Compyl

The Complete Guide to NIS2 Compliance

August 11, 2026
Regulation · NIS2

The Complete Guide to NIS2 Compliance

By Compyl ResearchLast updated: August 11, 202612 min read

NIS2 is the EU directive (Directive (EU) 2022/2555) requiring essential and important entities across 18 sectors to implement ten minimum cybersecurity measures, report significant incidents within 24 and 72 hours, and hold management personally accountable. It binds companies through national transposition laws, with fines reaching EUR 10 million or 2% of global annual turnover.

Key takeaways
  • NIS2 applies to entities in 18 sectors that are medium-sized or larger (roughly 50+ staff, or turnover and balance sheet above EUR 10 million), plus named entity types such as DNS providers and trust service providers regardless of size.
  • Essential and important entities owe the same obligations under Articles 21 and 23. The difference is supervision (proactive ex ante audits vs. ex post) and maximum fines: EUR 10 million or 2% of global turnover vs. EUR 7 million or 1.4%.
  • Incident reporting runs on one clock: early warning in 24 hours, full notification in 72 hours, final report within one month. For digital providers, a loss above EUR 500,000 or 5% of turnover is automatically significant.
  • Management bodies must approve and oversee the security measures, must complete training, and can be held liable. For essential entities, authorities can temporarily bar a CEO or legal representative from managerial functions.
  • Transposition is still incomplete: on July 8, 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice, seeking lump-sum and daily penalties. Obligations are already live and enforced in Germany, Belgium, Italy and most other member states.

What Is NIS2 and Why Does It Matter Now?

NIS2 is Directive (EU) 2022/2555, adopted on December 14, 2022. It replaced the original 2016 NIS Directive, widened the scope from a handful of “operators of essential services” to 18 sectors, and set a transposition deadline of October 17, 2024 for all 27 member states.

The single most important structural fact about NIS2 is that it is a directive, not a regulation. Unlike GDPR or DORA, NIS2 creates no directly binding obligation on your company. What binds you is the national law that transposes it — the German BSIG, the Dutch Cyberbeveiligingswet, the Belgian NIS2 law. The directive sets the floor; member states go further, and their registration portals, incident thresholds, and supervisory authorities all differ.

Annex I lists 11 “sectors of high criticality”: energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management (B2B), public administration, and space. Annex II adds seven “other critical sectors”: postal and courier services, waste management, chemicals, food, manufacturing, digital providers, and research.

The regulatory pressure is measurable. In its NIS360 2026 report, published May 28, 2026, ENISA found that 70% of surveyed organizations named regulatory compliance with NIS2, DORA, and the Cyber Resilience Act as the main driver of their cybersecurity investment over the previous year, and that 90% had implemented controls to manage supply chain risk. Only 35% reported faster incident detection as a result.

NIS2 at a glance
  • Legal basis: Directive (EU) 2022/2555, in force through national transposition laws.
  • Scope: 18 sectors, medium-sized entities and larger, plus named entity types regardless of size.
  • Core duties: 10 minimum risk-management measures (Art. 21), incident reporting at 24h/72h/1 month (Art. 23), management accountability (Art. 20).
  • Maximum fines: EUR 10 million or 2% of global turnover (essential), EUR 7 million or 1.4% (important).

Who Has to Comply With NIS2?

Start with the size test. Under Article 2(1), NIS2 applies to entities of a type listed in Annex I or II that qualify as medium-sized enterprises or exceed those ceilings. The EU SME definition in Recommendation 2003/361/EC puts the medium-sized band at fewer than 250 staff with turnover up to EUR 50 million or a balance sheet up to EUR 43 million, and the small band at fewer than 50 staff with turnover or balance sheet up to EUR 10 million. In practice that means roughly 50 employees, or more than EUR 10 million in turnover and balance sheet total, is where NIS2 starts to bite — and firms that are part of a larger group may have to count group figures.

Then apply Article 3. Entities in an Annex I sector that exceed the medium-sized ceilings are essential entities; everything else in scope is an important entity. Obligations under Articles 21 and 23 are identical for both. The difference is how you are supervised and how hard you can be hit.

The size test is not the whole test

Article 2(2) pulls certain entities in regardless of size: providers of public electronic communications networks and services, trust service providers, TLD name registries and DNS service providers, any entity that is the sole provider in a member state of a service essential to critical societal or economic activity, entities whose disruption could significantly affect public safety or induce systemic risk, and central government bodies. Article 2(3) captures every entity identified as critical under the CER Directive, and Article 2(4) captures domain name registration services.

What about non-EU companies?

Article 26 decides jurisdiction. Most entities answer to the member state where they are established. But cloud, data center, CDN, managed service and managed security service providers, online marketplaces, search engines and social platforms are governed by the state of their main establishment — defined as where cybersecurity risk-management decisions are predominantly taken. If those decisions are not taken in the EU, the test falls back to where cybersecurity operations run, then to the largest EU workforce.

Providers in that group with no EU establishment that offer services in the Union must designate an EU representative and fall under that representative’s member state. Without one, any member state where the service is offered can take legal action. US-headquartered SaaS and infrastructure providers routinely underestimate this; our guide to DORA and NIS2 for US companies works through the exposure in more detail.

Dimension Essential entities Important entities
Who qualifies Annex I entities above the medium-sized ceilings; qualified trust service providers, TLD name registries and DNS providers regardless of size; medium-sized electronic communications providers; central government; CER Directive critical entities Everything else in scope: medium-sized Annex I entities, and medium and large Annex II entities
Example sectors Energy, transport, banking, financial market infrastructures, health, water, digital infrastructure, ICT service management, public administration, space Postal and courier, waste, chemicals, food, manufacturing, online marketplaces and search engines, social platforms, research
Size threshold 250+ staff, or turnover above EUR 50 million and balance sheet above EUR 43 million 50+ staff, or turnover and balance sheet above EUR 10 million
Supervision Ex ante: inspections, random checks, regular and targeted audits, security scans, evidence requests — no suspicion required Ex post: authorities act on evidence or information of non-compliance
Maximum administrative fine At least EUR 10 million or 2% of total worldwide annual turnover, whichever is higher At least EUR 7 million or 1.4% of total worldwide annual turnover, whichever is higher
Extra enforcement powers Temporary suspension of a certification or authorization; temporary ban on the CEO or legal representative exercising managerial functions None

Where Does NIS2 Transposition Stand in August 2026?

Unevenly. As of August 11, 2026, NIS2 is in force across most of the EU and still not law in three of its largest economies.

The enforcement trail is easy to follow. On November 28, 2024 the Commission sent letters of formal notice to 23 member states that had missed the October 17, 2024 deadline. On May 7, 2025 it issued reasoned opinions to 19 of them. Then on July 8, 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice, asking the Court to impose financial sanctions consisting of a lump sum and daily penalties until each country notifies complete transposition.

The Netherlands has since closed its gap: the Cyberbeveiligingswet enters into force on August 15, 2026, covering more than 8,000 Dutch organizations with no general transition period. Ireland, Spain and France remain outstanding on the Commission’s own country pages.

Where transposition has happened, supervision is already real. Germany’s NIS2 implementation act took effect on December 6, 2025, and according to the BSI it applies to more than 29,500 companies, roughly five times the population covered by the old NIS regime. The BSI registration portal opened on January 6, 2026, registration is a statutory duty under Section 33(6) BSIG, and the BSI now states plainly that the statutory registration deadline has expired and unregistered in-scope entities should register immediately.

Do not read the delay as a reprieve

Two traps catch multinational groups. First, obligations bite entity by entity: a German subsidiary is regulated today even if the French parent is not. Second, the rules are still moving. On January 20, 2026 the Commission proposed targeted amendments to NIS2 (COM(2026) 13) to simplify jurisdiction rules, streamline ransomware data collection, and improve cross-border supervision with a larger coordinating role for ENISA — benefiting an estimated 28,700 companies including 6,200 micro and small enterprises. That proposal is not adopted. Nothing about it changes what a regulated entity owes today.

What Are the 10 Minimum Security Measures Under Article 21?

Article 21(1) requires “appropriate and proportionate technical, operational and organisational measures” based on state of the art, cost of implementation, and the entity’s exposure and size. Article 21(2) sets the floor: an all-hazards approach including at least these ten measures.

  1. Policies on risk analysis and information system security
  2. Incident handling
  3. Business continuity, such as backup management, disaster recovery, and crisis management
  4. Supply chain security, including the security of relationships with direct suppliers and service providers
  5. Security in acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure
  6. Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures
  7. Basic cyber hygiene practices and cybersecurity training
  8. Cryptography and, where appropriate, encryption policies and procedures
  9. Human resources security, access control policies and asset management
  10. Multi-factor or continuous authentication, secured voice, video and text communications, and secured emergency communications within the entity, where appropriate

Two of these carry more weight than their one-line phrasing suggests. Article 21(3) says supply chain measures must account for the vulnerabilities of each direct supplier, the overall quality of their products and cybersecurity practices, and their secure development procedures. And measure (f) — assessing effectiveness — is what turns a policy library into a defensible program, because it obliges you to test whether controls actually work. Article 21(4) then requires corrective action without undue delay once you find that you do not comply.

Where the requirements get specific

For digital infrastructure and digital providers, the vagueness disappears. Commission Implementing Regulation (EU) 2024/2690 of October 17, 2024 converts the ten measures into detailed technical requirements for DNS providers, TLD registries, cloud and data center providers, CDNs, managed service and managed security service providers, online marketplaces, search engines, social platforms, and trust service providers. It is built on ISO/IEC 27001, ISO/IEC 27002, ETSI EN 319 401 and CEN/TS 18026:2024. Where a requirement applies “where appropriate” and you decide it is not, the regulation requires you to document your reasoning in a comprehensible manner.

Entities outside that group should still treat the Implementing Regulation as the reference standard, alongside ENISA’s NIS2 Technical Implementation Guidance, published June 25, 2025. Both give supervisors a yardstick. Before you map controls, run a documented cybersecurity risk assessment — every Article 21 measure is proportionate to risk, and you cannot demonstrate proportionality without recorded risk analysis.

What Does NIS2 Require of Executives and Boards?

Article 20 is short and consequential. Management bodies of essential and important entities must approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for the entity’s infringements of Article 21. Article 20(2) then requires members of those management bodies to follow training so they can identify risks and assess cybersecurity risk-management practices, and encourages equivalent training for employees.

This is not symbolic. BSI President Claudia Plattner frames NIS2 as making cybersecurity a matter for the chief executive, and the BSI publishes a management training package (NIS-2-Geschaeftsleitungsschulung, April 17, 2026) for that obligation.

The sharpest tool sits in Article 32(5). Where softer enforcement measures against an essential entity have proven ineffective and a remediation deadline passes unmet, competent authorities can suspend a certification or authorization covering part or all of the entity’s services, and request a temporary ban on any natural person with managerial responsibility at CEO or legal representative level from exercising those functions. The directive limits this to a last resort, applied only until the deficiencies are remedied, with full procedural safeguards. Important entities are not subject to these two powers.

Member states can add personal exposure. Under the Dutch Cyberbeveiligingswet, individual board members can face fines of up to EUR 25,000 for failing to meet the knowledge and training requirement. For boards, the practical minimum is a documented approval of the risk-management program, dated training records, a standing cyber item on the agenda, and minutes that show oversight rather than a briefing.

How Fast Must You Report an Incident Under NIS2?

Fast, and in stages. Article 23 sets one clock that starts when you become aware of a significant incident, and everything else hangs off it.

  • Within 24 hours: an early warning to the CSIRT or competent authority, flagging whether the incident is suspected to be caused by unlawful or malicious acts or could have cross-border impact.
  • Within 72 hours: an incident notification updating the early warning, with an initial severity and impact assessment and, where available, indicators of compromise. Trust service providers must file this within 24 hours.
  • On request: an intermediate report with relevant status updates.
  • Within one month of the notification: a final report covering a detailed description, severity and impact, the likely root cause or threat type, applied and ongoing mitigations, and any cross-border impact.
  • If the incident is still running: a progress report at the one-month mark, and a final report within one month of the incident being handled.

You must also inform recipients of your services, without undue delay, where a significant incident is likely to adversely affect service delivery, and tell them about remedies for significant cyber threats. In return, the CSIRT should respond to the early warning within 24 hours where possible. Article 23(1) makes it clear that the act of notification itself does not increase your liability.

What counts as “significant”?

Article 23(3) defines a significant incident as one that has caused or is capable of causing severe operational disruption or financial loss for the entity, or considerable material or non-material damage to others. For the digital sector, Implementing Regulation (EU) 2024/2690 replaces that judgment call with thresholds. An incident is significant where it causes or could cause direct financial loss above EUR 500,000 or 5% of annual turnover, whichever is lower; where it exfiltrates trade secrets; where it causes death or considerable damage to health; or where there has been successful, suspectedly malicious unauthorized access capable of causing severe operational disruption. Smaller events aggregate: incidents with the same apparent root cause occurring at least twice in six months are treated collectively as one significant incident.

Sector thresholds get more precise still: for cloud computing providers, complete unavailability for more than 30 minutes is significant, as is degraded availability lasting over an hour and affecting 5% of EU users or one million EU users, whichever is smaller. Build these thresholds into your severity matrix now — a 24-hour clock leaves no room to work out who decides and who signs.

What Are the Penalties for NIS2 Non-Compliance?

Article 34 sets the fine floors that member states must implement. For infringements of Article 21 or Article 23, essential entities face administrative fines with a maximum of at least EUR 10 million or at least 2% of total worldwide annual turnover in the preceding financial year, whichever is higher. Important entities face at least EUR 7 million or 1.4%. Member states may also impose periodic penalty payments to force an ongoing infringement to stop.

Supervision differs sharply by class, and this is the practical reason the essential/important distinction matters. Under Article 32, authorities can subject essential entities to on-site inspections, off-site supervision, random checks, regular and targeted security audits, ad hoc audits, security scans, and demands for evidence of implemented policies — proactively, with no trigger required. The cost of a targeted audit carried out by an independent body is generally paid by the audited entity. Under Article 33, important entities are supervised ex post: authorities act when they have evidence, indication or information suggesting non-compliance.

Overlap with GDPR is handled, partly. Article 35 requires competent authorities to inform data protection authorities where a NIS2 infringement may entail a notifiable personal data breach. If the DPA imposes a GDPR fine for that same conduct, the NIS2 authority may not also impose an Article 34 fine — but it can still apply the other enforcement measures, including the Article 32(5) suspension and management-ban powers.

Financial entities should also watch the DORA boundary. Where the DORA regulation applies as lex specialis for ICT risk management and incident reporting, it takes precedence for those entities. Sort out which regime governs which obligation at the start of your program, not after your first incident.

How Do You Build a NIS2 Compliance Program?

A NIS2 program is mostly ordinary security work, sequenced around two immovable dates: your national registration deadline and the 24-hour reporting clock. Work through it in this order.

  1. Determine scope per legal entity, and record the reasoning. Map each entity to Annex I or II, apply the size test, check the regardless-of-size hooks in Article 2(2)-(4), and settle jurisdiction under Article 26. Non-EU providers in the Article 26(1)(b) group must appoint an EU representative. Keep the analysis as a document — a supervisor’s first question is why you concluded what you concluded.
  2. Register with each national authority, on their timetable. Registration is a separate legal duty from security compliance and it is the easiest violation for a regulator to spot. Germany’s window under Section 33(6) BSIG has already closed; the Dutch NCSC portal opens with the law on August 15, 2026.
  3. Run a gap assessment against Article 21, not against a generic checklist. Assess all ten measures, using Implementing Regulation (EU) 2024/2690 and the ENISA guidance as the yardstick. If you already hold ISO/IEC 27001, most control text maps across, but supply chain depth, effectiveness testing, and incident reporting speed are where certified organizations still fail.
  4. Fix the supply chain, then keep it fixed. Article 21(2)(d) and 21(3) require supplier-specific risk assessment and contractual security requirements. Practical implementation is a tiered vendor inventory, security clauses with incident notification timelines that let you meet your own 24-hour deadline, and periodic reassessment. Our guidance on third-party due diligence covers the mechanics.
  5. Build the reporting machine and test it. Define significance thresholds in your severity matrix, name the decision-maker for filing, pre-draft early warning and notification templates per jurisdiction, and rehearse a cross-border scenario against the clock. Track the one-month final report as a deliverable with an owner.
  6. Put governance in writing. Board approval of the risk-management measures, dated management training records, and a review cadence that survives auditor scrutiny. Article 20 makes this the management body’s job, not the CISO’s alone.
  7. Move to continuous evidence. Ex ante supervision means an essential entity can be audited without warning, and audit costs usually land on the audited entity. Continuously collected evidence — access reviews, patch metrics, backup restoration tests, supplier attestations — converts an audit from a fire drill into an export. Mapping NIS2 alongside your other compliance frameworks avoids running parallel evidence programs for one control set.

One closing point on timing: where transposition has happened there is generally no grace period, and where it has not, the national law lands with immediate effect once it does, as the Dutch example shows. The organizations that will struggle in 2027 are those treating a delayed transposition as extra runway.

Frequently asked questions

Is NIS2 mandatory for my company?
It is mandatory if you operate in one of the 18 Annex I or II sectors and qualify as medium-sized or larger, or fall into a regardless-of-size category such as DNS or trust service providers. The binding obligation comes from your member state’s transposition law, not the directive itself.
What is the difference between essential and important entities under NIS2?
Both owe identical security and reporting obligations. Essential entities are large Annex I organizations and face proactive ex ante supervision, fines up to EUR 10 million or 2% of global turnover, and possible suspension of authorizations. Important entities are supervised only after evidence of non-compliance, with fines capped at EUR 7 million or 1.4%.
Does NIS2 apply to US companies?
Yes, if you provide in-scope services in the EU. Cloud, data center, CDN, managed service and marketplace providers without an EU establishment must designate an EU representative under Article 26, and they fall under the jurisdiction of that representative’s member state. Without one, any member state where you operate can act.
What are the NIS2 incident reporting deadlines?
An early warning to your CSIRT or competent authority within 24 hours of becoming aware of a significant incident, a fuller incident notification within 72 hours, an intermediate report on request, and a final report within one month of the notification. Trust service providers must notify within 24 hours.
Which countries have not transposed NIS2 yet?
As of August 11, 2026, Ireland, Spain and France have not notified full transposition. The Netherlands adopted its Cyberbeveiligingswet after being referred to the Court of Justice on July 8, 2026, and that law enters into force on August 15, 2026 covering more than 8,000 organizations.
Does ISO 27001 certification make you NIS2 compliant?
No, but it covers a large share of the ground. Implementing Regulation (EU) 2024/2690 is explicitly built on ISO/IEC 27001 and 27002. Gaps typically remain in supply chain depth, measuring control effectiveness, statutory registration, management training records, and the 24-hour incident reporting capability.

Run Your NIS2 Program in Compyl

Compyl maps NIS2’s Article 21 measures against the frameworks you already run, automates control evidence so an ex ante audit becomes an export rather than a fire drill, and keeps supplier risk, incident timelines, and board-level attestations in one place. Built by CISOs who have carried the reporting clock themselves.

Request a demo →

About this guide. By Compyl Research. Last updated August 11, 2026. This is general information, not legal advice — consult counsel for your specific obligations. Compyl is an AI-powered, agentic GRC platform built by CISOs.


Monitoring thousands of environments daily
By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies