2 auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.

Recommended Tools