NIS 2 Directive: Cybersecurity Risk Management and Incident Reporting
Introduction
Directive (EU) 2022/2555 — commonly known as NIS 2 — is the EU’s flagship legislative instrument for cybersecurity risk management and incident reporting. Repealing and replacing the original NIS Directive (Directive 2016/1148), NIS 2 responds to the dramatic expansion of the cyber threat landscape, the increasing interdependence of digital infrastructure, and the shortcomings of the first NIS regime: inconsistent national implementation, narrow sectoral scope, and insufficient incident reporting obligations. NIS 2 establishes a high common level of cybersecurity across the Union, applying to a substantially broader range of sectors and entities with more stringent obligations.
Scope and Categorisation
NIS 2 extends its scope significantly beyond the original NIS Directive. The directive applies to medium-sized and large enterprises (50+ employees or €10 million+ annual turnover) in sectors classified as “essential” and “important.” Essential entities include energy, transport, banking, financial market infrastructure, health, drinking water supply, wastewater, digital infrastructure (IXPs, DNS, cloud computing, data centres), ICT service management, public administration, and space. Important entities include postal and courier services, waste management, chemicals, food, manufacturing (critical products, motor vehicles, machinery), digital providers (online marketplaces, search engines, social networking platforms), and research organisations.
Member States have the option to designate smaller entities where they play a critical role in the economy or society. The directive excludes entities subject to sector-specific cybersecurity rules under Regulation (EU) 910/2014 (eIDAS) for trust service providers, Regulation (EU) 2016/679 (GDPR) for data protection, and Regulation (EU) 2017/1939 (EPPO).
Cybersecurity Risk Management
Article 21 NIS 2 imposes a comprehensive cybersecurity risk management obligation on essential and important entities. Measures must be appropriate and proportionate to the risks posed and must address at minimum: (a) policies on risk analysis and information system security; (b) incident handling (prevention, detection, response); (c) business continuity, backup management, and crisis management; (d) supply chain security, including security-related aspects of the relationships between each entity and its direct suppliers or service providers; (e) security in network and information systems acquisition, development, and maintenance, including vulnerability handling and disclosure; (f) policies and procedures to test the effectiveness of cybersecurity risk management measures; (g) the use of cryptography and encryption; (h) human resources security, access control, and asset management; and (i) the use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications, and secured emergency communication systems within the entity.
The risk management measures must be based on a risk assessment approach, with entities implementing technical, operational, and organisational controls commensurate with the identified risks, the entity’s size, the likelihood of incidents, and their potential severity.
Incident Reporting
Article 23 establishes a tiered incident reporting framework. Entities must report: (a) an early warning within 24 hours of becoming aware of a significant incident, indicating whether the incident is suspected of being caused by unlawful or malicious acts or could have cross-border impact; (b) an incident notification within 72 hours, updating the information and providing an initial assessment of the incident, its severity, impact, and indicators of compromise; (c) an interim report upon request of the CSIRT or competent authority; and (d) a final report within one month, including a detailed description, the type of threat or root cause, mitigation measures applied, and the cross-border impact.
A significant incident is one that: (a) has caused or is capable of causing severe operational disruption of the services or financial loss for the entity; (b) has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage; or (c) has a cross-border dimension.
Essential vs Important Entities: Differential Treatment
The distinction between essential and important entities determines the stringency of the supervisory regime. Essential entities are subject to ex ante proactive supervision: competent authorities must conduct regular audits, targeted security checks, scans, and requests for information, and must have the power to carry out on-site inspections and off-site security assessments. Important entities are subject to ex post reactive supervision: authorities act on the basis of information provided or evidence of non-compliance, but may conduct audits and inspections where a significant incident has occurred or a breach obligation is suspected.
Supply Chain Security
NIS 2 introduces explicit obligations for supply chain security. Entities must address cybersecurity in the selection and management of direct suppliers and service providers (Article 21(2)(d)). Competent authorities may require entities to use certified ICT products, services, and processes under the EU Cybersecurity Act (Regulation 2019/881). The European Commission, with the Cooperation Group, may identify specific categories of critical ICT products, services, and processes that pose a significant potential for systemic disruption and require enhanced supply chain security.
Competent Authorities and CSIRTs
Each Member State must designate one or more competent authorities and a single Computer Security Incident Response Team (CSIRT) (Article 10). CSIRTs act as the operational hubs for incident detection, triage, early warning, coordination, and response; they participate in the CSIRT Network established at EU level, facilitating operational cooperation, cross-border incident response, and coordinated vulnerability disclosure.
ENISA and the Cooperation Group
The European Union Agency for Cybersecurity (ENISA) , established by the Cybersecurity Act (Regulation 2019/881), supports NIS 2 implementation through: (a) the development of cybersecurity certification schemes; (b) threat and vulnerability information sharing; (c) coordination of the CSIRT Network; (d) the EU Cybersecurity Reserve (under the Cyber Solidarity Act); and (e) the promotion of best practices and guidance. The Cooperation Group — composed of Member State representatives, the Commission, and ENISA — ensures strategic cooperation, exchanging best practices on implementation, transposition, and emerging threats.
Penalties and Enforcement
Member States must establish effective, proportionate, and dissuasive administrative fines (Article 34). For essential entities, maximum fines of at least €10,000,000 or 2% of total worldwide annual turnover, whichever is higher. For important entities, maximum fines of at least €7,000,000 or 1.4% of worldwide annual turnover. Member States may impose criminal penalties for natural persons, and directors may be held personally liable for failure to adopt adequate cybersecurity measures.
Transposition and Implementation
NIS 2 required transposition by 17 October 2024. Member States must identify essential and important entities by 17 April 2025. The directive applies from 18 October 2024. The European Commission, supported by the Cooperation Group, adopted an implementing regulation on incident reporting templates, timelines, and formats in 2024.