Skip to content

NIS2

Amended European Union · In force Jan 16, 2023 · next deadline Apr 17, 2027 (in 7 months)

Deadlines

DateWhat happens
Coming up
Apr 17, 2027in 6 monthsNext biennial entity notification
Oct 17, 2027in 1 yearCommission review of NIS2
Earlier
Apr 17, 20251 year agoMember States establish entity lists
Jan 17, 20251 year agoDigital infrastructure entities submit registration data
Nov 7, 20241 year agoImplementing Regulation 2024/2690 enters into force
Oct 18, 20241 year agoNational NIS2 measures apply; NIS1 repealed
Oct 17, 20241 year agoTransposition deadline
Jan 16, 20233 years agoNIS2 enters into force

Summaries for reference, not legal advice. Check the official text.

What it does

Requires medium and large entities in 18 critical sectors, including cloud, data centres, managed services, online marketplaces, search and social networks, to adopt cybersecurity risk-management measures. They must report significant incidents within 24 hours (early warning), 72 hours (notification) and one month (final report). Management bodies are accountable. Obligations apply through national transposing laws.

Who it applies to
Essential and important entities in Annex I/II sectors, generally medium-sized or larger (50+ employees or over EUR 10M turnover/balance sheet). DNS, TLD registries, trust service providers and public electronic communications providers are covered regardless of size.
Penalties
Essential entities: maximum of at least EUR 10M or 2% of worldwide annual turnover, whichever is higher. Important entities: maximum of at least EUR 7M or 1.4% (Art 34). Management can be held personally liable and temporarily suspended in some cases.
Enforced by
National competent authorities and CSIRTs designated by each Member State; NIS Cooperation Group; ENISA
Official name
Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive)
Citation
OJ L 333, 27.12.2022, p. 80
Topics
cybersecurity, breach-notification
Verified 2026-09-22 eur-lex.europa.eu insideprivacy.com
Research notes

Transposition was late in most Member States, so obligations and registration deadlines differ by country. On 20 Jan 2026 the Commission proposed targeted NIS2 amendments alongside a revised Cybersecurity Act (CSA2): narrower scope, more harmonised measures, certification-based compliance and a bigger role for ENISA. The Digital Omnibus COM(2025) 837 also proposes a single-entry point for incident reporting. Neither was adopted as of Sept 2026. The 2027-04-17 date is computed from 'every two years' after 17 Apr 2025.

Related

Questions about NIS2
What are the NIS2 compliance deadlines?
Jan 16, 2023: NIS2 enters into force. Oct 17, 2024: Transposition deadline. Oct 18, 2024: National NIS2 measures apply; NIS1 repealed. Nov 7, 2024: Implementing Regulation 2024/2690 enters into force. Jan 17, 2025: Digital infrastructure entities submit registration data. Apr 17, 2025: Member States establish entity lists. Apr 17, 2027: Next biennial entity notification. Oct 17, 2027: Commission review of NIS2.
When does NIS2 take effect?
NIS2 took effect on Jan 16, 2023. The next milestone is Apr 17, 2027: Next biennial entity notification.
Who does NIS2 apply to?
Essential and important entities in Annex I/II sectors, generally medium-sized or larger (50+ employees or over EUR 10M turnover/balance sheet). DNS, TLD registries, trust service providers and public electronic communications providers are covered regardless of size.
What are the penalties under NIS2?
Essential entities: maximum of at least EUR 10M or 2% of worldwide annual turnover, whichever is higher. Important entities: maximum of at least EUR 7M or 1.4% (Art 34). Management can be held personally liable and temporarily suspended in some cases.

Rule changes by email

The morning after a new data, privacy or AI law, or a deadline change; nothing in quiet weeks.

Double opt-in. Unsubscribe any time.