EU Regulatory Center
NIS2 — cybersecurity risk management and incident reporting
Cybersecurity risk-management measures and incident-reporting obligations for essential and important entities across the EU.
Status
Law in force
Directive (EU) 2022/2555
NIS2 repeals and replaces the original NIS Directive, widening sectoral scope and introducing stricter risk-management, incident-reporting and management-body accountability obligations. EU Member States were required to transpose NIS2 into national law by 17 October 2024; national transposition and enforcement timelines vary by country.
Scope at a glance
| Question | Answer |
|---|---|
| Who | Essential and important entities across roughly 18 sectors, sized above defined thresholds (with some sector-specific exceptions). |
| What | Risk-management measures covering supply chain, access control, incident handling, business continuity and more. |
| Reporting | Early warning within 24 hours, incident notification within 72 hours, and a final report within one month of a significant incident. |
| Accountability | Management bodies must approve risk-management measures and can be held accountable for compliance failures. |
Core obligations
- Implement risk-management measures proportionate to the entity’s size and risk exposure.
- Report significant incidents to the competent national authority within the required timelines.
- Address supply-chain and third-party risk as part of the risk-management measures.
- Ensure management-body oversight and training on cybersecurity risk.
General guidance, not legal advice
This page summarizes publicly available regulatory status for general guidance only. Confirm applicability, scope and deadlines with qualified legal counsel before making compliance decisions.
How CYRKIL helps
Regulatory Intelligence maps NIS2 requirements to controls and evidence, and the Fused Risk view shows exposure in the same terms an auditor will ask about.
See Regulatory ReadinessHow CYRKIL tracks this
Every regulatory page here runs through the Regulatory Truth Pipeline — official source, human and legal review, then publish, with the source, version and review date always shown.
See the pipeline