Back to blog
NIS2

What is NIS2? The EU cybersecurity directive, and what it means for your organization

NIS2 is the EU's updated directive on network and information security. It sets binding cybersecurity requirements for organizations across critical sectors in Europe, and since October 2024, it is in force.

31.07.26
12'
Maurice Müller

Maurice Müller

Senior Content Manager

Maurice Müller is a journalist and content strategist with experience across print and digital media. At Formalize, he translates complex compliance and regulatory topics into clear, practical content for compliance, risk, and security professionals across Europe.

Key takeaways

  • NIS2 applies to essential and important entities across 18 sectors in the EU.

  • It requires risk management, incident reporting, supply chain security, and management accountability.

  • Non-compliance can result in fines of up to €10 million or 2% of global annual turnover for essential entities.

  • As of mid-2026, most EU Member States have adopted transposing legislation, with enforcement already operational and first fines imposed across several countries.

What is NIS2?

NIS2 (formally the Network and Information Security Directive 2) is EU legislation designed to raise the baseline for cybersecurity across member states. It replaced the original NIS Directive (NIS1) from 2016, which had a narrower scope and inconsistent enforcement across countries.

The core goal is straightforward: organizations that operate critical infrastructure or provide essential services need to manage cyber risk actively, report incidents on time, and be able to demonstrate that their security measures are in place, not just on paper.

Why was NIS2 introduced?

The original NIS Directive (NIS1) left significant gaps. Coverage was limited, member states implemented requirements differently, and supervision varied widely. Meanwhile, the cyber threat landscape shifted considerably: ransomware attacks on hospitals, supply chain compromises, and state-sponsored intrusions became regular occurrences across Europe.

NIS2 was introduced to address three specific weaknesses in NIS1: inconsistent scope, fragmented enforcement, and insufficient attention to supply chain risk. The result is a directive that covers more sectors, sets clearer requirements, and gives national authorities stronger enforcement powers.

Who does NIS2 apply to?

NIS2 applies to medium and large organizations in 18 critical sectors. They are divided into two categories.

Essential entities include organizations in energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space. These entities are subject to proactive supervision, including regular audits and on-site inspections.

Important entities include organizations in postal and courier services, waste management, chemicals, food production, manufacturing, digital providers, and research. These are subject to reactive supervision, meaning oversight is typically triggered after an incident or evidence of non-compliance.

The size threshold generally covers organizations with 50 or more employees or an annual turnover above €10 million. Smaller organizations may also be in scope if they operate in particularly critical areas.

Compared to NIS1, the scope is considerably broader. Many organizations that were not previously regulated under cybersecurity law are now covered.

Does NIS2 apply to my organization?

A useful starting point is to work through four questions:

  1. Does your organization provide services in the EU?

  2. Does it operate in one of the sectors listed in Annex I or Annex II of the directive?

  3. Is it generally classified as a medium-sized or large organization (50+ employees or €10 million+ turnover)?

  4. Does a special exception or national designation bring it into scope regardless of size?

Meeting these general criteria does not automatically determine your legal status. Scope can depend on the specific services you provide, company ownership rules, national legislation, and whether your organization has been individually designated as critical.

Not sure whether your organization is covered? Complete the NIS2 Compliance Self-Assessment to identify your likely scope and initial compliance gaps.

Key NIS2 requirements

NIS2 sets out a minimum standard for cybersecurity measures. Organizations in scope must address four areas:

Risk management: Policies for analyzing and managing risks to network and information systems, including incident handling, business continuity, and crisis management.

Incident reporting: Significant incidents must be reported to the relevant national authority within 24 hours of detection (initial notification), followed by a more detailed report within 72 hours, and a final report within one month.

Supply chain security: Organizations must assess the cybersecurity practices of their suppliers and service providers, not just their own internal controls.

Governance and management accountability: Senior management is directly responsible for approving cybersecurity measures and can be held personally liable for non-compliance. This is a significant shift from how cybersecurity responsibility has traditionally been allocated.

NIS2 compliance deadlines

The transposition deadline for member states was 17 October 2024. Only four member states met it. The European Commission opened infringement procedures against 23 member states in November 2024, escalating to reasoned opinions against 19 of them in May 2025.

Since then, transposition has progressed significantly. As of mid-2026, 23 of 27 member states have fully transposed NIS2, with enforcement now operational across most of the EU. The four remaining member states, France, Ireland, the Netherlands, and Spain, have been referred to the Court of Justice of the European Union by the European Commission.

Regardless of local transposition status, organizations should not treat incomplete national implementation as a reason to delay. The direction of travel is clear, enforcement will follow, and the operational work (mapping controls, assigning ownership, building evidence) takes time.

NIS2 has been in force since October 2024. The key milestones so far:

  • 17 October 2024: transposition deadline for member states, with only four meeting it

  • 17 January 2025: new peer review practices came into effect

  • 17 April 2025: member states required to establish lists of essential and important entities

What comes next: the European Commission will review NIS2's functioning in October 2027, with potential amendments to follow.

For organizations that have not yet started, the question is no longer about deadlines. It is about being ready when enforcement reaches them.

Implementation status last updated: 31 July 2026

NIS2 vs. GDPR and NIS1: key differences

NIS2 and the GDPR address different problems and are not mutually exclusive. The GDPR focuses on the protection of personal data. NIS2 focuses on the security of the systems and infrastructure that process that data. An organization can be compliant with the GDPR and still fall short of NIS2 requirements, particularly around incident response, risk management, and supply chain security.

Compared to NIS1, NIS2 expands the scope significantly (more sectors, more organizations), raises the security requirements, introduces personal liability for management, and harmonizes penalties across member states.

A brief comparison:

NIS1

NIS2

GDPR

Focus

Critical infrastructure cybersecurity

Broader cybersecurity resilience

Personal data protection

Scope

Limited sectors

18 sectors

All organizations processing EU personal data

Penalties

Varied by member state

Up to €10 million or 2% of turnover (whichever is higher)

Up to €20 million or 4% of turnover (whichever is higher)

Management liability

No

Yes

Limited

Penalties for non-compliance

NIS2 introduces harmonized penalties across the EU for the first time, and enforcement has already begun. First fines have been reported in Belgium (€185,000), Italy (€450,000), and Hungary (€78,000), with national audit programs now running across more than a dozen member states. Fine amounts are based on reported figures from national authorities and enforcement trackers; for binding confirmation of any specific sanction, consult the relevant national competent authority.

Essential entities face fines of up to €10 million or 2% of global annual turnover, whichever is higher. Important entities face fines of up to €7 million or 1.4% of global annual turnover.

Beyond financial penalties, NIS2 Article 20 places explicit responsibility on management bodies to approve, oversee, and be accountable for cybersecurity risk management measures. Personal liability can be imposed on individual executives for non-compliance, including temporary bans from managerial functions. This shifts the question from "is the organization compliant" to "can leadership demonstrate that they fulfilled their oversight responsibilities."

How to get started with NIS2 compliance

The practical starting point is a gap assessment: understanding which NIS2 requirements apply to your organization and where your current controls, policies, and processes fall short.

From there, the work involves assigning ownership across teams, documenting controls, building continuous evidence collection, and establishing incident reporting workflows before an incident happens, not after.

Formalize is designed to operationalize NIS2, not just document it. A NIS2 Compliance Self-Assessment can help your team identify gaps quickly and prioritize the areas that need attention first. Formalize also offers 22 predefined NIS2 controls mapped to the directive's requirements, so teams do not need to build their compliance framework from scratch.

For organizations that want a broader overview of the directive and its implications, the NIS2 compliance hub covers requirements, sector applicability, and how to prepare.

Frequently asked questions

Last reviewed: 31 July 2026 | This article is intended as general information only and does not constitute legal advice.

Demo buchen