
NIS2 is the EU's second Network and Information Security Directive, Directive (EU) 2022/2555, and it dramatically widens the cybersecurity rules that used to apply to a small set of "operators of essential services." If you run a medium-sized or larger organisation in one of eighteen sectors, from energy and health to food, manufacturing, waste and digital services, the honest working assumption in 2026 is that NIS2 probably reaches you, and the question is not whether but as what. This guide answers the two things people actually search for: what NIS2 is, and who must comply. It is written for the compliance lead, IT director or founder who needs a clear answer before committing budget.
What NIS2 is, in one paragraph
NIS2 replaces the original 2016 NIS Directive. The first version covered a narrow group of essential operators and left too much to national discretion, so protection across the EU was uneven. NIS2 fixes that by expanding the sectors in scope, setting a common baseline of security measures, adding a strict incident-reporting timeline, and pushing accountability up to the management body with real penalties. It is a Directive, not a Regulation, which matters: it does not apply directly. Each of the 27 Member States transposes it into national law, so your precise obligations and the authority you answer to are national, even though the core rules are common. The EU-wide transposition deadline was 17 October 2024, and national laws have been landing since, some later than others.
Who must comply with NIS2: the scope test
Scope comes down to three questions in order: are you in a covered sector, are you above the size threshold, and does an exception apply. Work through them.
1. Are you in a covered sector?
NIS2 lists sectors in two annexes. Annex I (sectors of high criticality) covers energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management (business-to-business), public administration and space. Annex II (other critical sectors) covers postal and courier services, waste management, the manufacture and distribution of chemicals, food production, processing and distribution, certain manufacturing (including medical devices, computers and electronics, machinery, motor vehicles and other transport equipment), digital providers such as online marketplaces, search engines and social networking platforms, and research organisations. That is eighteen sectors in total, far more than NIS1.
2. Are you above the size threshold?
NIS2 generally applies to medium-sized and large entities in those sectors, meaning broadly 50 or more employees, or annual turnover or balance sheet above 10 million euro. Below that, you are usually out, with an important caveat: some entities are in scope regardless of size because of the criticality of what they do, for example DNS service providers, top-level-domain registries, trust service providers, providers of public electronic communications networks, and any entity that is the sole provider of a service critical to society in a Member State. Size is a filter, not the whole answer.
3. Does an exception or a national rule change it?
Member States can bring additional entities into scope, and sector-specific EU law can take precedence. The clearest example is finance: for banks and financial-market entities, the Digital Operational Resilience Act (DORA) is treated as the more specific regime for ICT risk, so those entities follow DORA rather than the equivalent NIS2 provisions. If you are unsure which applies, our guide to DORA versus NIS2 walks through the overlap.

Essential vs important entities: the split that changes your life
If you are in scope, NIS2 classifies you as either essential or important, and the difference is mostly about supervision, not obligations. The security measures and reporting duties are broadly the same for both, but the enforcement posture differs.
- Essential entities are the larger organisations in the Annex I high-criticality sectors. They face proactive supervision: authorities can inspect, audit and demand evidence before anything has gone wrong.
- Important entities are, broadly, the medium-sized organisations and those in the Annex II sectors. They face reactive supervision: authorities act on evidence of a problem rather than routinely.
Both can be fined, and both must meet the same baseline. The practical upshot is that essential entities should expect scrutiny without an incident, so "we will sort it out if asked" is not a strategy for them.
What NIS2 requires once you are in scope
Three obligations do most of the work, and they are where a compliance programme lives.
The ten Article 21 measures
Article 21 sets a minimum of ten risk-management measures: risk analysis and information-security policies; incident handling; business continuity and crisis management; supply-chain security; security in acquisition, development and maintenance including vulnerability handling; policies to assess the effectiveness of the measures; basic cyber hygiene and training; cryptography and encryption; human-resources security, access control and asset management; and multi-factor authentication and secured communications. These are the controls you have to implement and evidence.
Management accountability, Article 20
NIS2 makes the management body responsible. Directors must approve the cybersecurity measures, oversee their implementation, and follow training, and they can be held liable for failures. This is not a delegate-and-forget obligation, and it is one supervisors test.
The Article 23 reporting clock
For a significant incident, NIS2 imposes a three-stage clock: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, and a final report within one month, filed to your national CSIRT or competent authority.
Penalties and personal liability
NIS2 gives supervisors real teeth. For essential entities, administrative fines can reach up to 10 million euro or 2% of total worldwide annual turnover, whichever is higher; for important entities, up to 7 million euro or 1.4%. Beyond fines, authorities can order specific remediation and, in serious cases, temporarily suspend responsible individuals from management roles. Combined with the Article 20 accountability rule, that is why NIS2 is a board-level topic, not just an IT one.
Twenty-seven national laws, not one
Because NIS2 is a Directive, your actual obligations live in your Member State's transposition. Germany's NIS2 implementation, for example, carries its own registration and BSI duties; other states have their own portals, authorities and deadlines. If you operate in several countries, you are effectively subject to NIS2 several times over, and the registration and reporting mechanics differ each time. Confirm your national law and competent authority early, because that is where the filing actually happens.
What to do if you are in scope
- Confirm scope and role formally, per legal entity and per country: in scope or not, essential or important, and under which national law.
- Register with the national authority where required, within the national deadline.
- Run a gap assessment against the ten Article 21 measures and close the gaps, concentrating effort on incident reporting, supply chain and governance, which is where most organisations fall short.
- Stand up the Article 23 reporting workflow before you need it, so the 24-hour early warning is a process, not a scramble.
- Get the board engaged, approve the measures formally and record the Article 20 training.
- Reuse what you already have. If you hold ISO 27001 or run DORA, much of NIS2 overlaps; a crosswalk lets you satisfy the shared controls once.
For software to run all of this, see how Venvera handles NIS2, compare the market in our NIS2 compliance software round-up, or read the Vanta alternative for NIS2 comparison if you are choosing a tool.
Frequently Asked Questions
Who must comply with NIS2?
Broadly, medium-sized and large organisations (about 50 or more employees, or over 10 million euro turnover) operating in one of eighteen sectors across Annex I and Annex II of the Directive, plus certain entities that are in scope regardless of size because of the criticality of their service, such as DNS providers and trust service providers. Financial entities generally follow DORA instead for ICT risk.
What is the difference between essential and important entities?
Both must meet the same security and reporting obligations. The difference is supervision: essential entities (larger, Annex I sectors) face proactive audits and inspections, while important entities (medium-sized and Annex II sectors) face reactive supervision triggered by evidence of a problem. Both can be fined.
What is the difference between NIS2 and the original NIS Directive?
NIS2 widens the sectors in scope, sets a common EU baseline of ten security measures, adds a strict 24h/72h/1-month reporting clock, pushes accountability to the management body with personal liability, and raises penalties. NIS1 covered fewer operators and left more to national discretion, producing uneven protection.
What are the NIS2 fines?
For essential entities, up to 10 million euro or 2% of worldwide annual turnover, whichever is higher; for important entities, up to 7 million euro or 1.4%. Authorities can also order remediation and, in serious cases, temporarily suspend responsible managers.
Is NIS2 the same across the EU?
The core obligations are common, but NIS2 is a Directive transposed into 27 national laws, each with its own authority, registration process and deadlines. A multinational effectively complies per country. Confirm your national transposition and competent authority.
We already have ISO 27001. Are we compliant with NIS2?
Not automatically, but you are well on the way. ISO 27001 covers much of the Article 21 measures, but NIS2 adds the reporting clock, management-body accountability and training, supply-chain specifics and national registration. A crosswalk lets you reuse the overlap and focus on the genuinely new parts.
Primary sources
- Directive (EU) 2022/2555 (NIS2) - the governing text, including Annexes I and II (sectors), Article 20 (governance), Article 21 (measures), Article 23 (reporting) and Article 34 (penalties). EUR-Lex.
- ENISA - NIS2 Directive - implementation guidance and the essential/important framework. enisa.europa.eu.
Scope note. This guide summarises the common EU rules. Your precise obligations depend on your Member State's transposition; confirm your national law and competent authority before acting. Size thresholds and sector definitions follow the Directive and its annexes.
Confirmed you are in scope? Run NIS2 as the regulation.
Venvera handles NIS2 natively: a gap assessment against the ten Article 21 measures, the Article 23 24h / 72h / 1-month clock as a live workflow, management-body accountability and training, per-country scoping, and a crosswalk that reuses your ISO 27001 and DORA evidence. Flat pricing from EUR 399/month, EU data residency. See the NIS2 module or start with a free compliance check.
By Alexander Sverdlov, CEO and Founder, Venvera. Published 20 July 2026 - Last reviewed 20 July 2026.



