Cybersecurity regulation
NIS2: who it applies to and what it requires
In short
NIS2 (Directive (EU) 2022/2555) is the EU’s updated cybersecurity directive. It expands cybersecurity risk-management and incident-reporting obligations across a much wider range of essential and important entities, and introduces management accountability and stricter supervision. Member States were to transpose it into national law by 17 October 2024, so exact obligations follow each country’s implementing legislation.
Last reviewed: August 2026
Who it applies to
NIS2 splits organizations into “essential” and “important” entities across sectors such as energy, transport, banking, health, digital infrastructure, ICT service management, public administration, water, waste, food, manufacturing, postal services and digital providers. Medium and large entities in those sectors are generally in scope. Being classified essential vs important mainly changes the intensity of supervision, not the core duties.
Core requirements
- Risk-management measures covering policies, incident handling, business continuity and supply-chain security (Art. 21)
- Basic cyber hygiene, cryptography, access control and asset management
- A multi-stage incident reporting process (Art. 23)
- Supply-chain and supplier security as an explicit obligation
- Management bodies must approve and oversee the measures — and can be held liable
Incident reporting timeline
NIS2 introduces a staged reporting duty for significant incidents:
- 1Early warning to the CSIRT or competent authority within 24 hours
- 2Incident notification within 72 hours, with an initial assessment
- 3A final report within one month
Typical compliance challenges
- Confirming whether — and under which national law — you are in scope
- Standing up 24h/72h/1-month incident reporting that actually works under pressure
- Extending security requirements across the supply chain, not just internally
- Giving the management body evidence it can sign off on
- Avoiding duplicate effort where NIS2 overlaps ISO 27001
What can reasonably be automated
- Mapping NIS2 risk-management measures to existing ISO 27001 controls
- Continuous control monitoring and evidence collection
- An incident workflow with the 24h/72h/1-month clocks built in
- Supplier inventory, risk assessment and continuous questionnaires
- A reporting pack the management body can review and approve
Evidence and documentation
- Cybersecurity risk-management policies and their approval by management
- Asset inventory, access control and business-continuity plans
- Incident register and reports filed with authorities
- Supplier security assessments and contractual measures
- Records of testing, training and improvement actions
Relationship to ISO 27001
NIS2 does not mandate ISO 27001, but a certified ISMS covers a large part of the required risk-management measures. Treating them as overlapping frameworks — one control mapped to both — avoids double-documenting and gives the management body a single source of truth.
How Isodora supports NIS2
Isodora turns NIS2’s risk-management and reporting duties into a continuous operation rather than an annual exercise.
One control, many frameworks
Map NIS2 measures to the ISO 27001 controls you already run, so you never double-document.
Incident workflow with the clock built in
A staged process reflecting the 24h early warning, 72h notification and one-month final report.
Supply-chain oversight
Supplier inventory, risk assessment and continuous questionnaires — token-based, no supplier logins needed.
Board-ready reporting
A management-review pack the accountable body can actually sign off on.
NIS2 is transposed differently in each Member State. Isodora helps you operationalize the measures; scope and exact obligations depend on the applicable national law.
Frequently asked questions
- Who needs to comply with NIS2?
- Medium and large organizations operating in the sectors NIS2 designates as essential or important — including energy, transport, banking, health, digital infrastructure, public administration, water, food and manufacturing — as defined by each Member State’s implementing law.
- What is the difference between NIS2 and ISO 27001?
- NIS2 is binding EU cybersecurity law with reporting duties and management liability; ISO 27001 is a voluntary international standard you can certify against. They overlap heavily on risk-management measures, so a strong ISO 27001 ISMS is a solid foundation for NIS2.
- What are the NIS2 incident-reporting deadlines?
- For a significant incident: an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month.
- When did NIS2 take effect?
- The directive entered into force in January 2023, and Member States were required to transpose it into national law by 17 October 2024. The precise obligations that bind your organization come from your country’s implementing legislation.