A hospital in one Member State faced rigorous cybersecurity obligations. A comparable hospital two borders away faced almost none. That was the single market under the original Network and Information Systems Directive (NIS1, Directive 2016/1148), which carried two structural flaws that got harder to ignore every year: it covered too few sectors, and it handed Member States so much discretion over who counted as an "operator of essential services" that compliance fractured into a patchwork the NIS 2 directive was written to end. The threat landscape between 2016 and 2022 refused to wait while regulators dithered. Ransomware-as-a-service industrialised attacks on critical infrastructure, SolarWinds and Kaseya proved the supply chain was the real attack surface, and state-sponsored campaigns started hitting energy grids and healthcare with grim regularity.

Directive (EU) 2022/2555, better known as NIS 2, is the answer. It entered into force on 16 January 2023, Member States had to transpose it into national law by 17 October 2024, and NIS1 was formally repealed at that point. The ambition is hard to overstate: a single harmonised cybersecurity baseline across 18 critical sectors, with real enforcement teeth, personal liability for senior management, and supply chain obligations that stretch the directive’s practical reach far past the entities formally in scope.

Those 18 sectors split into two tiers that supervisors treat very differently. Essential Entities face proactive, ex-ante supervision, meaning regulators can audit, inspect, and run security scans without waiting for an incident to land. That tier pulls in energy (electricity, oil, gas, hydrogen), transport across air, rail, road, and maritime, banking and financial market infrastructure, health including hospitals and pharmaceutical manufacturers and R&D, drinking water and wastewater, digital infrastructure (internet exchange points, DNS providers, TLD registries, cloud providers, data centres, CDNs), ICT service management for B2B managed services, public administration at central and regional level, and space.

Important Entities get the lighter touch: reactive, ex-post supervision that only kicks in when there’s evidence of non-compliance or an actual incident. Postal and courier services live here, along with waste management, chemicals, food production and distribution, manufacturing (medical devices, electronics, machinery, motor vehicles), digital providers like online marketplaces and search engines and social platforms, and research organisations.

Whether you land in scope at all comes down to size thresholds.

Category Employees Turnover OR Balance sheet
Large ≥250 ≥€50M turnover / ≥€43M balance sheet
Medium ≥50 ≥€10M turnover / ≥€10M balance sheet
Small/micro <50 <€10M, generally out of scope

The "generally out of scope" line for small and micro enterprises comes with teeth of its own. TLD registries, DNS providers, and anyone that is the sole provider of an essential service in a Member State are automatically in scope no matter how small they are, as is any entity whose disruption could hit public safety or national security. Size buys you nothing there.

The substantive obligations break into five categories, none of them aspirational. These are legally enforceable, and you have to be able to prove you meet them.

Risk management is the foundation, and NIS 2 spells out ten mandatory control areas rather than leaving it vague: risk analysis and information system security policies, incident handling, business continuity covering backup and disaster recovery and crisis management, supply chain security for third-party and vendor risk, security across the acquisition and development and maintenance of network and information systems, policies to test whether the risk measures actually work, basic cyber hygiene and training, cryptography and encryption, human resources security alongside access control and asset management, and multi-factor authentication with secure communications. The standard is explicitly "all-hazards," so a physical disruption to an information system counts every bit as much as a cyberattack.

Incident reporting runs on a three-stage clock that leaves NIS1 looking relaxed.

Stage Deadline Required content
Early warning 24 hours after awareness Basic notification: attack type, suspected cause
Incident notification 72 hours after awareness Updated assessment, severity, indicators of compromise
Final report 1 month after notification Full analysis, root cause, cross-border impact assessment

Reports go to the national CSIRT or Competent Authority, and the trigger is a "significant incident," which the directive defines as one that causes or could cause serious disruption to a service. As of May 2026, the NIS Cooperation Group adopted common reporting templates to standardise formats across Member States, cleaning up one of the inconsistencies that had already started to surface.

Supply chain security is where NIS 2 quietly outgrows its own scope. Entities have to flow their cybersecurity risk-management requirements down to suppliers and service providers. A hospital classified as an essential entity must assess the security practices of its software vendors, cloud providers, and managed service providers, and can contractually force those vendors to meet NIS 2-derived standards even when the vendors aren’t in scope themselves. So a Tier-2 SaaS company selling to a hospital, or a hardware manufacturer selling to an energy operator, ends up carrying NIS 2 obligations through contract rather than direct regulation. For non-EU companies feeding EU critical infrastructure, that produces real compliance pressure with no direct legal exposure, and the enforcement boundaries around that arrangement are almost entirely untested.

Registration is the dull one: entities register with their national Competent Authority, which keeps the lists of essential and important entities in its jurisdiction.

Management body accountability is the genuinely new piece, with no real precursor. Boards and the C-suite must approve the cybersecurity risk-management measures, oversee how they’re implemented, and can be held personally liable for infringements. For essential entities, national authorities can temporarily ban individuals from management roles after serious failures. This is a deliberate shove to drag cybersecurity out of the IT department and onto the boardroom agenda by attaching personal consequences to governance failures. GDPR did something similar for data protection, but NIS 2 reaches for sharper sanctions.

The penalties scale with your tier.

Entity type Maximum fine
Essential entities €10 million or 2% of global annual turnover, whichever is higher
Important entities €7 million or 1.4% of global annual turnover, whichever is higher

"Global annual turnover" is the phrase doing the heavy lifting. It borrows straight from GDPR, and it means a large multinational can’t cap its exposure by keeping its EU revenues small on paper. The supervisory gap between the two tiers matters just as much: essential entities can be audited proactively, scanned, and inspected with no incident to justify it, while important entities get supervised reactively, leaving the regulatory relationship mostly dormant until something breaks.

NIS 2 runs through a layered institutional structure. At EU level, ENISA (the EU Agency for Cybersecurity) supplies technical guidance, publishes the annual European Union Agency for Cybersecurity Threat Landscape report, and backs national implementation. The NIS Cooperation Group runs strategic coordination between Member States, the Commission, and ENISA, and issues non-binding guidelines. The CSIRTs Network handles operational incident response between national teams. EU-CyCLONe, the European Cyber Crisis Liaison Organisation Network, activates when a crisis spills across borders and gets too big for any single Member State. Down at national level, every Member State has to designate a Competent Authority (or several, split by sector), a national CSIRT to catch incident reports, and a Single Point of Contact for cross-border liaison. Operate across several Member States and you deal with several national Competent Authorities, each applying its own transposition of the same directive.

Which is exactly where the whole harmonisation project starts eating itself. NIS 2 was built to fix NIS1’s inconsistency, and by mid-2026 it is busy reproducing it. A significant number of Member States blew past the October 2024 transposition deadline. Italy made it on time. Germany’s final implementing law slipped past the deadline with completion expected before the end of 2025. France was still grinding through its process as of mid-2025 and got referred to the Court of Justice of the EU in July 2026. Ireland, Spain, and the Netherlands landed at the Court of Justice too, on 8 July 2026, for failing to notify their transposition measures.

None of this is administrative housekeeping. In those jurisdictions the enforcement machinery, the Competent Authorities and the penalty regime and the supervisory powers, does not yet exist in final form. Companies operating there are left guessing which national rules actually bind them. The root cause is baked into the instrument itself. NIS 2 is a directive, not a regulation. A regulation applies directly and uniformly the instant it enters into force. A directive only sets objectives and minimum standards, then leaves each Member State to write its own implementing law, and variation walks in through that door. The Commission’s January 2026 proposed amendments target roughly 28,700 companies, including 6,200 micro and small enterprises stuck in ambiguous scope situations, and they try to shrink that variation without dissolving the underlying tension between EU harmonisation and national legislative sovereignty.

Mid-market technology companies feel the scope ambiguity worst. A SaaS company with 60 employees and €15M in revenue clears the size threshold without question, but its tier hangs entirely on how its services get characterised. Cast it as ICT service management to other businesses and it’s an essential entity, staring down proactive supervision and a €10M fine ceiling. Cast it as a digital provider and it drops to an important entity with reactive oversight and a lower cap. That call belongs to national Competent Authorities applying national transposition law, so the same company running in France, Germany, and the Netherlands could in theory collect three different classifications.

NIS 2 doesn’t stand alone either. The EU has been stacking cybersecurity regulation in layers, and you can’t read NIS 2 straight without seeing where it sits against the rest.

Law Scope Status
DORA (Regulation 2022/2554) Financial sector ICT risk management Fully applicable from 17 January 2025
Cyber Resilience Act (Regulation 2024/2847) Products with digital elements, hardware and software manufacturers Fully applicable from 11 December 2027
CER Directive (2022/2557) Physical resilience of critical entities Transposition deadline October 2024
Cyber Solidarity Act (Regulation 2025/38) EU-level detection, preparedness, and response capacity In force 2025

DORA is the interaction that matters most. The Digital Operational Resilience Act is a regulation, so it applies directly with no national transposition, and it’s cut specifically for financial sector ICT risk. For banks, insurers, investment firms, and financial market infrastructure, DORA effectively overrides NIS 2, being more detailed, more prescriptive, and sector-specific. The Cyber Resilience Act, once it fully bites in 2027, will drop security-by-design obligations on manufacturers of products with digital elements, and how that meshes with NIS 2’s supply chain rules hasn’t been worked out yet. NIS 2 is the horizontal floor and the sector-specific instruments sit on top. A technology company serving both financial institutions and healthcare providers gets to navigate overlapping obligations from several instruments at once.

The read at mid-2026 is split down the middle. The legal framework is sound and the obligations are clear, but the enforcement infrastructure is half-built and the harmonisation goal is already fraying. The personal liability provisions are the real structural shift, wiring a direct line between board-level governance and individual legal exposure that NIS1 never had. Early signals from Germany’s transposition debates show heavy corporate lobbying to water down that liability language at national level, which tells you the provision has bite before a single fine has landed.

The supply chain multiplier is the piece almost nobody has priced in properly. The roughly 100,000 entities formally in scope are the visible layer. The far larger crowd of suppliers, vendors, and service providers who inherit NIS 2-derived contractual requirements without any direct regulatory exposure is where the directive’s real reach lives, and it’s also where compliance maturity is thinnest.

If you operate in the EU, supply EU critical infrastructure, or sell technology into any of the 18 covered sectors, three questions decide your fate: which tier you fall into (or which tier your customers fall into), which national Competent Authority owns you, and whether your risk management, incident response, and supply chain security could actually survive a proactive audit. The audit question is the one that will cause the most pain, because a rule you can’t yet be fined under still leaves you exposed the day the Competent Authority finally opens its doors, and in several of the biggest Member States that machinery is still on the workbench. Build for the audit you can’t yet fail, not the fine that hasn’t arrived.


Canonical sources: European Commission NIS2 page; full directive text at EUR-Lex reference 32022L2555; ICLG EU Cybersecurity Regulatory Landscape 2026.