NIS2 Directive
The NIS2 Directive (EU 2022/2555) is the EU cybersecurity law for 18 critical sectors, mandating risk management, training and 24-hour incident reporting.
The NIS2 Directive (Directive (EU) 2022/2555) is the European Union's cybersecurity law for critical and important infrastructure. It replaced the original 2016 NIS Directive, dramatically widening its reach: essential and important entities across 18 sectors — energy, transport, health, digital infrastructure, ICT service management, public administration, manufacturing of critical products and more — must implement a defined set of cybersecurity risk-management measures and report significant incidents on strict deadlines. Member states were required to transpose the directive into national law by 17 October 2024; in July 2026 the European Commission referred the last four holdouts to the Court of Justice for missing that deadline.
How it works
NIS2 operates through national law rather than directly, which is why transposition matters. Once in force, three mechanisms carry most of its weight. Article 21 lists ten minimum measures every in-scope entity must implement, ranging from incident handling and supply-chain security to "basic cyber hygiene practices and cybersecurity training." Article 20 makes the management body accountable: directors must approve the risk-management measures, oversee their implementation, follow cybersecurity training themselves, and can be held personally liable for infringements. Article 23 sets the reporting clock — an early warning to the authority within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within a month. Non-compliance carries fines of up to €10 million or 2% of worldwide turnover for essential entities (€7 million or 1.4% for important ones).
How to defend and comply
The human-layer obligations are the ones security teams most often underestimate. A defensible NIS2 posture needs documented training for the management body, a regular training cadence for the workforce, and an incident-reporting reflex fast enough to beat the 24-hour early-warning window — which in practice means employees who recognize social engineering and report it in minutes, not days. Continuous phishing simulation and a measurable human risk score turn those duties into evidence a supervisor can audit. Our guide to NIS2's human-risk requirements walks through Articles 20, 21 and 23 in detail.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo