EUCRABEuropean Compliance & Regulation Advisory Board

Directive (EU) 2022/2555

NIS2 Directive

NIS2 strengthens cybersecurity risk management and incident reporting for essential and important entities across sectors such as energy, transport, health, digital infrastructure, and public administration.

Am I affected?

  1. Are you in a sector listed as essential or important under national transposition?

    Check member-state NIS2 scope lists.

  2. Do you have 50+ employees or €10M+ turnover?

    Size thresholds often determine important-entity status.

  3. Do you provide managed security or cloud services to others?

    Digital providers are commonly in scope.

Fines & sanctions

JurisdictionMaximumNotes
Essential entitiesUp to €10M or 2% turnoverMember-state enforcement.
Important entitiesUp to €7M or 1.4% turnoverMember-state enforcement.

Key requirements

Deadlines

Documents

Our services

EUCRAB offers audit, compliance, and full-service packages tailored to your assessment results.

View service packages