A comprehensive guide to Directive (EU) 2022/2555: what it is, who it applies to, obligations, and penalties for businesses.
NIS2 (Network and Information Security Directive 2) is European Directive 2022/2555 of the European Parliament and of the Council of 14 December 2022, establishing measures for a high common level of cybersecurity across the European Union.
It replaces and repeals the previous NIS Directive (2016/1148).
NIS2 applies to two categories of entities:
Medium to large entities in highly critical sectors:
Other critical sectors:
NIS2 applies to medium-sized enterprises as defined in Recommendation 2003/361/EC:
Micro-enterprises (fewer than 10 employees, turnover < โฌ2 million), self-employed professionals, and artisans.
BUT โ Micro and small enterprises also fall within scope if they are the sole national provider of an essential service or are explicitly designated by the Member State.
Entities must implement appropriate measures to manage risks, including:
Entities must provide essential information to the competent national authority.
Maximum fine:
โฌ10,000,000
OR 2% of global annual turnover (whichever is higher)
Management liability for serious violations
Maximum fine:
โฌ7,000,000
OR 1.4% of global annual turnover
EU Directive 2022/2555 (NIS2) transposes NIS2 into national law in each Member State.
| Aspect | ๐ NIS1 | โ NIS2 |
|---|---|---|
| Entities covered (example) | ~700 | ~4,000-5,000 estimated |
| Sectors | 7 sectors | 15 sectors + Public Administration |
| Obligations | Generic | Detailed and specific |
| Maximum penalties | โฌ150,000 | Up to โฌ10M or 2% of turnover |
| Incident reporting | Not mandatory | Mandatory within 24 hours |
| Supply chain | Not mentioned | Included (Art. 21) |