Skip to content
TECHNOMATON | Docs SAI Certified Trainers

NIS2: Overview

Regulation: Directive (EU) 2022/2555 / National Cybersecurity Act (transposition) Effective: November 11, 2026 Scope: Cybersecurity of critical infrastructure


What is NIS2?

NIS2 is the EU directive on the security of network and information systems. It is transposed into national law by each Member State. It regulates organisations providing critical services.

Who Falls Under NIS2?

Essential Entities (Higher obligations)

SectorExamples
EnergyElectricity, gas, oil, hydrogen
TransportAviation, rail, maritime, road
BankingCredit institutions
HealthcareHospitals, laboratories, pharmaceuticals
Digital infrastructureDNS, TLD, cloud computing, data centres
ICT services B2BManaged services, security services
Public administrationCentral and local government bodies
SpaceSatellite operators

Important Entities (Lower obligations)

SectorExamples
Postal servicesCouriers, postal operators
WasteWaste processing
ChemicalsChemical manufacturing
FoodFood production and distribution
ManufacturingMedical devices, computers, machinery
Digital servicesOnline marketplace, search engines, social networks
ResearchResearch organisations

Key Obligations

ISMS (Information Security Management System)

Incident Reporting

Incident typeNotificationTo whom
Critical24 hoursNational CSIRT/authority
Significant72 hoursNational CSIRT/authority
StandardAs appropriateInternal log

Registration

  • Registration with national competent authority is mandatory
  • Mandatory for Essential and Important entities
  • Deadline: before 11.11.2026

Timeline

Penalties

CategoryPenalty
Essential entitiesup to EUR 10M or 2% of global turnover
Important entitiesup to EUR 7M or 1.4% of turnover

Plus:

  • Order to remedy within 30-60 days
  • Suspension of activities
  • Ban on exercising management functions

Next Steps

  1. Determine your scope
  2. Review ISMS requirements
  3. Go through the checklist

Resources