NIS2 Directive: what it means for your organization
The NIS2 Directive is the EU's cybersecurity law for network and information systems. It requires medium and large organizations across 18 sectors to manage cyber risk, report incidents fast, and hold management accountable.

The NIS2 Directive, formally Directive (EU) 2022/2555, is the European Union's law for a high common level of cybersecurity across network and information systems. It replaces the original NIS Directive (2016/1148) and applies to medium and large organizations across 18 critical sectors, from energy and healthcare to digital infrastructure and public administration. According to the European Commission, the directive raises the EU's common level of cybersecurity ambition through a wider scope, clearer rules, and stronger supervision tools than its predecessor.
NIS2 entered into force on 27 December 2022, after adoption by the European Parliament and Council that November. EU member states had until 17 October 2024 to transpose it into national law, with the new rules applying from 18 October 2024. The EU repealed NIS1 the same day.
Which sectors and organizations does NIS2 cover?
NIS2 extends the original NIS Directive's six sectors, energy, transport, healthcare, finance, water management, and digital infrastructure, to 18 sectors in total. New additions include providers of public electronic communications, digital services such as social media platforms, waste and wastewater management, critical product manufacturing, postal and courier services, the space sector, and public administration at central and regional level. Member states can choose to extend coverage to local government too.
The directive applies a size-cap rule: medium and large entities operating in these sectors generally fall within scope, replacing the old system where each member state decided which operators counted as essential. NIS2 classifies entities as either essential or important, with essential entities facing closer supervision.
A few areas sit outside NIS2's scope entirely: defense, national security, public security, law enforcement, and the judiciary, along with parliaments and central banks.
Non-EU organizations that offer certain digital services in the EU, including cloud computing, data center, and managed service providers, online marketplaces, search engines, and social networking platforms, must appoint a representative established in an EU member state where they operate. Without one, any member state where the organization offers services can take legal action for non-compliance.
What NIS2 requires organizations to do
Essential and important entities must put technical, operational, and organizational measures in place that match their risk exposure, size, and the likely impact of an incident. NIS2 calls this an all-hazards approach: it covers anything that could compromise a system's availability, integrity, or confidentiality, not just cyberattacks.
At minimum, the required measures cover:
- Risk analysis and information system security policies
- Incident handling
- Business continuity, including backup management, disaster recovery, and crisis management
- Supply chain security, including the security of relationships with direct suppliers and service providers
- Security in the acquisition, development, and maintenance of systems, including vulnerability handling and disclosure
- Policies to assess how effective the cybersecurity measures actually are
- Basic cyber hygiene practices and cybersecurity training
- Policies on cryptography and encryption
- Human resources security, access control, and asset management
- Multi-factor authentication and secure communications, where appropriate
Governance: management bodies are on the hook
NIS2 puts accountability at board level. Management bodies of essential and important entities have to approve the organization's cybersecurity risk-management measures, oversee how they're carried out, and can be held personally liable for infringements. NIS2 also requires management body members to complete cybersecurity training, and encourages organizations to extend similar training to employees generally.
This board-level accountability isn't unique to cybersecurity law. SOX requires similarly personal executive sign-off over financial reporting controls. France's Sapin II law goes further for large companies, mandating one of eight specific anti-corruption measures rather than leaving the approach up to the board. And the EU Anti-Corruption Directive treats a genuine, resourced compliance program, not a paper one, as a mitigating factor when a corruption case reaches court.
Incident reporting: the clock starts fast
When a significant incident occurs, NIS2 sets tight deadlines. Organizations must send an early warning to their national competent authority or CSIRT within 24 hours of becoming aware of the incident, followed by a fuller incident notification within 72 hours. A final report follows once the incident is resolved, covering its cause, impact, and any cross-border effects.
In May 2026, the NIS2 Cooperation Group adopted common templates for these reports, aiming to standardize the format across member states and cut the administrative burden of reporting the same incident under multiple national systems. The European Commission is expected to make the templates mandatory through an implementing act.
Cooperation and crisis response
NIS2 also builds EU-level infrastructure for cooperation. Each member state's CSIRT feeds into a network that shares threat intelligence and coordinates incident response. For large-scale incidents, the European Cyber Crisis Liaison Organisation Network (EU-CyCLONe) coordinates a joint response across member states and EU institutions. The NIS Cooperation Group, made up of member states, the Commission, and ENISA, publishes non-binding guidance to support consistent implementation.
Enforcement
National competent authorities can inspect essential and important entities, request evidence of compliance, and issue binding instructions. They also have the power to impose administrative fines for non-compliance. Several member states are still finalizing their national transposition of NIS2, and the Commission continues to pursue enforcement action against countries that missed the October 2024 deadline.
How NIS2 relates to other EU rules you may already track
NIS2 isn't the only cybersecurity or resilience law in play. For financial entities, the Digital Operational Resilience Act (DORA) takes precedence: where DORA's ICT risk-management, incident reporting, resilience testing, and third-party risk rules apply, they replace the equivalent NIS2 provisions for that entity. Outside financial services, NIS2 remains the baseline.
If your organization also deploys high-risk AI systems in a NIS2-covered sector, you don't need two parallel risk-management processes. Under Article 9(10) of the EU AI Act, providers already meeting risk-management duties under other EU law, NIS2 among them, can fold their AI risk management into the same process.
NIS2 also sits alongside, not instead of, the EU Whistleblowing Directive. The two protect different things: NIS2 protects systems and services, the Whistleblowing Directive protects people who report wrongdoing. But the overlap already exists in the text of both laws. The Whistleblowing Directive lists privacy, data protection, and network and information security as one of its own protected reporting categories, so a report about a security incident can already trigger an organization's existing whistleblowing obligations, on top of any separate duty to notify authorities under NIS2.
What's changing next
On 20 January 2026, the European Commission proposed targeted amendments to NIS2 as part of a wider cybersecurity package, aimed at simplifying compliance and increasing legal clarity. The Commission estimates the changes would ease compliance for around 28,700 companies, including 6,200 micro and small enterprises. These are proposals, not yet law, so the current NIS2 requirements still apply in full until the EU formally adopts any changes. For a detailed, continuously updated breakdown of NIS2's articles, deadlines, and national transposition status, see the NIS2 Directive resource site maintained by Cyber Risk GmbH.
How SpeakUp supports your reporting and governance obligations
SpeakUp doesn't replace the technical security controls NIS2 requires. Intrusion detection, backups, and encryption stay with your IT and security teams. What SpeakUp Report gives you is a structured intake and case management channel: employees, contractors, and third parties can flag a suspected security incident, policy gap, or governance failure the same way they'd report any other type of misconduct, anonymously if they choose.
Every report lands in one auditable system with clear ownership, timestamps, and escalation paths. That system directly supports the incident-handling and effectiveness-review measures NIS2 requires. It also gives a management body something concrete to show: a working channel where cybersecurity concerns actually surface, with a full audit trail behind it.
If your organization's reporting program already runs through SpeakUp, extending it to capture NIS2-relevant reports is a configuration change, not a new system. Book a demo to see how it fits your setup, or visit our whistleblowing software page for the full picture on secure reporting and case management.
Frequently asked questions
What is the NIS2 Directive?
The NIS2 Directive (Directive (EU) 2022/2555) is the EU's cybersecurity law for network and information systems. It replaces the original 2016 NIS Directive and requires medium and large organizations across 18 critical sectors to manage cybersecurity risk, report significant incidents quickly, and make management bodies accountable for compliance.
Which organizations does NIS2 apply to?
NIS2 applies to medium and large entities operating in 18 sectors, including energy, transport, healthcare, finance, digital infrastructure, public electronic communications, waste and wastewater management, manufacturing of critical products, postal and courier services, space, and public administration at central and regional level. NIS2 excludes defense, national security, public security, law enforcement, the judiciary, parliaments, and central banks.
What are the NIS2 incident reporting deadlines?
Organizations must send an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report once the incident is resolved.
How is NIS2 different from the original NIS Directive?
NIS2 covers far more sectors and applies a size-cap rule, so most medium and large entities fall into scope automatically. It also replaces the operator-of-essential-services and digital-service-provider split with "essential" and "important" entity categories, and adds explicit management body accountability, including personal liability for infringements.
How does NIS2 relate to DORA?
For financial entities, DORA is treated as sector-specific legislation. Where DORA's ICT risk-management and incident-reporting rules apply, they take the place of the equivalent NIS2 provisions for that entity. NIS2 continues to apply as the baseline for sectors DORA doesn't cover.
What happens if an organization doesn't comply with NIS2?
National authorities can inspect essential and important entities, demand evidence of compliance, and impose administrative fines. They can also hold management bodies personally liable for failing to approve or oversee the required cybersecurity risk-management measures.
