Kardu
Europa · NIS2

The new obligationin European cybersecurity

NIS2 (Directive (EU) 2022/2555) extends cybersecurity obligations to around 160,000 European companies in essential and important sectors, with fines of up to €10M or 2% of global turnover.

This guide summarizes the directive in plain language and does not replace legal advice. Always check the official text and your country’s law before making decisions.

What NIS2 is

It applies to medium and large companies (generally 50+ employees or €10M+ turnover) in critical sectors, and rests on three pillars.

Essential and important sectors

Energy, transport, banking, healthcare, digital infrastructure, public administration and other critical sectors, plus their suppliers.

Risk management measures

Risk analysis, incident handling, business continuity, supply chain security and access control, among others.

Staged notification

Early warning within 24 hours, incident notification within 72 hours, and a final report within one month.

Timeline and deadlines

01 / December 2022

Directive published

Directive (EU) 2022/2555 (NIS2) is published, expanding the scope and obligations of its NIS1 predecessor.

02 / October 17, 2024

Transposition deadline

Deadline for each member state to transpose NIS2 into national law.

03 / Applicable by country

Each country sets the detail

The effective rollout schedule, the sanctions regime and which specific entities are affected vary by each country’s national law.

By the numbers

~160K

European companies affected

21

Risk management measures

24h/72h

Staged notification

€10M/2%

Maximum fine (essential)

Sanctions

The directive sets maximum caps based on entity type; each country legislates the exact sanctions regime in its transposition law.

Entity typeMaximum fineSector examples
Essential entitiesUp to €10M or 2% of global turnover (whichever is higher)Energy, transport, banking, financial market infrastructure, healthcare, water, digital infrastructure.
Important entitiesUp to €7M or 1.4% of global turnover (whichever is higher)Postal services, waste management, manufacturing of critical products, digital providers, research.

76.3%

How much ISO 27001 covers of NIS2

According to Kardu’s internal control mapping, implementing the 93 controls of ISO 27001:2022 covers 76.3% of NIS2 requirements (71 of 93 controls). The rest are specific governance and notification obligations that NIS2 requires on its own.

What it means for your SME

NIS2 applies directly to medium and large companies in critical sectors. If your SME is smaller but supplies an affected company, you’ll likely be asked for compliance evidence anyway.

If you’re unsure whether your company is directly affected, it’s worth confirming with your country’s transposition law or with legal counsel.

6 minimum requirements

  • A documented risk analysis
  • A business continuity plan
  • An incident management procedure
  • A supply chain security assessment
  • Access control and identity management
  • A 24h / 72h incident notification plan

Official sources

This guide is a summary. For the legal detail, consult the directive’s text directly.

Official NIS2 text on EUR-Lex →
How Kardu helps

ISO 27001 as the base, NIS2 included

Kardu organizes your compliance evidence around ISO 27001 and maps it to NIS2 and any other frameworks that apply to you, so you don’t duplicate work across regulations.