The Cyber Academy take
NIS 2 (Directive (EU) 2022/2555) is the EU directive that puts cybersecurity boards on the hook. Mid-sized or larger entities in 18 listed sectors are in scope. On a significant incident: 24-hour early warning, 72-hour notification, full report at one month. Penalties up to 10 million euros or 2% of worldwide turnover for essential entities. Transposed unevenly across member states since October 2024.
TL;DR
- 1In scope: 18 sectors, mid-sized (50+ FTE / 10M+ turnover) and larger. Two tiers, essential and important, with different supervisory intensity.
- 2Ten cybersecurity risk-management measures under Article 21. The directive says what; ISO 27001 is the most common how.
- 3Incident reporting: 24-hour early warning, 72-hour notification, full report at one month. Define the path before you need it.
- 4Personal liability and management accountability are now explicit. The board is on the hook, not just the CISO.
- 5Transposition state varies country to country, check your national authority before assuming the EU text applies as-is.
Working out whether you are in scope, and at which tier
Scope is the question that decides everything else, so resolve it first and write down the reasoning. NIS 2 applies to entities operating in one of the 18 listed sectors that also meet a size threshold. The default rule is the medium-enterprise floor: at least 50 employees, or annual turnover and balance sheet above 10 million euros. Below that floor you are usually out, but not always: the directive pulls certain providers in regardless of size when the service is critical enough (for example DNS providers, top-level domain registries, and some public electronic communications and trust service providers).
The two tiers, essential and important, are not two lists you pick from. They follow from your sector and size. The high-criticality sectors (energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, space) produce essential entities at the larger sizes; the other listed sectors, and smaller entities in the high-criticality ones, are generally classified as important. The practical consequence is supervisory intensity, not a softer set of obligations: the security measures and the reporting deadlines are the same for both tiers.
Essential vs important: where the two tiers actually diverge
Both tiers carry the same Article 21 measures and the same incident-reporting clock. What changes is how the regulator watches you and what it can do when something is wrong. Essential entities face proactive, ex-ante supervision: an authority can inspect and demand evidence without waiting for an incident. Important entities are supervised reactively, ex-post, meaning scrutiny typically follows an incident or a credible complaint. The penalty ceilings differ too, and that gap is the single most-cited reason to confirm your tier early.
| Dimension | Essential entities | Important entities |
|---|---|---|
| Supervision model | Proactive (ex-ante): inspections and evidence requests at any time | Reactive (ex-post): triggered by an incident or complaint |
| Maximum administrative fine | At least 10 million euros or 2% of total worldwide annual turnover, whichever is higher | At least 7 million euros or 1.4% of total worldwide annual turnover, whichever is higher |
| Security obligations (Article 21) | All ten measures apply | All ten measures apply (identical) |
| Reporting timeline | 24h / 72h / 1 month (identical) | 24h / 72h / 1 month (identical) |
| Management accountability | Explicit; bodies can be held liable, individuals can face temporary management bans | Explicit; individual liability applies, management bans are generally reserved for essential entities |
Read the table the way an auditor will: the measures and deadlines are non-negotiable for everyone, so the tier mostly tells you how much margin for error you have before someone comes looking. Essential entities should assume an inspection can happen on a quiet Tuesday. Important entities should assume the first real test will be a live incident, which is the worst moment to discover your evidence is thin.
The ten Article 21 measures, and why ISO 27001 is the usual answer
Article 21(2) lists ten categories of cybersecurity risk-management measures that every in-scope entity must implement, proportionate to its risk exposure. The directive describes outcomes, not controls, which is deliberate: it tells you what must be covered and leaves the how to you.
- Policies on risk analysis and information system security.
- Incident handling (detection, response, and the reporting obligations below).
- Business continuity, including backup management and disaster recovery, and crisis management.
- Supply chain security, covering the security of relationships with direct suppliers and service providers.
- Security in network and information systems acquisition, development, and maintenance, including vulnerability handling and disclosure.
- Policies and procedures to assess the effectiveness of the measures.
- Basic cyber hygiene practices and security training.
- Policies and procedures on cryptography and, where appropriate, encryption.
- Human resources security, access control policies, and asset management.
- Multi-factor authentication, secured communications, and secured emergency communication where appropriate.
Read that list next to an Annex A control set and the overlap is obvious. This is why, in practice, the most common route to demonstrable compliance is an ISO 27001 information security management system. NIS 2 names the outcomes; ISO 27001 gives you the management system, the risk-treatment discipline, and the documented evidence that maps onto nine of the ten categories without much translation. You do not strictly need a certificate to satisfy NIS 2, but the ISMS structure is the cleanest way to produce the records an authority expects.
The fastest way for a team to internalise both the obligation and the build is to pair the regulatory view with the implementation view: the NIS 2 Directive Lead Implementer course for the programme itself, and the ISO 27001 Lead Implementer course to stand up the ISMS that carries most of the Article 21 weight.
The reporting clock: 24 hours, 72 hours, one month
The reporting obligation triggers on a significant incident, meaning one that has caused or is capable of causing severe operational disruption or financial loss, or that has affected others through considerable material or non-material damage. The clock then runs in three stages to your national CSIRT or competent authority.
- 24 hours: an early warning. State whether you suspect the incident is unlawful or malicious and whether it could have cross-border impact. This is a flag, not a forensic report.
- 72 hours: an incident notification. Update the early warning with an initial assessment, including severity, impact, and any indicators of compromise you have.
- One month: a final report. A full account of the incident, its likely root cause, the mitigation applied, and any cross-border impact. If the incident is still ongoing at one month, you provide a progress report and a final one when it closes.
The deadlines look generous until you map them against a real incident. The 24-hour warning lands while you are still confirming what happened, so the path has to be defined in advance: who decides an incident is "significant", who drafts the early warning, who has the authority to file, and which portal or contact it goes to in each member state where you operate. Rehearse it. A tabletop exercise that ends with a draft early warning written against the clock is worth more than any policy document about reporting.
Management liability and the mistakes that show up in the audit room
NIS 2 moves accountability up. Management bodies must approve the cybersecurity risk-management measures, oversee their implementation, and follow training so they can identify risks themselves. Non-compliance can attach to named individuals, and for essential entities authorities can impose temporary bans on individuals exercising management functions. The board is on the hook, and "the CISO handles security" is no longer a complete answer to a regulator.
The recurring failures we see are rarely exotic. They are predictable, and they are avoidable:
- Treating transposition as uniform. The directive is transposed into national law and the timing, thresholds, registration duties, and reporting portals vary by country. Check the national authority for every member state you operate in before assuming the EU text applies as-is.
- Ignoring the registration and self-identification duty. Many member states require in-scope entities to register with the competent authority. Being in scope and unregistered is its own finding, separate from any security gap.
- Under-investing in supply chain security. It is one of the ten measures, and it is where the largest entities are most exposed. A thin supplier-risk process is a visible weakness.
- Confusing tiers with obligations. Important entities sometimes assume lighter supervision means lighter duties. It does not: the same measures and the same reporting clock apply.
- No rehearsed reporting path. The 24-hour warning is the obligation most often missed, because nobody owned the decision and the draft until the incident forced it.
If your team needs to get its bearings on scope, tiers, and obligations before committing to a build, the NIS 2 Directive Foundation course is the right starting point; move to the Lead Implementer and ISO 27001 tracks once you are scoping the programme itself.
NIS 2 interacts with other EU regimes (DORA governs financial-sector operational resilience and generally takes precedence there as the more specific rule; the AI Act adds its own obligations for AI systems), so confirm which regime is lead for a given obligation rather than reporting the same incident twice or, worse, not at all. When in doubt, the safe posture is the one the directive itself rewards: documented decisions, a maintained control mapping, and a reporting path you have run before you needed it.
Frequently asked questions
01Am I in scope of NIS 2?
Two filters: sector and size. You must be in one of 18 listed sectors (energy, transport, finance, health, digital infrastructure, public administration, space, food, chemicals, postal services, manufacturing of critical products, research, waste management, plus a few others). And you must meet the size threshold: 50+ employees or 10 million euros annual turnover. Below that, you are out of scope by default, with national exceptions for critical entities of any size.
Two tiers within scope: essential entities (energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management B2B, public administration, space) face heavier supervision and higher penalties. Important entities (postal, waste, chemicals, food, manufacturing, digital providers, research) face lighter supervision but the same control obligations.
02What are the ten Article 21 measures?
Article 21(2) lists ten cybersecurity risk-management measures: (a) policies on risk analysis and information system security; (b) incident handling; (c) business continuity and crisis management; (d) supply-chain security; (e) acquisition, development and maintenance security; (f) policies and procedures to assess the effectiveness of cybersecurity risk-management measures; (g) basic cyber hygiene and cybersecurity training; (h) policies on cryptography and encryption; (i) human resources security, access control and asset management; (j) the use of multi-factor authentication, secured voice/video/text communications and secured emergency communication systems.
The directive does not say how to implement each. ISO 27001 maps cleanly onto all ten; NIST CSF and CIS Controls cover most of them. Pick a framework, document the mapping, and the supervisory authority is satisfied.
03What is the incident reporting timeline?
On a significant incident, three deadlines: 24-hour early warning (initial assessment, whether the incident is suspected to be caused by unlawful or malicious acts, potential cross-border impact); 72-hour notification (broader assessment, indicators of compromise); one-month final report (detailed description of the incident, severity, impact, mitigation measures taken, root-cause analysis where available).
A significant incident is one that has caused or is capable of causing severe operational disruption or financial losses, or affects others by causing considerable material or non-material damage. The thresholds are clarified by national authorities; check yours.
04What are the penalties?
Essential entities face administrative fines up to 10 million euros or 2% of worldwide annual turnover, whichever is higher. Important entities face up to 7 million euros or 1.4% of worldwide annual turnover. National authorities can also impose non-financial sanctions: orders to comply, public disclosure of non-compliance, temporary bans on management persons holding their role.
Penalties are not the only enforcement vector. Supervisory dialogue, audits, and orders to perform a specific corrective action all sit below the fine threshold and are more common in practice.
05How does NIS 2 interact with DORA and the AI Act?
For financial entities, DORA is lex specialis on ICT topics: where DORA applies, it prevails over NIS 2 for the ICT-related provisions. Financial entities still apply NIS 2 for non-ICT topics covered by the directive.
The AI Act is parallel, it governs AI systems, not cybersecurity programmes. If you operate high-risk AI systems within a critical sector, you face both: NIS 2 for the cybersecurity baseline, the AI Act for the AI conformity work.


