NIS2 Essential Entities Guide: What the Directive Requires in 2026
NIS2 transposition deadlines passed in October 2024. If you operate in energy, transport, banking, health, digital infrastructure or public administration, you are already subject to enforcement. Here is the complete obligation map.
Key figures: NIS2 covers ~160,000 entities across the EU. Essential entities: max fine €10M or 2% global annual turnover. Important entities: max fine €7M or 1.4% turnover. Incident notification: 24h early warning, 72h full notification, 1 month final report.
Essential vs Important entities — are you in scope?
| Criterion | Essential Entity | Important Entity |
|---|---|---|
| Size | Large (≥250 employees or ≥€50M turnover) | Medium (≥50 employees or ≥€10M turnover) |
| Sectors (Annex I) | Energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space | Postal, waste management, chemicals, food production, manufacturing, digital providers, research |
| Supervision | Ex-ante (proactive, ongoing) | Ex-post (triggered by incident or complaint) |
| Max penalty | €10M or 2% global turnover | €7M or 1.4% global turnover |
Note: certain entities are in scope regardless of size — DNS providers, TLD registries, cloud providers, data centres, CDNs, and electronic communication networks.
10 mandatory security measures (Art. 21)
NIS2 Article 21 requires a risk-based approach covering at minimum:
- Risk analysis and information system security policies
- Incident handling — detection, response, recovery procedures
- Business continuity — backup management, disaster recovery, crisis management
- Supply chain security — including relationships with direct suppliers and service providers
- Security in network and information systems acquisition, development and maintenance
- Policies and procedures to assess effectiveness of cybersecurity risk-management measures
- Basic cyber hygiene practices and cybersecurity training
- Policies on the use of cryptography and, where appropriate, encryption
- Human resources security, access control policies and asset management
- Multi-factor authentication (MFA) or continuous authentication solutions
Incident notification timeline
Management liability — the key change from NIS1
NIS2 explicitly makes management bodies personally liable for cybersecurity failures. This is the biggest cultural shift from NIS1:
- Management must approve cybersecurity risk management measures
- Management must oversee their implementation
- Management can be held personally liable for infringements
- Competent authorities can temporarily ban managers from leadership roles for serious or repeated failures
- All managers must complete regular cybersecurity training
Practical implication: "The IT department handles security" is no longer a valid board position. Cybersecurity is now a board-level governance obligation, not an operational technicality.
NIS2 compliance checklist
FAQ
NIS2 compliance Q&A — answered instantly
IgeraRegTech NIS2 indexes the full directive and your internal policies, so your team gets instant, cited answers to any compliance question.
Explore IgeraRegTech NIS2Updated: June 2026 | Sources: Directive (EU) 2022/2555 (NIS2), ENISA NIS2 Implementation Guidance 2024, European Commission NIS2 FAQ | This article is informational; consult a cybersecurity legal specialist for entity-specific compliance advice.