NIS2
Amended European Union · In force Jan 16, 2023 · next deadline Apr 17, 2027 (in 7 months)
Deadlines
Summaries for reference, not legal advice. Check the official text.
What it does
Requires medium and large entities in 18 critical sectors, including cloud, data centres, managed services, online marketplaces, search and social networks, to adopt cybersecurity risk-management measures. They must report significant incidents within 24 hours (early warning), 72 hours (notification) and one month (final report). Management bodies are accountable. Obligations apply through national transposing laws.
- Who it applies to
- Essential and important entities in Annex I/II sectors, generally medium-sized or larger (50+ employees or over EUR 10M turnover/balance sheet). DNS, TLD registries, trust service providers and public electronic communications providers are covered regardless of size.
- Penalties
- Essential entities: maximum of at least EUR 10M or 2% of worldwide annual turnover, whichever is higher. Important entities: maximum of at least EUR 7M or 1.4% (Art 34). Management can be held personally liable and temporarily suspended in some cases.
- Enforced by
- National competent authorities and CSIRTs designated by each Member State; NIS Cooperation Group; ENISA
- Official name
- Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive)
- Citation
- OJ L 333, 27.12.2022, p. 80
- Topics
- cybersecurity, breach-notification
Research notes
Transposition was late in most Member States, so obligations and registration deadlines differ by country. On 20 Jan 2026 the Commission proposed targeted NIS2 amendments alongside a revised Cybersecurity Act (CSA2): narrower scope, more harmonised measures, certification-based compliance and a bigger role for ENISA. The Digital Omnibus COM(2025) 837 also proposes a single-entry point for incident reporting. Neither was adopted as of Sept 2026. The 2027-04-17 date is computed from 'every two years' after 17 Apr 2025.
Related
Questions about NIS2
- What are the NIS2 compliance deadlines?
- Jan 16, 2023: NIS2 enters into force. Oct 17, 2024: Transposition deadline. Oct 18, 2024: National NIS2 measures apply; NIS1 repealed. Nov 7, 2024: Implementing Regulation 2024/2690 enters into force. Jan 17, 2025: Digital infrastructure entities submit registration data. Apr 17, 2025: Member States establish entity lists. Apr 17, 2027: Next biennial entity notification. Oct 17, 2027: Commission review of NIS2.
- When does NIS2 take effect?
- NIS2 took effect on Jan 16, 2023. The next milestone is Apr 17, 2027: Next biennial entity notification.
- Who does NIS2 apply to?
- Essential and important entities in Annex I/II sectors, generally medium-sized or larger (50+ employees or over EUR 10M turnover/balance sheet). DNS, TLD registries, trust service providers and public electronic communications providers are covered regardless of size.
- What are the penalties under NIS2?
- Essential entities: maximum of at least EUR 10M or 2% of worldwide annual turnover, whichever is higher. Important entities: maximum of at least EUR 7M or 1.4% (Art 34). Management can be held personally liable and temporarily suspended in some cases.