We use a few strictly-necessary cookies, no marketing trackers, and cookieless analytics. Read our cookie policy, or pick a preference.
The EU's baseline for cybersecurity resilience, and the first of these regimes to put the duty on the boardroom by name. It requires essential and important entities across eighteen sectors to manage cyber risk, report incidents on a tight clock, and have their management bodies personally approve and oversee the measures.
NIS2 widened the old NIS regime to eighteen sectors and two classes of entity, and it raised the stakes by making cyber risk a governance obligation rather than a purely technical one. The measures are proportionate to risk, but the reporting clock is not: an early warning is due within 24 hours, a fuller notification within 72 hours, and a final report within one month.
For AI, the point is that models and their pipelines are part of the network and information systems that must be secured, and AI vendors fall inside the supply-chain security duty. An AI incident can trip NIS2 reporting and AI Act Article 73 reporting at the same time, on different clocks.
Management bodies approve the risk measures, oversee them, and take training. Duties they cannot delegate away.
Ten baseline measures: policies, incident handling, continuity, supply-chain security, testing, crypto, access, MFA.
Early warning in 24 hours, notification in 72 hours, final report within one month of the significant incident.
Audits, inspections, binding instructions, and, for essential entities, sanctions that reach individuals.
NIS2 requires the management body of an essential or important entity to approve the cybersecurity risk-management measures, to oversee their implementation, and to follow cybersecurity training. Members can be held personally liable for the entity's infringements, and for essential entities a supervisory authority may temporarily ban an individual from exercising management functions until the failing is fixed. Cyber risk is, by design, no longer something the board can leave entirely to the security team.
NIS2 applies through national transposition. The EU deadline has passed; some member states legislated late, so the exact text and authority depend on where you operate.
Directive enters into force, replacing the 2016 NIS Directive.
Deadline for member states to transpose NIS2 into national law.
National regimes come into effect and enforcement begins; registration duties apply.
Source: Official Journal of the EU · confirm the transposing national law in each member state you operate in
Scope turns on your sector and size. The class you fall into sets the intensity of supervision and the size of the fine.
Energy, transport, banking, health, water, digital infrastructure, ICT management, public administration, space. Proactive supervision and the highest fines.
Postal, waste, chemicals, food, manufacturing, digital providers, research. Supervised after the fact, with lower ceilings.
Approve and oversee the measures, take training, and carry personal liability under Article 20.
Article 21 pulls supplier security inside your duty, so vendor and model-provider risk becomes your obligation to manage.
Monetary ceilings are set against worldwide annual turnover, and the personal consequences sit alongside them.
| Against | Exposure |
|---|---|
| €10M / 2%whichever is higher | Essential entities, for failing the risk-management or reporting duties. |
| €7M / 1.4%whichever is higher | Important entities, for the equivalent failures. |
| Personalbans + liability | Management-body members: personal liability, and temporary bans from management functions in essential entities. |
Figures per NIS2 Article 34 · national implementations may set additional or higher penalties · confirm locally
"Cybersecurity is the security team's problem, not the board's."
Article 20 makes the management body approve and oversee the measures, take training, and carry personal liability. It is a governance duty now, not only a technical one.
"We're not critical national infrastructure, so NIS2 doesn't reach us."
NIS2 covers eighteen sectors and most medium and large organisations within them, including manufacturing, food, waste, and digital providers. The scope is far wider than the old regime.
"We can assess an incident properly before we report it."
An early warning is due within 24 hours of becoming aware of a significant incident, well before full analysis. The reporting workflow has to be ready in advance.
NIS2 applies to medium and large entities in the sectors listed in Annexes I and II (energy, transport, banking, health, digital infrastructure, ICT service management, public administration, and more), classifying them as "essential" or "important" entities. Size generally means 50+ staff or over EUR 10 million turnover, though some entities are in scope regardless of size.
For essential entities, fines can reach at least EUR 10 million or 2% of total worldwide annual turnover, whichever is higher. For important entities, the ceiling is at least EUR 7 million or 1.4%, whichever is higher (Article 34). NIS2 sets these as minimum maximums, so national transposition may go further.
Member States had to transpose NIS2 into national law by 17 October 2024, with national measures applying from 18 October 2024. NIS2 is a directive, so the operative obligations live in each Member State's implementing law; transposition has run late in several states.
Yes. NIS2 makes management bodies responsible for approving and overseeing cybersecurity risk-management measures (Article 20), and Member States can hold senior management personally accountable, including temporary bans from management roles for essential entities in cases of serious, repeated non-compliance. Board-level engagement is a legal requirement, not a recommendation.
Article 23 sets a multi-stage timeline for significant incidents: an early warning within 24 hours of becoming aware, a fuller incident notification within 72 hours, and a final report within one month. This is stricter and more prescriptive than the original NIS Directive.
Not necessarily. NIS2 substantially widens the sectors and entity types in scope, tightens risk-management and reporting duties, adds management accountability, and raises penalties. Many organisations newly fall in scope or face heavier obligations than under the 2016 regime, so prior NIS compliance is a starting point, not sufficiency.
A financial entity meets NIS2 and DORA together; an AI system meets the AI Act's security and incident duties as well. We map at the level of the obligation, so one control satisfies many.