Regulation: Directive (EU) 2022/2555 / National Cybersecurity Act (transposition)
Effective: November 11, 2026
Scope: Cybersecurity of critical infrastructure
What is NIS2?
NIS2 is the EU directive on the security of network and information systems. It is transposed into national law by each Member State. It regulates organisations providing critical services.
Who Falls Under NIS2?
Essential Entities (Higher obligations)
| Sector | Examples |
|---|
| Energy | Electricity, gas, oil, hydrogen |
| Transport | Aviation, rail, maritime, road |
| Banking | Credit institutions |
| Healthcare | Hospitals, laboratories, pharmaceuticals |
| Digital infrastructure | DNS, TLD, cloud computing, data centres |
| ICT services B2B | Managed services, security services |
| Public administration | Central and local government bodies |
| Space | Satellite operators |
Important Entities (Lower obligations)
| Sector | Examples |
|---|
| Postal services | Couriers, postal operators |
| Waste | Waste processing |
| Chemicals | Chemical manufacturing |
| Food | Food production and distribution |
| Manufacturing | Medical devices, computers, machinery |
| Digital services | Online marketplace, search engines, social networks |
| Research | Research organisations |
Key Obligations
Incident Reporting
| Incident type | Notification | To whom |
|---|
| Critical | 24 hours | National CSIRT/authority |
| Significant | 72 hours | National CSIRT/authority |
| Standard | As appropriate | Internal log |
Registration
- Registration with national competent authority is mandatory
- Mandatory for Essential and Important entities
- Deadline: before 11.11.2026
Timeline
Penalties
| Category | Penalty |
|---|
| Essential entities | up to EUR 10M or 2% of global turnover |
| Important entities | up to EUR 7M or 1.4% of turnover |
Plus:
- Order to remedy within 30-60 days
- Suspension of activities
- Ban on exercising management functions
Next Steps
- Determine your scope
- Review ISMS requirements
- Go through the checklist
Resources