Directive (EU) 2022/2555
NIS2 Directive
NIS2 strengthens cybersecurity risk management and incident reporting for essential and important entities across sectors such as energy, transport, health, digital infrastructure, and public administration.
Am I affected?
Are you in a sector listed as essential or important under national transposition?
Check member-state NIS2 scope lists.
Do you have 50+ employees or €10M+ turnover?
Size thresholds often determine important-entity status.
Do you provide managed security or cloud services to others?
Digital providers are commonly in scope.
Fines & sanctions
| Jurisdiction | Maximum | Notes |
|---|---|---|
| Essential entities | Up to €10M or 2% turnover | Member-state enforcement. |
| Important entities | Up to €7M or 1.4% turnover | Member-state enforcement. |
Key requirements
- Risk-management measures: policies, asset inventory, access control.
- Supply-chain security and vendor due diligence.
- Incident detection, response, and business continuity.
- Management body training and accountability.
- Report significant incidents within 24h / 72h / 1 month.
- Cooperate with national CSIRTs and competent authorities.
Deadlines
- Member-state transpositionOct 2024
- Ongoing incident reportingContinuous
Documents
Our services
EUCRAB offers audit, compliance, and full-service packages tailored to your assessment results.
View service packages