Skip to content

NIS2

Amended European Union · In force Jan 16, 2023 · next deadline Apr 17, 2027 (in 7 months)

Deadlines

DateWhat happens
Jan 16, 2023NIS2 enters into force3.7 years ago
Oct 17, 2024Transposition deadline23 months ago
Oct 18, 2024National NIS2 measures apply; NIS1 repealed23 months ago
Nov 7, 2024Implementing Regulation 2024/2690 enters into force23 months ago
Jan 17, 2025Digital infrastructure entities submit registration data20 months ago
Apr 17, 2025Member States establish entity lists17 months ago
Apr 17, 2027Next biennial entity notificationin 7 months
Oct 17, 2027Commission review of NIS2in 13 months

Summaries for reference, not legal advice. Check the official text.

What it does

Requires medium and large entities in 18 critical sectors, including cloud, data centres, managed services, online marketplaces, search and social networks, to adopt cybersecurity risk-management measures. They must report significant incidents within 24 hours (early warning), 72 hours (notification) and one month (final report). Management bodies are accountable. Obligations apply through national transposing laws.

Who it applies to
Essential and important entities in Annex I/II sectors, generally medium-sized or larger (50+ employees or over EUR 10M turnover/balance sheet). DNS, TLD registries, trust service providers and public electronic communications providers are covered regardless of size.
Penalties
Essential entities: maximum of at least EUR 10M or 2% of worldwide annual turnover, whichever is higher. Important entities: maximum of at least EUR 7M or 1.4% (Art 34). Management can be held personally liable and temporarily suspended in some cases.
Enforced by
National competent authorities and CSIRTs designated by each Member State; NIS Cooperation Group; ENISA
Official name
Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive)
Citation
OJ L 333, 27.12.2022, p. 80
Topics
cybersecurity, breach-notification
Verified 2026-09-22 eur-lex.europa.eu insideprivacy.com
Research notes

Transposition was late in most Member States, so obligations and registration deadlines differ by country. On 20 Jan 2026 the Commission proposed targeted NIS2 amendments alongside a revised Cybersecurity Act (CSA2): narrower scope, more harmonised measures, certification-based compliance and a bigger role for ENISA. The Digital Omnibus COM(2025) 837 also proposes a single-entry point for incident reporting. Neither was adopted as of Sept 2026. The 2027-04-17 date is computed from 'every two years' after 17 Apr 2025.

Related

Questions about NIS2
What are the NIS2 compliance deadlines?
Jan 16, 2023: NIS2 enters into force. Oct 17, 2024: Transposition deadline. Oct 18, 2024: National NIS2 measures apply; NIS1 repealed. Nov 7, 2024: Implementing Regulation 2024/2690 enters into force. Jan 17, 2025: Digital infrastructure entities submit registration data. Apr 17, 2025: Member States establish entity lists. Apr 17, 2027: Next biennial entity notification. Oct 17, 2027: Commission review of NIS2.
When does NIS2 take effect?
NIS2 took effect on Jan 16, 2023. The next milestone is Apr 17, 2027: Next biennial entity notification.
Who does NIS2 apply to?
Essential and important entities in Annex I/II sectors, generally medium-sized or larger (50+ employees or over EUR 10M turnover/balance sheet). DNS, TLD registries, trust service providers and public electronic communications providers are covered regardless of size.
What are the penalties under NIS2?
Essential entities: maximum of at least EUR 10M or 2% of worldwide annual turnover, whichever is higher. Important entities: maximum of at least EUR 7M or 1.4% (Art 34). Management can be held personally liable and temporarily suspended in some cases.

When the rules change: new data, privacy and AI laws and deadlines, the next morning.