Bidda Sovereign Intelligence · 10,108 Verified Nodes · 39 Sovereign Pillars
NIS2 Directive Compliance: A 2026 Field Guide for Essential and Important Entities
NIS2 (Directive EU 2022/2555) replaces the 2016 NIS1 framework, expanding cybersecurity obligations across eleven sectors of essential entities and seven…
· 10 min read · Cybersecurity & Compliance
Directive EU 2022/2555 expanded EU cybersecurity duties across eighteen sectors. What changed from NIS1, what your incident clock now looks like, and what the management body actually owes.
What NIS2 Replaces
The NIS2 Directive (Directive EU 2022/2555) was adopted in December 2022 and required transposition by Member States by 17 October 2024. It replaces the 2016 NIS1 Directive (Directive EU 2016/1148), which had patchy implementation across the bloc and an inconsistent definition of operators of essential services. NIS2 harmonises scope, raises the cybersecurity baseline, and standardises supervisory and enforcement powers.
Expanded Scope: Essential vs Important Entities
Annex I lists eleven sectors of essential entities: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, and space. Annex II lists seven sectors of important entities: postal and courier services, waste management, manufacture/production/distribution of chemicals, production/processing/distribution of food, manufacturing (medical devices, computers, electrical equipment, motor vehicles), digital providers (search engines, marketplaces, social networks), and research organisations. The size-cap rule under Article 2 brings every medium and large enterprise within these sectors into scope; smaller entities are in scope only if specifically designated.
The Core Obligations
Article 20: Management-Body Accountability
Management bodies of essential and important entities must approve the cybersecurity risk-management measures adopted under Article 21, oversee their implementation, and can be held liable for the entity's infringements. Members of management bodies are required to follow cybersecurity training and to offer similar training to their employees on a regular basis. This is one of the most material changes from NIS1 - director-level accountability for cybersecurity.
Article 21(2) lists ten minimum measures every in-scope entity must implement: (a) policies on risk analysis and information system security; (b) incident handling; (c) business continuity, backup and disaster recovery; (d) supply chain security including security-related aspects of the relationships between each entity and its direct suppliers or service providers; (e) security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure; (f) policies and procedures to assess the effectiveness of cybersecurity risk-management measures; (g) basic cyber hygiene practices and cybersecurity training; (h) policies and procedures on the use of cryptography and, where appropriate, encryption; (i) human resources security, access control and asset management; (j) the use of multi-factor authentication, secured voice/video/text communications and secured emergency communication systems.
Article 23: The Incident Reporting Cadence
NIS2 sets a three-stage reporting timeline for significant incidents. An early warning must be submitted to the competent authority or CSIRT within 24 hours of becoming aware of the incident. A more substantive incident notification follows within 72 hours, including an initial assessment of severity, impact and indicators of compromise. A final report must be submitted within one month of the incident notification. The same Article also requires the entity to notify recipients of its services that are potentially affected.
Significant Incidents: The Definition That Triggers the Clock
Article 23(3) defines a significant incident as one that has caused, or is capable of causing, severe operational disruption of the services or financial loss for the entity, or has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage. The Commission has adopted an implementing regulation (Commission Implementing Regulation EU 2024/2690) setting out detailed criteria, particularly for digital infrastructure entities, ICT service management and digital providers.
Penalties
Article 34 requires Member States to ensure that infringements by essential entities can attract administrative fines of a maximum of at least €10 million or 2% of total worldwide annual turnover for the preceding financial year, whichever is higher. For important entities the corresponding ceiling is at least €7 million or 1.4% of global turnover. Article 32 also gives competent authorities powers to suspend, temporarily, the certification or authorisation of an essential entity, and to prohibit any natural person from exercising managerial functions at the level of chief executive or legal representative.
How NIS2 Interacts with DORA, GDPR and the EU AI Act
For financial entities, DORA (Regulation EU 2022/2554) is lex specialis: DORA's ICT risk and incident provisions take precedence over the equivalent NIS2 provisions. GDPR Article 33 personal-data breach notification (72 hours to the supervisory authority) remains separately applicable; many incidents will trigger both. For providers of high-risk AI systems under the EU AI Act, the cybersecurity requirements of Article 15 align with - but do not replace - the corresponding NIS2 obligations.
How Bidda Maps NIS2
The Bidda registry represents the NIS2 Directive, each Annex I and Annex II sector, the ten Article 21(2) measures, the Article 23 reporting cadence, and the Commission Implementing Regulation 2024/2690 thresholds as discrete nodes. Each crosswalks to ISO/IEC 27001:2022 Annex A controls, the NIST Cybersecurity Framework 2.0 functions, DORA where applicable, and to the relevant ENISA guidance. Compliance teams use the registry to evidence each Article 21(2) measure against their internal controls; AI agents query the same nodes via the discovery API or the MCP server.
Frequently Asked Questions
When did NIS2 become enforceable?The NIS2 Directive (Directive EU 2022/2555) required transposition by Member States by 17 October 2024. Member State transposition laws now apply directly to essential and important entities established in their territory.
Who is an essential entity vs an important entity under NIS2?Annex I of NIS2 lists eleven sectors of essential entities: energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, and space. Annex II lists seven sectors of important entities: postal and courier, waste management, chemicals, food, certain manufacturing, digital providers, and research organisations. The size-cap rule brings every medium and large enterprise within these sectors into scope.
What is the NIS2 24-72-30 incident reporting timeline?Article 23 requires three stages for a significant incident: an early warning to the competent authority or CSIRT within 24 hours of becoming aware of the incident, an incident notification within 72 hours, and a final report within one month of the notification. The entity must also notify potentially affected service recipients.
What management-body accountability does NIS2 require?Under Article 20, management bodies must approve the cybersecurity risk-management measures adopted under Article 21, oversee their implementation, and can be held liable for the entity's infringements. Members of management bodies are required to follow cybersecurity training. Article 32 allows competent authorities to prohibit any natural person from exercising managerial functions at the level of CEO or legal representative.
What are the maximum NIS2 penalties?Article 34 requires Member States to ensure that infringements by essential entities can attract administrative fines of at least €10 million or 2% of worldwide annual turnover, whichever is higher. For important entities the ceiling is at least €7 million or 1.4% of worldwide turnover.
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.