NIS2 Explained: Who Is Affected, What You Must Do, and by When
August 6, 2026 · by Pentevo
NIS2 Explained
NIS2 is EU Directive (EU) 2022/2555. It requires organisations in defined sectors to implement ten cybersecurity risk-management measures, report significant incidents within 24 hours, register with their national authority, and hold management personally accountable for compliance. It replaced the original NIS Directive and dramatically widened the scope — in Germany alone the number of regulated entities went from a few thousand to roughly 29,500.
Two things make NIS2 different from earlier cybersecurity regulation, and both are why it is being taken seriously:
- Management is personally liable. Art. 20 puts approval and oversight of the security measures on the management body, and members can be held personally responsible.
- The size threshold catches ordinary mid-sized companies. If you have 50+ employees and operate in a listed sector, you are probably in scope — including manufacturers, food producers, waste management and logistics firms that have never been regulated for cybersecurity before.
Timeline: where things stand
| Date | Event |
|---|---|
| 16 Jan 2023 | NIS2 entered into force at EU level |
| 17 Oct 2024 | Member State transposition deadline — most missed it |
| Nov 2024 | Commission opened infringement proceedings against late Member States, Germany included |
| 06 Dec 2025 | Germany's NIS2UmsuCG entered into force — ~29,500 entities now under BSI supervision |
Verify the German implementation date and entity count against the current BSI publication before relying on them — figures circulated during the legislative process varied.
Because Member States transposed at different times and with different national additions, the directive tells you the shape of your obligations; your national law tells you the detail. If you operate in several Member States, you may be regulated separately in each.
Are you in scope? The three-question test
NIS2 scope is determined by sector, then size, with a set of exceptions that override both.
Question 1 — Are you in a listed sector?
Annex I — sectors of high criticality
| Sector | Includes |
|---|---|
| Energy | Electricity, district heating/cooling, oil, gas, hydrogen |
| Transport | Air, rail, water, road |
| Banking | Credit institutions |
| Financial market infrastructures | Trading venues, CCPs |
| Health | Healthcare providers, EU reference labs, pharma manufacturing |
| Drinking water | Supply and distribution |
| Waste water | Collection, disposal, treatment |
| Digital infrastructure | IXPs, DNS providers, TLD registries, cloud, data centres, CDNs, trust services, electronic communications |
| ICT service management (B2B) | Managed service providers (MSPs), managed security service providers (MSSPs) |
| Public administration | Central and (per Member State) regional bodies |
| Space | Ground-based infrastructure operators |
Annex II — other critical sectors
| Sector | Includes |
|---|---|
| Postal and courier services | |
| Waste management | |
| Chemicals | Manufacture, production, distribution |
| Food | Production, processing, distribution |
| Manufacturing | Medical devices, computers/electronics/optical, electrical equipment, machinery, motor vehicles, other transport equipment |
| Digital providers | Online marketplaces, search engines, social networking platforms |
| Research organisations |
Manufacturing is the sleeper. A great many German Mittelstand engineering firms fall into Annex II via machinery or motor vehicles and have no history of cybersecurity regulation at all.
Question 2 — Do you meet the size threshold?
| Size class | Criteria |
|---|---|
| Medium | 50–249 employees, or turnover > €10m and ≤ €50m |
| Large | ≥ 250 employees, or turnover > €50m and balance sheet > €43m |
Below medium (under 50 staff and under €10m) you are generally out of scope — unless an exception applies.
Question 3 — Does an exception override the size rule?
Some entities are in scope regardless of size:
- DNS service providers
- TLD name registries
- Qualified trust service providers
- Providers of public electronic communications networks or publicly available electronic communications services
- Entities that are the sole provider of a critical service in a Member State
- Entities whose disruption could have significant impact on public safety, security or health
- Public administration entities, as designated nationally
- Entities identified as critical under the CER Directive (resilience of critical entities)
Essential vs important entities
This determines how hard you are supervised and how large the fines are.
| Essential | Important | |
|---|---|---|
| Who | Annex I entities at large size; plus size-independent categories | Annex I at medium size; all Annex II entities |
| Supervision | Ex-ante — proactive audits, inspections, no suspicion required | Ex-post — only on evidence of non-compliance |
| Maximum fine | €10m or 2% of total worldwide annual turnover, whichever is higher | €7m or 1.4%, whichever is higher |
The practical difference is large: essential entities should expect an authority to arrive unprompted. Important entities are, in effect, regulated on complaint or incident.
What you must actually do
1. Register with the authority
NIS2 requires entities to submit identifying information — name, address, sector, contact details, IP ranges — to the national authority. In Germany that is registration with the BSI.
This is an independent legal duty. No certificate substitutes for it, and it is the easiest thing for an authority to check.
2. Implement the ten Article 21 measures
Art. 21(2) lists ten areas. They must be "appropriate and proportionate", taking into account state of the art, cost, and the entity's exposure and size.
| # | Measure | What evidence looks like |
|---|---|---|
| (a) | Risk analysis and information system security policies | Documented methodology, risk register, approved policy |
| (b) | Incident handling | Playbooks, ticket records, post-incident reviews |
| (c) | Business continuity — backup, disaster recovery, crisis management | BCP/DRP, restore tests, crisis roles |
| (d) | Supply chain security | Supplier register, security requirements in contracts, assessments |
| (e) | Security in acquisition, development, maintenance; vulnerability handling and disclosure | SDLC controls, patch SLAs, CVD policy |
| (f) | Assessing effectiveness of the measures | Internal audits, metrics, management review |
| (g) | Cyber hygiene and training | Training records, phishing simulations, completion rates |
| (h) | Cryptography and encryption | Crypto policy, key management, encryption inventory |
| (i) | HR security, access control, asset management | Screening, joiner/mover/leaver, asset register, access reviews |
| (j) | MFA, secured voice/video/text, emergency communications | MFA coverage evidence, secure comms tooling |
Measure (f) is the one most organisations skip, and it is the one that turns a folder of policies into a management system. It requires you to test whether your measures work — which is where security testing, internal audit and metrics come in.
3. Meet the reporting cascade (Article 23)
Triggered by a significant incident: one that causes or is capable of causing severe operational disruption or financial loss, or that has affected or is capable of affecting others through considerable material or non-material damage.
| Stage | Deadline | Content |
|---|---|---|
| Early warning | 24 hours from awareness | Whether suspected to be caused by unlawful/malicious acts; whether cross-border impact is possible |
| Incident notification | 72 hours from awareness | Update to the early warning, initial severity and impact assessment, indicators of compromise |
| Intermediate report | On request | Status updates as requested by the CSIRT or authority |
| Final report | 1 month after the notification | Detailed description, type of threat and root cause, mitigation applied, cross-border impact |
If the incident is still ongoing at the one-month point, submit a progress report and the final report within one month of handling being completed.
The 24-hour clock is the hardest requirement to satisfy in practice. It runs from awareness, not from resolution, and most organisations have never defined in writing what "aware" means or who is authorised to declare it at 03:00 on a Sunday.
4. Satisfy the Article 20 governance duties
- Management bodies must approve the risk-management measures and oversee implementation
- Members can be held personally liable for infringements
- Members must undergo training to gain sufficient knowledge to identify risks and assess management practices
- Entities must offer similar training to employees
This is the clause that changes budget conversations. It is no longer purely an IT matter.
Does ISO 27001 make you NIS2 compliant?
No — but it covers most of the technical and organisational work. The ten Art. 21 measures map closely onto ISO 27001's clauses and Annex A controls. See the full mapping in What Is an ISMS?.
What a certificate does not give you:
- Registration with the BSI — a separate legal duty
- The Art. 23 reporting cascade with its 24h/72h/1-month deadlines and specified recipient
- Art. 20 management liability and training
- Scope alignment — a certificate scoped to one product line does not cover the whole regulated entity
Treat ISO 27001 as a strong evidence base with distinct legal duties layered on top.
NIS2, KRITIS and CER — how they fit together
Germany had critical-infrastructure rules (KRITIS) before NIS2, and there is a parallel EU directive on physical resilience. They overlap.
| NIS2 | KRITIS (BSIG) | CER / KRITIS-Dachgesetz | |
|---|---|---|---|
| Focus | Cybersecurity | Cybersecurity for critical infrastructure | Physical resilience |
| Scope | Broad — ~29,500 entities in Germany | Narrow — high thresholds | Critical entities |
| Origin | EU Directive 2022/2555 | German BSIG | EU Directive 2022/2557 |
Many KRITIS operators are also NIS2 entities and will additionally be captured by the Dachgesetz. See KRITIS Explained and KRITIS-Dachgesetz.
What to do first — a realistic order
- Determine scope in writing. Sector, size, exceptions, and which national law applies. Document the reasoning — you may need to justify a "not in scope" conclusion later.
- Register, if in scope. It is a hard legal duty and cheap to satisfy.
- Build the 24-hour reporting capability. It is the shortest deadline and the one you cannot retrofit under pressure. Name the owner, define "aware", write the templates, and run one tabletop exercise against the clock.
- Gap-assess against the ten measures. Be honest about (d) supply chain and (f) effectiveness — these are usually the thinnest.
- Get management trained and on record, because Art. 20 requires evidence, not intent.
- Then build out the ISMS properly.
Most organisations do this in the wrong order — starting with an ISMS project and leaving registration and reporting until last. Registration and reporting are the duties an authority checks first.
FAQ
Who is affected by NIS2? Entities with 50+ employees or €10m+ turnover operating in the Annex I or Annex II sectors, plus certain entities regardless of size (DNS providers, TLD registries, qualified trust service providers, public electronic communications providers, sole providers of a critical service).
What is the difference between essential and important entities? Essential entities face proactive supervision and fines up to €10m or 2% of worldwide turnover. Important entities are supervised reactively, with fines up to €7m or 1.4%.
What are the NIS2 reporting deadlines? Early warning within 24 hours of becoming aware, full notification within 72 hours, and a final report within one month of the notification.
Are small companies exempt from NIS2? Generally yes, below 50 employees and €10m turnover — unless a size-independent exception applies, or you are the sole provider of a critical service.
Can managers be held personally liable under NIS2? Yes. Art. 20 requires management bodies to approve and oversee the measures, and provides for personal liability for infringements.
Does NIS2 require penetration testing? Not by name. Art. 21(2)(f) requires policies and procedures to assess the effectiveness of your measures, and (e) covers vulnerability handling. Security testing is the usual way to evidence both, but the directive does not prescribe a method.
Is my company affected if we only supply a regulated company? Not automatically — but Art. 21(2)(d) makes your customer responsible for supply chain security, so you should expect security requirements to reach you contractually.
What happens if we do nothing? Fines up to €10m or 2% of worldwide turnover, supervisory measures including binding instructions and audits, and — for essential entities — the possibility of management being temporarily barred from exercising managerial functions.
Next step
→ NIS2 Scope Checker — find out in two minutes whether you are in scope
Related reading:
Frequently asked questions
Who is affected by NIS2?
Entities with 50+ employees or €10m+ turnover operating in the Annex I or Annex II sectors, plus certain entities regardless of size — DNS providers, TLD registries, qualified trust service providers, public electronic communications providers, and sole providers of a critical service.
What is the difference between essential and important entities under NIS2?
Essential entities face proactive (ex-ante) supervision and fines up to €10m or 2% of worldwide annual turnover. Important entities are supervised reactively (ex-post), only on evidence of non-compliance, with fines up to €7m or 1.4% of turnover.
What are the NIS2 reporting deadlines?
An early warning must be submitted within 24 hours of becoming aware of a significant incident, a full incident notification within 72 hours, and a final report within one month of the notification.
Are small companies exempt from NIS2?
Generally yes — entities below 50 employees and €10m turnover are out of scope — unless a size-independent exception applies, such as being the sole provider of a critical service or a qualified trust service provider.
Can managers be held personally liable under NIS2?
Yes. Article 20 requires management bodies to approve and oversee the cybersecurity risk-management measures, and provides for personal liability of individual managers for infringements. For essential entities, temporary prohibition from exercising managerial functions is also possible.
Does NIS2 require penetration testing?
Not by name. Article 21(2)(f) requires policies and procedures to assess the effectiveness of your measures, and Article 21(2)(e) covers vulnerability handling. Security testing is the standard way to evidence both, but the directive does not prescribe a specific method.
Is my company affected by NIS2 if we only supply a regulated company?
Not automatically — but Article 21(2)(d) makes your customer responsible for supply chain security, so you should expect security requirements to reach you contractually through your agreements with regulated entities.
What happens if a company does nothing about NIS2?
Fines up to €10m or 2% of worldwide annual turnover, supervisory measures including binding instructions and audits, and — for essential entities — the possibility of management being temporarily barred from exercising managerial functions.
Related reading
EU Cyber Resilience Act (CRA) Explained: Who It Affects and What It Requires
The CRA applies to all products with digital elements sold in the EU. Essential requirements, SBOM mandate, 24-hour vulnerability reporting, and the December 2027 deadline.
complianceWhat Is an ISMS? ISO 27001 Information Security Management System Explained
An ISMS is the documented management system ISO 27001 requires. Clauses 4–10, the 93 Annex A controls, the Statement of Applicability, and how it maps to NIS2 Article 21.
complianceSBOM Explained: Software Bill of Materials, Formats, and Why the CRA Requires One
What an SBOM is, what belongs in one, CycloneDX vs SPDX, how to generate and maintain one, and exactly what the EU Cyber Resilience Act mandates.
complianceKRITIS Explained: Germany's Critical Infrastructure Security Requirements
A practitioner's guide to KRITIS — the legal basis, which sectors and thresholds apply, what §8a BSIG demands, how the KRITIS-Dachgesetz adds physical resilience, and what BSI inspectors look for.
Practice this hands-on
Pentevo Academy turns these concepts into guided lessons, videos and quizzes — free.
Start learning free