The new obligationin European cybersecurity
NIS2 (Directive (EU) 2022/2555) extends cybersecurity obligations to around 160,000 European companies in essential and important sectors, with fines of up to €10M or 2% of global turnover.
This guide summarizes the directive in plain language and does not replace legal advice. Always check the official text and your country’s law before making decisions.
What NIS2 is
It applies to medium and large companies (generally 50+ employees or €10M+ turnover) in critical sectors, and rests on three pillars.
Essential and important sectors
Energy, transport, banking, healthcare, digital infrastructure, public administration and other critical sectors, plus their suppliers.
Risk management measures
Risk analysis, incident handling, business continuity, supply chain security and access control, among others.
Staged notification
Early warning within 24 hours, incident notification within 72 hours, and a final report within one month.
Timeline and deadlines
01 / December 2022
Directive published
Directive (EU) 2022/2555 (NIS2) is published, expanding the scope and obligations of its NIS1 predecessor.
02 / October 17, 2024
Transposition deadline
Deadline for each member state to transpose NIS2 into national law.
03 / Applicable by country
Each country sets the detail
The effective rollout schedule, the sanctions regime and which specific entities are affected vary by each country’s national law.
~160K
European companies affected
21
Risk management measures
24h/72h
Staged notification
€10M/2%
Maximum fine (essential)
Sanctions
The directive sets maximum caps based on entity type; each country legislates the exact sanctions regime in its transposition law.
| Entity type | Maximum fine | Sector examples |
|---|---|---|
| Essential entities | Up to €10M or 2% of global turnover (whichever is higher) | Energy, transport, banking, financial market infrastructure, healthcare, water, digital infrastructure. |
| Important entities | Up to €7M or 1.4% of global turnover (whichever is higher) | Postal services, waste management, manufacturing of critical products, digital providers, research. |
76.3%
How much ISO 27001 covers of NIS2
According to Kardu’s internal control mapping, implementing the 93 controls of ISO 27001:2022 covers 76.3% of NIS2 requirements (71 of 93 controls). The rest are specific governance and notification obligations that NIS2 requires on its own.
What it means for your SME
NIS2 applies directly to medium and large companies in critical sectors. If your SME is smaller but supplies an affected company, you’ll likely be asked for compliance evidence anyway.
If you’re unsure whether your company is directly affected, it’s worth confirming with your country’s transposition law or with legal counsel.
6 minimum requirements
- A documented risk analysis
- A business continuity plan
- An incident management procedure
- A supply chain security assessment
- Access control and identity management
- A 24h / 72h incident notification plan
Official sources
This guide is a summary. For the legal detail, consult the directive’s text directly.
Official NIS2 text on EUR-Lex →ISO 27001 as the base, NIS2 included
Kardu organizes your compliance evidence around ISO 27001 and maps it to NIS2 and any other frameworks that apply to you, so you don’t duplicate work across regulations.