For most essential and important entities, NIS2 compliance takes six to twelve months to reach a defensible first pass, and twelve to eighteen months from a standing start with no ISO 27001 certificate, no supplier assessment programme and no rehearsed incident process. The range is wide because Directive (EU) 2022/2555 does not ask for a certificate by a date. It asks for ten categories of measures under Article 21(2), a management body that approved them and was trained under Article 20, and a reporting process that can produce an early warning within 24 hours under Article 23(4). Two of those three move at the pace of your suppliers and your board calendar, not your project plan.
The other thing to say first is that the legal dates have gone. Article 41 required Member States to transpose the Directive by 17 October 2024 and to apply the measures from 18 October 2024. The Article 27 registry information for digital infrastructure and digital service entities was due by 17 January 2025, and Article 3(3) required Member States to have their lists of essential and important entities by 17 April 2025. The question is no longer how long you have. It is how long you stay exposed.
| Phase | Typical duration | What gates it |
|---|---|---|
| Confirm scope, classification and registration | 2 to 4 weeks | One answer per legal entity per Member State: in scope or not, essential or important, and under which national law. |
| Gap assessment against Article 21(2) | 4 to 8 weeks | Access to the people who actually run the systems. Supply chain and effectiveness testing are usually the widest gaps. |
| Article 20 governance | 2 to 6 weeks, in parallel | The board calendar. A dated approval and a training record are quick once a meeting exists. |
| Article 23 reporting workflow | 4 to 8 weeks | Deciding who may file an early warning on incomplete information, and rehearsing it once. |
| Remediation and supply chain security | 3 to 9 months | Supplier response times and engineering capacity. This phase decides whether you land at 6 months or 18. |
| Evidence and effectiveness testing | Ongoing | Article 21(2)(f) requires policies to assess the effectiveness of the measures, so the programme never closes. |
How long does NIS2 compliance take?
Six to eighteen months, and the distribution inside that range is uneven. Scoping, the gap assessment and governance are predictable and short. Remediation and supply chain work are not, and they dominate the total.
A quick way to place yourself: can you show a board minute approving your cybersecurity risk-management measures, a list of direct suppliers with a security assessment against each, and a record of the last time someone rehearsed filing a 24 hour early warning? Three yeses put you at the six month end. Three shrugs put you at eighteen, because each one is a phase rather than a document.
What decides whether it takes 6 months or 18?
Four things, in descending order of impact.
1. Supplier count and supply chain maturity
Article 21(2)(d) requires supply chain security, including the security-related aspects of the relationships between the entity and its direct suppliers or service providers. Article 21(3) requires entities to take into account the vulnerabilities specific to each direct supplier and service provider and the overall quality of their products and cybersecurity practices, including their secure development procedures. That is an assessment per supplier, and suppliers answer on their own schedule. Fifty direct suppliers is a quarter of work. Five hundred is most of the year.
2. Whether you already hold ISO 27001
A certified information security management system covers a large part of the Article 21(2) list already: risk analysis policies, incident handling, business continuity, access control, cryptography and human resources security all have ISO equivalents. What it does not give you is the Article 23 reporting clock, the Article 20 management body duties, or the supplier-specific analysis in Article 21(3). Our guide to NIS2 vs ISO 27001 maps the overlap and the four gaps.
3. How many Member States you operate in
NIS2 is a Directive, so the obligations that bind you are in national law, and transposition has been uneven. The Commission sent letters of formal notice to 23 Member States on 28 November 2024 and reasoned opinions to 19 on 7 May 2025, and on 8 July 2026 it announced the referral of Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify transposing measures. A multi-country entity is therefore running several programmes with different registration mechanics and different authorities, even though the Article 21 substance is the same. The cost side of that multiplier is covered in NIS2 compliance cost.
4. Essential or important
Article 3 splits entities into essential and important. The measures are the same, but the supervision is not: essential entities can be audited with no incident first, important entities only after evidence of a problem. An essential entity has to reach evidenced compliance faster because the request for evidence can arrive at any time. If you have not settled which you are, start with what NIS2 is and who must comply. What the request for evidence looks like is in NIS2 audit: what to expect.
Which NIS2 dates matter now?
All of the Directive's own dates have passed, which changes what a timeline is for. You are not planning towards a deadline. You are shortening a period of exposure that began, at the latest, on 18 October 2024.
| Date | Provision | What happened |
|---|---|---|
| 16 January 2023 | Article 45 | The Directive entered into force, twenty days after publication in the Official Journal on 27 December 2022. |
| 17 October 2024 | Article 41(1) | Transposition deadline. Member States had to adopt and publish their national measures, and apply them from 18 October 2024. |
| 17 October 2024 | Article 21(5) | The Commission adopted Implementing Regulation (EU) 2024/2690, setting technical and methodological requirements for DNS, TLD, cloud, data centre, content delivery network, managed service, managed security service, online marketplace, search engine, social network and trust service providers. |
| 17 January 2025 | Article 27(2) | Entities in those same digital categories had to submit their registry information to competent authorities. |
| 17 April 2025 | Article 3(3) | Member States had to establish their lists of essential and important entities, to be reviewed at least every two years. |
If your entity is in one of the Article 27 categories, the Implementing Regulation is your actual specification for the Article 21 measures and for what counts as a significant incident. Read it before you scope, because it turns ten headings into a much longer list.
What has to be ready before the programme finishes?
Two obligations cannot wait for the end of the plan, because they can be tested on day one.
The first is the Article 23(4) clock. For a significant incident an entity must submit an early warning within 24 hours of becoming aware, an incident notification within 72 hours, and a final report not later than one month after the incident notification, with intermediate reports on request. An incident in month two of an eighteen month programme still runs on that clock. Name the person who may file on incomplete information, give them the CSIRT contact details, and rehearse once. That is weeks of work, and it should be the first thing finished.
The second is Article 20. The management body must approve the cybersecurity risk-management measures and oversee their implementation, and can be held liable for infringements (Article 20(1)). Its members must follow training (Article 20(2)). A dated approval and a training record are cheap, they are the first things a supervisor asks for, and they are the reason a board meeting belongs in the first month of the plan rather than the last. How the NIS2 clock sits next to the GDPR, DORA and CRA clocks is in incident reporting deadlines by regulation.
What the other results get wrong
Three errors recur.
The first is quoting a single number. Six months, nine months and twelve months all appear as the answer, and each describes one entity without saying so. Supplier count alone moves the total by two quarters.
The second is counting towards a deadline. Several ranking pages still present 17 October 2024 as a date to prepare for. It was the date by which Member States had to transpose, and it has passed. The relevant clock now is Article 23(4), which starts when you become aware of a significant incident.
The third is treating NIS2 as a certification project. There is no NIS2 certificate. Article 21(2)(f) requires policies and procedures to assess the effectiveness of your measures, which means the evidence has to stay current after the project closes. A plan that ends at go-live has funded the build and not the operation.
Estimate your own NIS2 timeline
Fill this in for one legal entity. Any row you cannot complete is a phase you have not started.
| Question | Your answer | Why it sets the clock |
|---|---|---|
| Essential or important, and in which Member States? | Sets your supervision exposure and the number of national regimes you answer to. | |
| How many of the ten Article 21(2) measures can you evidence today? | Each unevidenced measure is a remediation stream. | |
| How many direct suppliers do you have, and how many have a security assessment? | Article 21(2)(d) and 21(3). The longest phase scales with this number. | |
| Has the management body approved the measures and completed training? | Article 20. Quick to do, first to be asked for. | |
| Could you file a 24 hour early warning tomorrow? | Article 23(4). The one obligation that can be breached before the programme finishes. | |
| Do you hold ISO 27001 or already comply with DORA? | Reusable evidence shortens the gap assessment and remediation phases. |
If most rows are blank, start with a free compliance check against the ten measures. It will not close the supplier gap, but it will tell you which of the six phases above is going to take the time. Entities in financial services should also read DORA and NIS2 compared, since Article 2(10) removes from NIS2 the entities Member States have exempted from DORA under Article 2(4) of that Regulation, and the two regimes overlap for everyone else.
Frequently asked questions
Can we be NIS2 compliant in three months?
You can have scope confirmed, the board approval recorded, the reporting workflow rehearsed and a gap assessment finished in three months. You cannot usually have the supply chain assessed or the technical gaps closed. Three months buys defensibility on the obligations that get tested first, not completion.
Is there a NIS2 certificate we can get?
No. The Directive creates no certificate and no accredited NIS2 auditor. Article 24 lets Member States require the use of ICT products, services and processes certified under European cybersecurity certification schemes, which certifies technology rather than your entity.
Do we have to register somewhere?
Article 3(4) requires entities to submit at least their name, address and contact details, their sector and the Member States where they provide services, so that Member States can build the Article 3(3) list. Entities in the Article 27(1) categories, such as cloud, data centre, managed service and DNS providers, had to submit registry information by 17 January 2025. The mechanics are national, so check your competent authority's portal.
Does ISO 27001 make us compliant already?
No, but it removes months. The measures overlap heavily. The Article 20 duties, the Article 23 clock and the supplier-specific analysis in Article 21(3) are the gaps certification leaves.
What if our Member State has not finished transposing?
The obligations that bind you come from national law, and where it is incomplete your exact duties may not yet be fixed. The Article 21 substance is the same everywhere once it lands, the Commission is actively enforcing transposition, and a late national law is not a reason to have no measures. Build to the Directive now and adjust the mechanics when the national text arrives.
What are the penalties for taking too long?
Article 34 sets minimum ceilings for infringing Articles 21 or 23: at least 10 million euros or 2% of total worldwide annual turnover for essential entities, and at least 7 million euros or 1.4% for important entities, whichever is higher. The non-financial sanctions are in NIS2 fines and penalties.
Primary sources
Article references are taken from Directive (EU) 2022/2555 as published in the Official Journal on 27 December 2022: Articles 2, 3, 20, 21, 23, 24, 27, 34, 41 and 45, and Annexes I and II. The sector-specific requirements are in Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024. Enforcement dates come from the European Commission's referral announcement of 8 July 2026 and its NIS2 transposition tracker. Durations are planning estimates from implementation work, not figures from the Directive. Confirm your national transposing law before relying on a date.





