Regulations library · European Union
NIS2
NIS2 Directive (EU) 2022/2555
In force European Union security incident reporting
Cybersecurity risk management, management accountability and staged incident reporting starting with an early warning within 24 hours.
At a glance
- Who it applies to
- Medium and large entities in listed essential and important sectors, and some others regardless of size.
- Who enforces it
- National cybersecurity authorities
- When
- Member states had to transpose it by 17 October 2024; it applies through national laws, some adopted late.
A practical guide to this law, with scenarios and flashcards, is being written. The summary above is the reference entry.
Recent developments
Nothing reported yet. Regulatory Watch lists new rules, enforcement and court decisions as they arrive.
Sources
- Directive (EU) 2022/2555 EUR-Lex · Official text or regulator
Dates and status are from the association's inventory and are being checked against primary sources. This page explains the law for practitioners; it is not legal advice.