Licensed by the Estonian FIU · FIU000117Operating since 2014Punane 6, Tallinn

info@micaconsult.com+372 5089565

LexorCorp Global

Guide

What is NIS2? The EU cybersecurity directive explained

The NIS2 Directive in plain terms: where it comes from, how it becomes national law, and the four things it asks of every company within its scope.

LexorCorp Global OÜ · published 30 September 2026

NIS2 is the European Union's cybersecurity directive for companies and public bodies that keep the economy and society running. Its full title is Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. It entered into force in January 2023 and replaced the first NIS Directive (EU) 2016/1148. This guide explains, in the terms a corporate lawyer would use with a client, what the directive is, how it becomes binding on a company, and what it asks a company in its scope to do.

The guide is general information, not legal advice.

Why the EU replaced the first NIS Directive

The first NIS Directive of 2016 left it to each Member State to identify "operators of essential services". The results differed widely: comparable companies were covered in one country and not in the next, and supervision and sanctions were uneven. NIS2 replaces case-by-case identification with a rule: an entity is in scope if it is of a type listed in the directive's annexes and reaches the size threshold. It also widens the list of sectors, puts the management body in charge, harmonises incident reporting and sets minimum levels for fines.

How a directive becomes binding on a company

A directive is addressed to the Member States. They had to adopt national laws transposing NIS2 by 17 October 2024 and apply them from 18 October 2024 (Article 41(1)). A company is therefore bound by its country's transposition act, not by the directive itself. In Estonia, for example, NIS2 is transposed through the Cybersecurity Act (küberturvalisuse seadus) and supervised by the Information System Authority (RIA). The national acts follow the structure of the directive but differ in details: the competent authority, the registration procedure, the exact deadlines and the level of fines. Several Member States transposed late, so the national position must always be checked in the act of the country concerned.

Who is covered, in one paragraph

NIS2 covers public and private entities of the types listed in Annex I (sectors of high criticality, such as energy, transport, banking, health, drinking water, digital infrastructure and ICT service management) and Annex II (other critical sectors, such as postal services, waste management, chemicals, food, manufacturing and digital providers) that are at least medium-sized: in practice 50 or more employees, or an annual turnover and a balance sheet total each above EUR 10 million (Article 2(1)). Some entities are covered regardless of size. Covered entities are either essential or important. The details are in the guide Who does NIS2 apply to?

The four core obligations

1. Governance and management responsibility (Article 20)

The management body must approve the cybersecurity risk-management measures, oversee their implementation and can be held liable for infringements. Its members must follow training so that they can identify risks and assess risk-management practices. Cybersecurity is therefore a board matter, not only an IT matter.

2. Cybersecurity risk-management measures (Article 21)

Entities must take appropriate and proportionate technical, operational and organisational measures, based on an all-hazards approach. Article 21(2) lists ten minimum areas:

  1. policies on risk analysis and information system security;
  2. incident handling;
  3. business continuity, such as backup management and disaster recovery, and crisis management;
  4. supply chain security, including the security of relationships with direct suppliers and service providers;
  5. security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure;
  6. policies and procedures to assess the effectiveness of the measures;
  7. basic cyber hygiene practices and cybersecurity training;
  8. policies and procedures on cryptography and, where appropriate, encryption;
  9. human resources security, access control policies and asset management;
  10. multi-factor or continuous authentication, and secured voice, video, text and emergency communications where appropriate.

Proportionality matters: the measures must reflect the entity's exposure to risk, its size, the likelihood and severity of incidents and the cost of implementation (Article 21(1)). For certain digital providers, Commission Implementing Regulation (EU) 2024/2690 sets out the technical and methodological requirements in detail.

3. Incident reporting (Article 23)

A significant incident — one that has caused or can cause severe operational disruption or financial loss, or considerable damage to others — is reported to the CSIRT or the competent authority in stages: an early warning within 24 hours of becoming aware of it, an incident notification within 72 hours, intermediate reports on request, and a final report no later than one month after the incident notification. Where appropriate, the recipients of the entity's services must be informed as well.

4. Registration (Articles 3(4) and 27)

Entities provide the competent authority with their name, address and contact details, IP ranges, sector and the Member States in which they operate, and report changes within two weeks. DNS service providers, top-level domain registries, cloud and data centre providers, managed service providers and certain online platforms register with additional information under Article 27.

Supervision and sanctions

Essential entities are supervised proactively, important entities after evidence or an indication of non-compliance. Member States must provide for maximum fines of at least EUR 10 million or 2% of worldwide annual turnover for essential entities and at least EUR 7 million or 1.4% for important entities (Article 34). See What happens without NIS2 compliance.

What NIS2 means in practice

For a company in scope, NIS2 compliance is a combination of documents and practice: written policies and plans that follow Article 21, management approval and training under Article 20, an incident procedure that can meet the 24-hour and 72-hour deadlines, registration with the authority, and evidence that the measures are actually applied. Documents alone do not make a company compliant, but without documents the company cannot show the authority — or its customers — what it does. Companies outside the scope are often affected as suppliers; see NIS2 supply chain requirements for suppliers.

Company-specific NIS2 documentation based on the national transposition law of 24 EU countries is available on nis2europe.eu, operated by AIPOS OÜ; the current prices are on nis2europe.eu/pricing. The overview of scope, obligations and fines is on the page NIS2 compliance documentation.

Ready to start? Scope, obligations, supply chain and fines on one page, with the link to the documentation on nis2europe.eu. NIS2 compliance documentation.

Frequently asked questions

What is the NIS2 Directive?

Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. It replaced the first NIS Directive (EU) 2016/1148 and had to be transposed into national law by 17 October 2024.

Does NIS2 apply directly to companies?

No. A directive binds the Member States, which transpose it into national law. Companies are bound by their country's transposition law, which may add national details.

What are the core obligations under NIS2?

Management approval and oversight of cybersecurity (Article 20), risk-management measures (Article 21), reporting of significant incidents (Article 23) and registration with the competent authority (Articles 3(4) and 27).

Related guides

More on this topic: NIS2 compliance documentation.

See what NIS2 requires from your company

Scope, obligations, supply chain and fines on one page, with the link to the documentation on nis2europe.eu.

NIS2 compliance documentation Go to nis2europe.eu