NIS2 Directive: scope, cybersecurity measures and incident reporting
Covers Directive (EU) 2022/2555 (NIS2) and its Implementing Regulation (EU) 2024/2690 on the essential/important entity size-cap and sector scope (Annex I/II), the 10 minimum cybersecurity risk-management measures of Article 21, incident reporting deadlines and significance thresholds, management body liability and training, supervision and fines, registration obligations, supply-chain security and the relation with DORA, together with ENISA's technical implementation guidance and the Commission's transposition tracker. Built for CISOs, compliance and IT managers of medium and large companies, MSPs and public bodies who need precise, article-level answers rather than a general overview. Curated by Kopik from public sources: EUR-Lex / Publications Office of the European Union and European Commission (reuse authorised, Decision 2011/833/EU), ENISA (reproduction authorised with acknowledgement).
Posez votre question
Compte gratuit requisLes réponses sont rédigées par un modèle de langage à partir des seuls documents de cette base, avec leurs sources numérotées. Elles peuvent être inexactes et ne constituent pas un conseil juridique, médical ou financier : vérifiez les sources avant toute décision importante.
This assistant answers precise questions on the NIS2 Directive (EU) 2022/2555: who is in scope, which cybersecurity measures are required, how incidents must be reported and what supervisors can impose. It is meant for CISOs, compliance and IT managers, managed service providers and public bodies. Answers are drawn from the Directive itself, Implementing Regulation (EU) 2024/2690, Commission guidelines and Q&A, and ENISA guidance.
Who falls within the scope of NIS2
NIS2 applies to public or private entities of a type listed in Annex I or Annex II that qualify as medium-sized enterprises under Commission Recommendation 2003/361/EC, or exceed those ceilings, and that provide services or carry out activities in the Union. Under that Recommendation, the SME category covers enterprises with fewer than 250 persons and an annual turnover not exceeding EUR 50 million and/or a balance sheet total not exceeding EUR 43 million.
Some entities are covered regardless of size, for example providers of public electronic communications networks or services, trust service providers, top-level domain name registries and DNS service providers.
The Commission Q&A lists the sectors of high criticality (energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space) and other critical sectors such as postal services, waste management, chemicals, food, manufacturing, digital providers and research organisations.
Essential or important entity: why the category matters
Essential entities include Annex I entities that exceed the ceilings for medium-sized enterprises, qualified trust service providers, TLD name registries and DNS service providers regardless of size, and entities identified as critical entities under Directive (EU) 2022/2557. Entities of a type in Annex I or II that do not qualify as essential are important entities.
The category drives supervision. According to the Directive's recitals, essential entities are subject to a comprehensive ex ante and ex post supervisory regime, while important entities face a light, ex post only regime, triggered when the authority receives evidence or indications of non-compliance.
The ten minimum cybersecurity risk-management measures
Article 21 requires appropriate and proportionate technical, operational and organisational measures, based on an all-hazards approach. Proportionality takes into account the entity's exposure to risks, its size, and the likelihood and severity of incidents.
The measures must include at least: risk analysis and information system security policies; incident handling; business continuity, backup management, disaster recovery and crisis management; supply chain security; security in acquisition, development and maintenance, including vulnerability handling and disclosure; policies to assess the effectiveness of the measures; basic cyber hygiene and training; cryptography and, where appropriate, encryption; human resources security, access control and asset management; and multi-factor or continuous authentication and secured communications, where appropriate.
An entity that finds it does not comply must take the necessary corrective measures without undue delay.
Management body accountability
Article 20 requires the management bodies of essential and important entities to approve the cybersecurity risk-management measures, oversee their implementation, and makes them liable for infringements of Article 21.
Members of management bodies are required to follow training so they can identify risks and assess cybersecurity risk-management practices. Entities are encouraged to offer similar training to their employees on a regular basis.
Questions fréquentes
What are the maximum fines under NIS2?
For essential entities, Member States must provide for a maximum of at least EUR 10,000,000 or 2% of total worldwide annual turnover of the preceding financial year, whichever is higher. For important entities, the maximum must be at least EUR 7,000,000 or 1.4% of that turnover, whichever is higher. Authorities consider factors such as the nature, gravity and duration of the infringement and whether it was intentional or negligent.
Can a CEO be barred from managing an essential entity?
Yes, as an enforcement measure for essential entities. Authorities can request that the relevant bodies, courts or tribunals temporarily prohibit any person discharging managerial responsibilities at chief executive officer or legal representative level from exercising managerial functions in that entity, in accordance with national law.
How do authorities check compliance in practice?
NIS2 gives competent authorities a minimum list of supervisory means, including regular and targeted audits, on-site and off-site checks, requests for information and access to documents or evidence. Sanctions include binding instructions, orders to implement the recommendations of a security audit, orders to bring security measures in line with NIS2 requirements, and administrative fines.
When did Member States have to transpose NIS2?
The transposition deadline was 17 October 2024. On 7 May 2025 the Commission sent a reasoned opinion to 19 Member States for failing to notify full transposition, and on 8 July 2026 it referred Ireland, Spain, France and the Netherlands to the Court of Justice of the European Union.
Do we have to register with an authority?
Member States had to establish a list of essential and important entities by 17 April 2025 and review it at least every two years. Entities must submit at least their name, address, up-to-date contact details including email addresses, IP ranges and telephone numbers, their sector and subsector, and the Member States where they provide services. Member States may set up national mechanisms for entities to register themselves.
Which Member State supervises a company established in several countries?
As a rule, an entity is under the jurisdiction of the Member State where it is established, and of each Member State if it is established in several. Exceptions exist: for example, DNS service providers, cloud and data centre providers, managed service providers and online marketplaces fall under the Member State of their main establishment in the Union.
Intégrer / API / MCP
Branchez cette base à Claude, Cursor, ChatGPT ou votre propre application. Chaque requête API ou MCP coûte 0,10 €, débitée de votre crédit Kopik (non facturée si rien n'est trouvé). Il vous faut une clé API : créez-la depuis votre tableau de bord.
MCP pour vos agents
Adresse du serveur MCP de cette base (outils ask_base et search_base) :
https://kopik.io/api/mcp?base=eu-nis2-cybersecurityClaude Code, Cursor et autres clients
claude mcp add --transport http kopik-eu-nis2-cybersecurity "https://kopik.io/api/mcp?base=eu-nis2-cybersecurity" --header "Authorization: Bearer kpk_…"{
"mcpServers": {
"kopik-eu-nis2-cybersecurity": {
"url": "https://kopik.io/api/mcp?base=eu-nis2-cybersecurity",
"headers": {
"Authorization": "Bearer kpk_…"
}
}
}
}API REST pour vos applications
mode vaut "answer" (réponse rédigée + sources) ou "passages" (passages bruts seulement). Ajoutez un maxPriceCents facultatif pour plafonner le prix : si la base coûte plus cher, l'appel est refusé sans rien débiter.
curl -X POST https://kopik.io/api/v1/bases/eu-nis2-cybersecurity/query \
-H "Authorization: Bearer kpk_…" \
-H "Content-Type: application/json" \
-d '{"question": "Votre question ici", "mode": "answer"}'Pour commencer
- Créez une clé dans votre tableau de bord et rechargez votre crédit.
- Remplacez
kpk_…par votre clé. - Tout le détail (réponses, erreurs, exemples JS et Python) : documentation développeurs.