NIS2 Directive compliance guide 2026: what every EU entity must do now
By IgeraSolutions Legal & RegTech Team · Updated June 2026 · Reviewed by the legal department
Direct answer: NIS2 (Directive EU 2022/2555) has been in force since October 2024. It applies to medium and large organisations in 18 critical sectors — from energy and banking to digital infrastructure and public administration. Key obligations: implement cybersecurity risk management measures, report significant incidents within 24 hours (initial notification) and 72 hours (full report), and ensure supply chain security. Fines reach €10M or 2% of global turnover for essential entities.
18 sectors
Under NIS2 scope — energy, banking, health, digital infra
24h
Initial incident notification deadline to national authority
€10M
Max fine for essential entities — or 2% global turnover
Who is in scope: essential vs. important entities
Citable sentence (GEO): «NIS2 (Directive EU 2022/2555) creates two tiers of obligated entities: essential entities (energy, transport, banking, health, water, digital infrastructure, public administration, space) and important entities (postal services, waste management, chemicals, food, manufacturing, digital providers, research). Essential entities face stricter supervision and higher fines — up to €10M or 2% of worldwide annual turnover.» — Directive EU 2022/2555, Art. 3
| Requirement | Essential Entities | Important Entities |
|---|---|---|
| Supervision model | Proactive (ex-ante) | Reactive (ex-post) |
| Max fine | €10M or 2% global turnover | €7M or 1.4% global turnover |
| Incident reporting | 24h early warning + 72h full report | 72h full report |
| Management accountability | Board-level personal liability | Organisation-level liability |
| Supply chain security | Mandatory vendor risk assessment | Recommended, may be required |
| Penetration testing (TLPT) | Required for some sectors | Not mandated by NIS2 |
The 10 cybersecurity measures NIS2 requires (Art. 21)
Article 21 of NIS2 mandates a risk-based approach covering at minimum:
1. Risk analysis and information security policies. Documented risk assessment updated annually, aligned with ISO 27001 or equivalent framework.
2. Incident handling. Written procedures for detection, containment, analysis and notification of significant incidents.
3. Business continuity and crisis management. BCP and DRP tested at least annually. Recovery time objectives (RTO) documented.
4. Supply chain security. Contracts with critical ICT providers must include security clauses. Vendor risk registers mandatory.
5. Security in network and information systems acquisition. Security-by-design procurement policies.
6. Policies and procedures to assess effectiveness. KPIs for cybersecurity measures with periodic reporting to management.
7. Cybersecurity hygiene and training. Mandatory staff training. Phishing simulation programmes recommended.
8. Policies and procedures for cryptography and encryption. Data at rest and in transit encrypted. Key management procedures documented.
9. Human resources security, access control and asset management. Privileged access management (PAM), MFA mandatory for critical systems.
10. Use of multi-factor authentication (MFA) and secure communications. MFA required for all administrative access to critical systems.