Nix2
Back to Nix2
Directive·European Union (directive — binds Member States, not entities directly)

NIS2

NIS2 — Network and Information Security Directive 2

EU baseline for cybersecurity risk management and incident reporting — enforced through each Member State's national transposition law.

Official sources ↓
EU entry into force 16 Jan 2023 · national transposition deadline 17 Oct 2024
Scroll
Overview

NIS2 is an EU directive. A directive is addressed to Member States: it sets a common target, and each country writes its own national law to reach it. Entities are bound by the national law of the country where they are established or provide services, not by the EU text itself.

This means obligations, competent authority, reporting portal, sanctions and even the list of covered entities can differ from one Member State to the next — and the transposition timeline differs too. Some countries were in force on 18 October 2024, others are still in parliamentary process well into 2025 and 2026.

Nix2 therefore tracks each national transposition (e.g. BE CyFun, NL Cyberbeveiligingswet, DE NIS2UmsuCG, IT D.Lgs. 138/2024, FR bill in progress) as its own framework, with its own catalog, evidence expectations and citations — because the EU directive alone is not what a compliance officer must satisfy.

Who it applies to
01

Essential and important entities in the sectors listed in the national transposition (energy, transport, banking, health, digital infrastructure, ICT service management, public administration, postal, waste, food, manufacturing, digital providers, research…).

02

Size threshold generally follows the EU medium/large enterprise definition — indicatively >50 staff or >€10M turnover / balance sheet — but the exact wording is set by each national law.

03

Certain entities regardless of size when they play a critical role (e.g. sole DNS/TLD providers, trust service providers, certain public administrations).

Core obligations
Duty · 01

Cybersecurity risk-management measures across governance, incident handling, business continuity, supply chain, access control, cryptography and HR security — implemented per the national law.

Duty · 02

Management-body accountability, approval of the measures and mandatory training.

Duty · 03

Incident reporting to the national CSIRT / competent authority: early warning without undue delay and in any event within 24h of awareness, incident notification within 72h, final report within 1 month.

Duty · 04

Registration with the national authority and cooperation with national supervisory activity (inspections, audits, requests for information).

Timeline
  1. 2020-12-16
    European Commission proposal for NIS2
  2. 2022-11-10
    European Parliament adopts NIS2
  3. 2022-11-28
    Council of the EU adopts NIS2
  4. 2022-12-27
    Directive (EU) 2022/2555 published in the Official Journal
  5. 2023-01-16
    EU entry into force (20 days after OJ publication)
  6. 2024-10-17
    Deadline for Member States to transpose NIS2 into national law
  7. 2024-10-18
    From this date, national transposition laws must apply — where they have actually been adopted and entered into force
National transposition

Because NIS2 is a directive, what actually binds your organisation is the national law of each Member State. Below is the status of the transpositions Nix2 tracks with verified primary sources. Countries not listed yet are being added as their laws progress — no status is inferred from the EU text alone.

Status verified against official government sources. Not legal advice.

Official sources

License · EU legislative texts are reusable under the EUR-Lex reuse policy (© European Union).

Explore other frameworks