Regulations library · European Union

NIS2

NIS2 Directive (EU) 2022/2555

In force European Union security incident reporting

Cybersecurity risk management, management accountability and staged incident reporting starting with an early warning within 24 hours.

At a glance

Who it applies to
Medium and large entities in listed essential and important sectors, and some others regardless of size.
Who enforces it
National cybersecurity authorities
When
Member states had to transpose it by 17 October 2024; it applies through national laws, some adopted late.

A practical guide to this law, with scenarios and flashcards, is being written. The summary above is the reference entry.

Recent developments

Nothing reported yet. Regulatory Watch lists new rules, enforcement and court decisions as they arrive.

Sources

Dates and status are from the association's inventory and are being checked against primary sources. This page explains the law for practitioners; it is not legal advice.