The NIS 2 Directive (Directive (EU) 2022/2555) is the European Union's updated cybersecurity legislation, replacing the original NIS Directive from 2016. It significantly expands the scope of organizations covered, strengthens cybersecurity requirements, introduces stricter incident reporting obligations, and increases penalties for non-compliance. Member states were required to transpose NIS 2 into national law by October 17, 2024. This guide covers everything organizations need to know to achieve and maintain compliance.
PoliWriter generates all the policies, mappings, and audit-ready artifacts referenced in this guide — customized to your AWS / GitHub / Okta stack. 60+ integrations, continuous monitoring, evidence collection — at a fraction of Vanta's price.
Monthly billing · cancel anytime · 30-day money-back guarantee
NIS 2 applies to medium and large organizations (50+ employees or 10M+ euro annual turnover) operating in one of 18 covered sectors including energy, transport, health, digital infrastructure, ICT services, manufacturing, and digital providers. Some smaller organizations may also be covered if designated by member states as critical. If your organization provides services within the EU in a covered sector, you should assess applicability.
Essential Entities are large organizations in Sectors of High Criticality (Annex I) and face proactive supervision and higher fines (up to 10M euros or 2% of turnover). Important Entities are medium organizations in Annex I sectors or organizations in Other Critical Sectors (Annex II) and face reactive supervision and lower fines (up to 7M euros or 1.4% of turnover). Both must comply with the same Article 21 cybersecurity measures.
ISO 27001 provides an excellent foundation for NIS 2 compliance. Many Article 21 requirements align with ISO 27001 controls. However, NIS 2 adds specific requirements beyond ISO 27001 including mandatory incident reporting timelines, management body accountability and training, supply chain security obligations, and sector-specific requirements. Organizations certified to ISO 27001 will have a significant head start but should conduct a gap analysis.
While the transposition deadline was October 17, 2024, some member states may be delayed. However, organizations should prepare now because the directive's requirements are clear and national laws will be retroactive to the directive's requirements. Starting compliance efforts early avoids a rush when national legislation is enacted and demonstrates good faith.
Yes. Article 20 explicitly states that management bodies must approve cybersecurity risk management measures and oversee their implementation, and can be held liable for infringements. Member states determine the specific liability mechanisms in national law, but the directive's intent is clear: cybersecurity is a board-level responsibility with personal consequences for negligence.
NIS 2 applies to entities providing services within the EU, regardless of where they are established. Non-EU organizations providing services in covered sectors to EU customers must comply and are required to designate a representative in one of the member states where they provide services. This extraterritorial reach mirrors GDPR's approach.
NIS 2 establishes a three-phase reporting timeline: an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours with an initial assessment of severity and impact, and a final report within one month with a detailed description, root cause analysis, and mitigation measures applied.
PoliWriter generates all the policies, mappings, and audit-ready artifacts referenced in this guide — customized to your AWS / GitHub / Okta stack. 60+ integrations, continuous monitoring, evidence collection — at a fraction of Vanta's price.
PoliWriter creates all the policies you need for NIS 2 Directive compliance, customized to your organization. AI-powered, audit-ready, hours not months.
Get Started Free