EU ENISA, National Competent Authorities

NIS2 Directive

In force since 18 October 2024

Agent Navigation: For section discovery, use /regulations/eu/nis2/llms.txt

Quick Reference

The NIS2 Directive (Directive 2022/2555) establishes cybersecurity risk management and incident reporting obligations for essential and important entities across the EU. Replaces NIS1 with significantly expanded scope and stricter requirements.

Applies to: Medium+ enterprises (50+ employees or €10M+ turnover) in 18 critical sectors, plus some smaller entities regardless of size (DNS, TLDs, trust services)

Key rules:

  • Must implement appropriate cybersecurity risk management measures [Art 21]
  • Must report significant incidents within 24 hours (early warning), 72 hours (full report) [Art 23]
  • Management bodies must approve and oversee cybersecurity, receive training [Art 20]
  • Must assess and manage supply chain security risks [Art 21(2)(d)]
  • Must maintain business continuity and crisis management capabilities [Art 21(2)(c)]
QuestionAnswerCitation
Who’s covered?Essential + important entities in 18 sectorsArt 2, Annex I-II
Size threshold?50+ employees or €10M+ turnoverArt 2
Incident notification deadline?24 hours (early warning)Art 23(4)(a)
Full incident report deadline?72 hoursArt 23(4)(b)
Maximum fine (essential)?€10M or 2% global turnoverArt 34
Maximum fine (important)?€7M or 1.4% global turnoverArt 34

Regulation Map (All Chunks)

Every section of NIS2 Directive coverage is listed here for full-text lookup and agent navigation.

Definitions

Requirements

Enforcement

Scenarios

Official Sources

Contains public sector information licensed under the Open Government Licence v3.0 where applicable. This is not legal advice. Always refer to official sources for authoritative text.

llms.txt