NIS2

The NIS2 Directive Hub

NIS2 Directive compliance resources for essential and important entities. Cybersecurity risk management obligations, incident reporting timelines, supply chain security, and EU Member State implementation.

EU Directive 2022/2555

Essential vs Important EntitiesRisk Management MeasuresIncident ReportingSupply Chain SecuritySanctions & EnforcementNIS2 vs GDPR

The NIS2 Directive (Directive 2022/2555) significantly broadens the scope of EU cybersecurity obligations. Member States had until 17 October 2024 to transpose — most are still deploying secondary legislation in 2026. NIS2 captures essential and important entities across 18 sectors, with up to €10M or 2% of turnover penalties for essential entities.

Start with the basics: NIS2 compliance guide, essential vs important entity classification, and the risk management measures required by Article 21. For incidents, see NIS2 incident reporting (24h early warning, 72h notification, 1-month final report).

Cross-regulation guidance: NIS2 vs GDPR comparison, DORA vs NIS2, and the unified incident reporting framework. For penalties, our NIS2 penalties guide documents the enforcement landscape. For tools, see the NIS2 software buyer's guide.

7 articles