Back to blog
NIS2

NIS2 Requirements: Key Pillars & Compliance Checklist

NIS2 expanded EU cybersecurity compliance to roughly 160,000 organizations, with mandatory timelines and executive liability whose exact terms depend on national law. Here's what it actually requires, and how to check where you stand.

25.08.26
12'
Maurice Müller

Maurice Müller

Senior Content Manager

Maurice Müller is a journalist and content strategist with experience across print and digital media. At Formalize, he translates complex compliance and regulatory topics into clear, practical content for compliance, risk, and security professionals across Europe.

Key takeaways:

  • NIS2 requirements can be organized into four practical compliance areas: management accountability, risk management measures, incident reporting, and supply chain security.

  • It applies to "essential" and "important" entities, split by sector and by company size.

  • Significant incidents require an early warning within 24 hours, a full notification within 72 hours, and a final report within a month.

  • Fines reach €10 million or 2% of global turnover for essential entities, €7 million or 1.4% for important entities.

  • ISO 27001 covers an estimated 70 to 80% of NIS2. The rest still needs direct attention.

Governance teams have spent the past two years absorbing what NIS2 actually changes. For many, the honest answer is still "we're not entirely sure." That uncertainty is reasonable. NIS2 didn't just update a checklist. It rewired who's accountable, how fast incidents must be reported, and how deep into the supply chain an organization has to look. Getting a clear, structured picture of the requirements is the first real step toward closing that gap.

What are the NIS2 directive requirements?

NIS2, formally Directive (EU) 2022/2555, is the EU's cybersecurity directive for essential and important entities. It requires in-scope organizations to manage cybersecurity risk with board-level accountability, and to prove it, not just document it.

For the full picture on what NIS2 is, who created it, and why, see What is NIS2?. This piece stays focused on what compliance actually requires in practice.

The 4 core compliance areas of NIS2 requirements

1. Management accountability and governance

Top management must approve the organization's cybersecurity risk measures. They must actively oversee how those measures are carried out, and complete mandatory cybersecurity training themselves. This isn't a delegation option. NIS2 makes cybersecurity a board-level responsibility, not something that stays inside IT.

2. Risk management measures

Article 21 sets out at least ten baseline measures organizations must implement. These cover areas like risk analysis, encryption, access controls, multi-factor authentication, and incident handling procedures. These aren't abstract principles. Auditors expect to see them actually running, not just documented.

3. Incident reporting timelines

Significant incidents trigger a strict, staged clock: an early warning within 24 hours, a full incident notification within 72 hours, and a final report within a month of that notification. The 24-hour window is unforgiving. Teams that haven't rehearsed the process before a real incident are the ones most likely to miss it.

4. Supply chain security

Organizations must evaluate and continuously monitor the cybersecurity posture of their direct vendors, suppliers, and service providers. A weak link in a supplier's security becomes the organization's own exposure the moment that supplier touches its systems or data.

The NIS2 compliance checklist

NIS2 doesn't leave the basics to guesswork. Article 21(2) sets out ten baseline measures every in-scope organization needs. Here's what to actually check for each one.

NIS2 requirement

What to check

Risk analysis and information system security policies

Do you have approved, regularly reviewed security and risk policies?

Incident handling

Is there a documented process for detecting, reporting, and responding to incidents?

Business continuity and crisis management

Do you have backup management, disaster recovery, and crisis management plans in place?

Supply chain security

Are your suppliers' and service providers' security practices actually assessed, not just assumed?

Security in system acquisition, development, and maintenance

Is vulnerability handling and disclosure built into how you acquire and maintain systems?

Policies to assess the effectiveness of security measures

Do you regularly test whether your controls actually work, not just that they exist?

Cyber hygiene and security training

Is there mandatory, ongoing security awareness training for staff?

Cryptography and encryption

Do you have a policy governing when and how encryption is used?

Human resources security, access control, and asset management

Are access rights tied to roles, and is there a current asset inventory?

Multi-factor authentication and secure communications

Is MFA enforced, and are emergency communication channels secured?

Who must comply with NIS2 compliance requirements?

NIS2 splits organizations into two tiers, based on sector and size.

Essential entities are large organizations, 250+ employees or over €50 million in annual turnover, in the 11 sectors the directive treats as highest-criticality. Those sectors are energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space.

Important entities are medium-sized organizations, 50+ employees or over €10 million in annual turnover, in those same sectors. It also includes medium and large organizations in seven additional sectors: postal and courier services, waste management, chemicals, food production and distribution, manufacturing, digital providers, and research.

Roughly 160,000 organizations fall into one of these two tiers across the EU, according to the European Commission's own November 2025 estimate, a figure revised up from an original 2020 estimate of 110,000 once the directive was actually being implemented.

Essential entities

Important entities

Size threshold

250+ employees or €50 million+ turnover

50+ employees or €10 million+ turnover

Sectors

Annex I (11 high-criticality sectors)

Annex I or Annex II (18 sectors total)

Supervision

Proactive, ongoing

Reactive, triggered by incidents or complaints

Maximum fine

€10 million or 2% of global turnover

€7 million or 1.4% of global turnover

A handful of organizations, including qualified trust service providers, DNS providers, and top-level domain registries, count as essential regardless of size.

Streamlining NIS2 compliance with Formalize

Most organizations start NIS2 work the same way: a spreadsheet, a shared drive folder, and a growing sense that something's being missed. That approach breaks down fast. It can't enforce who owns a control. It can't remind anyone that a review is overdue. It can't produce evidence on demand when an auditor asks.

Formalize's NIS2 compliance software replaces that fragmented setup with a structured system built around the same four compliance areas covered above. Approval workflows and executive dashboards give leadership the oversight NIS2's governance requirements actually demand, instead of a policy nobody outside IT ever sees. Controls, tasks, and evidence live in one place, mapped directly to what the directive requires. Being audit-ready doesn't mean a scramble through old email threads.

Ready to see it for yourself?

Book a demo built around your own compliance work, not a generic script.

The bigger, quieter cost of manual NIS2 work is headcount. Formalize is built to automate the repetitive parts instead: reminders, periodic reviews, incident workflows. Those are the tasks that otherwise tend to justify hiring someone new, or extending a consultant's contract indefinitely. And because most organizations don't stop at NIS2, controls mapped once carry forward to ISO 27001, the GDPR, and whatever comes next. There's no need to start the mapping exercise over from scratch each time.

Formalize also offers a free NIS2 gap assessment and 22 predefined NIS2 controls already mapped to the directive, for teams that want a concrete starting point rather than a blank page.

NIS2 compliance deadlines

Member states were required to transpose NIS2 into national law by 17 October 2024, with obligations applying from the next day. In practice, that timeline slipped in many countries. As of mid-2026, 23 of 27 member states have national NIS2 law fully in force. The remaining four, France, Ireland, the Netherlands, and Spain, have been referred to the EU Court of Justice for the delay.

That patchwork doesn't change what organizations should be doing. If you're in scope, national enforcement is either already active or close behind it. That's true regardless of which exact week your country's law took effect. Waiting for a specific local deadline before starting is a losing bet. Start the gap assessment now. Treat the local transposition date as a hard deadline rather than a soft one.

Penalties for non-compliance

Fines scale with entity type. Essential entities face up to €10 million, or 2% of global annual turnover, whichever is higher. Important entities face up to €7 million, or 1.4%, on the same basis.

Beyond fines, essential entities face a sharper consequence. Under Article 32, national authorities can request a temporary ban on a named individual, at CEO or legal representative level, from exercising management functions at all. That follows a proven infringement. This specific power applies to essential entities. Important entities fall under a separate, generally less severe enforcement track. Either way, the direction is the same. NIS2 turns cybersecurity failure into a personal, not just corporate, consequence.

The exact mechanics vary by country, though. NIS2 is a directive, not a regulation, so each member state transposes Article 32 into its own national law. The specific process for a management ban, who can request it, what counts as a proven infringement, how it's enforced, depends on how your country implemented the directive, not on a single EU-wide procedure.

Frequently asked questions

Book a demo