Topic Hub

NIS2 Directive Resources

Everything you need to understand and comply with the EU NIS2 Directive (Directive 2022/2555). Readiness guides, Article 21 controls, incident reporting playbooks, supply chain requirements, and ISO 27001 mapping for Essential and Important entities.

Get NIS2 Ready

What is the NIS2 Directive?

The NIS2 Directive (Directive 2022/2555) is the EU's updated cybersecurity legislation that replaces the original NIS Directive (2016/1148). It significantly expands the scope of organizations required to implement cybersecurity risk management measures and report incidents, covering an estimated 160,000+ entities across the EU.

NIS2 introduces stricter supervisory measures, tougher enforcement, and personal accountability for management bodies. Member States were required to transpose the Directive into national law by October 17, 2024, with enforcement now underway across the EU.

  • Applies to Essential and Important entities across 18 critical and important sectors
  • Article 21 mandates 10 specific cybersecurity risk management measures
  • Multi-stage incident reporting: 24-hour early warning, 72-hour notification, 1-month final report
  • Supply chain and third-party risk management obligations
  • Management body accountability with personal liability for executives
  • Maximum fines of EUR 10 million or 2% of global turnover for Essential entities
10
NIS2 Resources
EUR 10M
Maximum Fine (or 2% turnover)
24h
Early Warning Window
18
Sectors Covered

NIS2 Resources

Loading resources...