Framework guide • European Union

NIS2: NIS2 Directive (EU) 2022/2555

NIS2 (Directive (EU) 2022/2555) is the EU's cybersecurity law for essential and important entities in sectors such as energy, transport, health, digital infrastructure and ICT services. It makes management bodies accountable and requires ten cybersecurity risk-management measures (Article 21). It also imposes a three-stage incident-reporting regime (Article 23). Member States had to transpose it into national law by 17 October 2024.

Last updated · By the Faseel compliance team · Not legal advice

NIS2 at a glance

Legal instrument
Directive (EU) 2022/2555, transposed into national law by each Member State (deadline 17 October 2024)
Applies to
Essential and important entities in sectors listed in Annexes I and II (energy, transport, banking, health, digital infrastructure, ICT service management and more)
Core obligations
Management accountability (Art. 20), ten risk-management measures (Art. 21(2) a–j), incident reporting (Art. 23), registration
Incident reporting
Early warning within 24 hours, incident notification within 72 hours, final report within one month
Maximum fines
Essential entities: €10M or 2% of worldwide turnover; important entities: €7M or 1.4%
In Komply
18 organisation-facing obligations, all mapped to ISO 27001:2022

Who must comply with NIS2

Essential entities

Large organisations in high-criticality sectors such as energy, transport, banking, health and digital infrastructure.

Important entities

Medium and large organisations in other critical sectors, such as postal services, manufacturing, food and digital providers.

Non-EU providers serving the EU

Certain digital service providers outside the EU must designate an EU representative.

What NIS2 requires

  • Management bodies approve and oversee cyber-risk measures and complete cybersecurity training (Art. 20).
  • Risk analysis and security policies, incident handling, business continuity and crisis management (Art. 21).
  • Supply-chain security, secure acquisition and development, and vulnerability handling (Art. 21).
  • Effectiveness assessment, cyber hygiene and training, cryptography, HR security, access control and MFA (Art. 21).
  • Report significant incidents to the CSIRT or authority: 24-hour early warning, 72-hour notification, one-month final report (Art. 23).

NIS2 domains and control counts

18 controls across 4 areas, as mapped in Komply.

NIS2 domains with number of controls
DomainControls
Art. 20 — Governance & Accountability2
Art. 21 — Risk-Management Measures10
Art. 23 — Incident Reporting5
Registration & Scope1
Total18

How NIS2 maps to ISO 27001

All 18 NIS2 obligations in Komply map to ISO/IEC 27001:2022 Annex A controls. An ISMS is the most practical way to meet Article 21.

Komply maps NIS2 onto the same control set as ISO 27001 and GDPR, with incident-reporting timelines built into your incident register. See how Komply works.

NIS2 FAQ

What is NIS2?

NIS2 is Directive (EU) 2022/2555, the EU's updated law on network and information security. It sets cybersecurity risk-management and incident-reporting obligations for essential and important entities, and makes management bodies accountable for compliance.

What are the NIS2 incident-reporting deadlines?

For significant incidents: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, and a final report within one month.

What are the ten NIS2 risk-management measures?

Article 21(2) lists: (a) risk analysis and security policies, (b) incident handling, (c) business continuity and crisis management, (d) supply-chain security, (e) security in acquisition, development and maintenance, including vulnerability handling, (f) policies to assess effectiveness, (g) cyber hygiene and training, (h) cryptography and encryption, (i) HR security, access control and asset management, and (j) MFA and secured communications.

Does ISO 27001 certification mean NIS2 compliance?

Not automatically, but it covers most of Article 21. All 18 NIS2 obligations mapped in Komply have an ISO 27001:2022 equivalent. You still need NIS2-specific items such as registration, management training and the reporting timelines.

How does Komply help with NIS2?

Komply tracks every NIS2 obligation in one control set with ISO 27001 and GDPR, drafts policies, stores evidence and exports an auditor-ready package.

Do ISO 27001 once. Prove NIS2 too.

Komply maps 14 frameworks and 1,100+ controls into one control set. Start with a free gap assessment.