EU Regulatory Center

NIS2 — cybersecurity risk management and incident reporting

Cybersecurity risk-management measures and incident-reporting obligations for essential and important entities across the EU.

Status

Law in force
Directive (EU) 2022/2555
NIS2 repeals and replaces the original NIS Directive, widening sectoral scope and introducing stricter risk-management, incident-reporting and management-body accountability obligations. EU Member States were required to transpose NIS2 into national law by 17 October 2024; national transposition and enforcement timelines vary by country.
Reviewed 2026-06 · Source: Official Journal of the European Union

Scope at a glance

QuestionAnswer
WhoEssential and important entities across roughly 18 sectors, sized above defined thresholds (with some sector-specific exceptions).
WhatRisk-management measures covering supply chain, access control, incident handling, business continuity and more.
ReportingEarly warning within 24 hours, incident notification within 72 hours, and a final report within one month of a significant incident.
AccountabilityManagement bodies must approve risk-management measures and can be held accountable for compliance failures.

Core obligations

General guidance, not legal advice
This page summarizes publicly available regulatory status for general guidance only. Confirm applicability, scope and deadlines with qualified legal counsel before making compliance decisions.
How CYRKIL helps

Regulatory Intelligence maps NIS2 requirements to controls and evidence, and the Fused Risk view shows exposure in the same terms an auditor will ask about.

See Regulatory Readiness
How CYRKIL tracks this

Every regulatory page here runs through the Regulatory Truth Pipeline — official source, human and legal review, then publish, with the source, version and review date always shown.

See the pipeline

Get a readiness review against this regulation.