Regulatory primer

NIS2

Directive (EU) 2022/2555 — Network and Information Security Directive 2 · European Union · Transposition deadline 17 October 2024; in force in transposing member states

NIS2 is the EU's cybersecurity baseline for essential + important entities across 18 critical sectors. It expands NIS1's scope, harmonises risk-management measures, mandates incident reporting on tight timelines, and puts supply-chain security on the agenda. Transposition deadline was 17 October 2024 — most member states are now active.

Updated 15 May 2026·Reading time ~ 7 min·Regulator-first explainer

What it is

NIS2 replaces the 2016 NIS Directive. The expansion is structural: NIS1 covered ~7 sectors; NIS2 covers 18. NIS1 left scope-determination to member states; NIS2 fixes scope at EU level via size + sector criteria. NIS1 had loose risk-management expectations; NIS2 fixes minimum measures in Art. 21.

Two regulated categories: 'essential entities' (energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space) and 'important entities' (postal + courier, waste management, chemicals, food, manufacturing of critical products, digital providers, research). Essential entities face proactive supervision; important entities face reactive (ex post) supervision.

Size threshold: medium-sized enterprises (€10M turnover OR 50+ employees) in the listed sectors are in scope by default. Some sectors (e.g. critical digital infrastructure providers, qualified trust service providers) are in scope regardless of size.

Who's in scope

  • Essential entities: energy, transport, banking, financial market infrastructure, health, drinking + wastewater, digital infrastructure, ICT service management (B2B), public administration, space.
  • Important entities: postal + courier, waste management, chemicals, food production + distribution, manufacturing of critical products (medical devices, vehicles, electronics, machinery), digital providers (online marketplaces, search engines, social networks), research.
  • Size threshold: medium-sized (€10M turnover OR 50+ employees) by default. Some sectors apply regardless of size.
  • Financial entities subject to DORA are largely excluded (DORA acts as lex specialis for financial-sector cybersecurity).
  • Cross-border + supply-chain dimension: even non-regulated entities supplying regulated customers carry indirect supply-chain risk-management expectations.

Key obligations

Art. 21 — cybersecurity risk-management measures

Appropriate + proportionate technical, operational, organisational measures. Minimum measures specified: risk-analysis + IS policies, incident handling, business continuity + backup, supply chain security (Art. 21(2)(d)), security in acquisition + development + maintenance, policies on effectiveness assessment, basic cyber hygiene + training, cryptography + encryption, HR security + access control + asset management, multi-factor authentication.

Art. 21(2)(d) — supply-chain security

Risk-management measures must include 'supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers'. The basis for cascading evidence demands to vendors.

Art. 23 — incident reporting (24h / 72h / 1 month)

Significant incidents must be reported to CSIRT or competent authority: early warning within 24h, incident notification within 72h, final report within 1 month. Affected recipients (where relevant) notified without undue delay.

Art. 24 — use of European certification schemes

Member states may require essential + important entities to use ICT products + services certified under the EU Cybersecurity Certification Framework (EUCC) for specific risk categories.

Art. 32 — management body liability

Management bodies of essential + important entities must approve risk-management measures + oversee implementation. Personal liability + accountability is in scope.

Timeline + applicability

  • 16 Jan 2023NIS2 entered into force at EU level.
  • 17 Oct 2024Transposition deadline for member states. Most transposed on time; a handful slipped.
  • 18 Oct 2024NIS2 measures apply in transposing member states.

What's still being worked out

Areas where the regulation's interpretation is genuinely unsettled. Vendor pages skip this; we don't. Your counsel is the right venue for definitive guidance on your deployment.

  • How 'supply-chain security' under Art. 21(2)(d) cascades — what evidence regulated entities must demand from non-regulated suppliers. National practice is forming.
  • Boundary with DORA — financial entities have lex specialis treatment, but non-financial ICT providers serving them may still be NIS2-regulated separately.
  • What counts as a 'significant incident' under Art. 23 — quantitative thresholds vary across member-state transposition.
  • Public-administration scope — local + regional authorities are in scope unless excluded by member state. Practice varies.
  • Penalty structure — Art. 34 sets minimum maximum penalties (essential entities: €10M or 2% turnover; important: €7M or 1.4%) but national implementations differ on aggravation factors.

Sectors most affected

Primary sources

Where Promethean fits

Promethean's L12 chain + audit-bundle export feed two NIS2 obligations directly: (1) Art. 21(2)(d) supply-chain assurance to customers — per-tenant audit bundle filtered to the customer's deployment gives them verifiable evidence of vendor AI behaviour for their own NIS2 compliance posture; (2) Art. 23 incident-timeline reconstruction — when an AI component is implicated in a significant incident, recordedAtIso + tamper-evident chain anchored to Bitcoin via OpenTimestamps provide an independently verifiable timeline.

What Promethean does NOT solve

  • Broader cybersecurity controls (Art. 21 minimum measures other than the AI-component slice) — that's the operator's full security programme.
  • Penetration testing / TLPT — specialist offensive security work.
  • Business-continuity + disaster recovery planning.
  • EUCC certification — that's a separate certification pathway.
  • Management-body governance + training — organisational responsibility.

FAQ

Am I in NIS2 scope?

Two questions: are you in an Annex I (essential) or Annex II (important) sector, AND do you meet the size threshold (medium = €10M turnover OR 50+ employees)? Some sectors apply regardless of size (qualified trust service providers, DNS service providers, TLD name registries, critical digital infrastructure). Member-state transpositions vary; check your national implementing law.

What's the difference between essential + important entities?

Essential entities are subject to proactive (ex ante) supervision: CSIRTs + competent authorities can audit + impose measures. Important entities are subject to reactive (ex post) supervision: action follows evidence of non-compliance. Penalty caps differ — essential €10M or 2% global turnover; important €7M or 1.4% (Art. 34).

Does NIS2 apply to my SaaS vendor?

Directly: only if the vendor is in an Annex sector + meets the size threshold (or is a sector-regardless-of-size category like ICT service management). Indirectly: every regulated NIS2 customer carries Art. 21(2)(d) supply-chain obligations, which cascade vendor-assessment demands. Practically, vendors serving regulated customers should expect evidence requests even when not directly NIS2-regulated.

How does NIS2 interact with DORA?

Financial entities subject to DORA are largely excluded from NIS2 obligations — DORA acts as lex specialis on cybersecurity + ICT risk for the financial sector. But non-financial ICT vendors supplying financial entities can be NIS2-regulated separately. Vendor-side: be ready for both DORA Art. 28 evidence demands AND NIS2 Art. 21(2)(d) supply-chain demands from different customer-types simultaneously.

What's the management-body liability under Art. 32?

Management bodies of essential + important entities must approve risk-management measures + oversee implementation. Personal accountability is in scope: member-state transpositions can include personal sanctions (e.g. temporary prohibitions on holding management positions). The practical effect: AI + cybersecurity-evidence questions are now board-level governance issues, not just CISO-level operational ones.