Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallNIS2 is the EU’s cybersecurity directive for certain public and private entities. It requires covered organizations to manage cyber risks and report significant incidents, but it is not a single EU-wide checklist that determines every company’s status: coverage and practical procedures depend on the entity’s activities, the directive’s rules and exceptions, and the relevant Member State’s implementation.
What is NIS2?
NIS2 is Directive (EU) 2022/2555. Its stated aim is “to achieve a high common level of cybersecurity across the Union, with a view to improving the functioning of the internal market” (Article 1(1)). It combines duties for Member States—such as national cybersecurity strategies and authorities—with risk-management, incident-reporting, information-sharing, supervision, and enforcement rules for specified entities.
The directive repealed the earlier NIS Directive, Directive (EU) 2016/1148, from 18 October 2024. NIS2 is a directive rather than a complete, self-contained compliance determination for each organization: Member States transpose its requirements into national law, and some technical requirements are set out in a separate implementing act.
Does NIS2 apply to my company?
You cannot determine coverage from a company’s name or broad industry label alone. The analysis depends on what service the entity provides, whether that activity falls within a sector listed in Annex I or II, where it provides the service or carries out the activity, its size, and whether an exception, special rule, or national designation applies. Article 3 sets out the entity and size rules; the directive also includes cases in which an entity may be covered regardless of size or through specific identification provisions.
Recommended Free Tools
#1 Best Overall
Use these questions to organize a scope assessment:
- What does the entity actually do? Identify the service and activity, rather than relying only on its registered business description.
- Is that activity in Annex I or Annex II? Annex I covers high-criticality sectors; Annex II covers other critical sectors. Check the directive’s annexes against the entity’s actual activities.
- Where does it provide the service or carry out the activity? Establish the relevant countries and any jurisdictional facts needed under the directive and national law.
- How large is the entity, and does a special rule apply? Apply the directive’s size rule and check its exceptions and provisions for entities covered regardless of size.
- What does the relevant Member State’s law or authority say? Check national transposition, competent-authority guidance, and whether the entity has been identified or listed under the applicable rules.
Member States were required to establish and maintain lists of essential and important entities and domain-name registration service providers. The directive set 17 April 2025 as the initial list-establishment milestone and requires regular review, at least every two years. Being included on a list may be relevant to the entity’s status, but an organization should assess the legal rules applicable to its particular facts rather than treating a list—or its absence—as a substitute for that analysis.
What is the difference between essential and important entities?
NIS2 distinguishes essential entities from important entities, and that categorization matters to the directive’s supervision framework. The categorization is not interchangeable with the annex distinction: Annex I identifies high-criticality sectors and Annex II other critical sectors, while essential and important are entity categories established under the directive and national implementation.
| Distinction | What it means | What to verify |
|---|---|---|
| Annex I versus Annex II | Annex I covers high-criticality sectors; Annex II covers other critical sectors. | Whether the entity’s actual service or activity falls within a listed sector. |
| Essential versus important entity | NIS2 uses these entity categories in its framework, including supervision and enforcement. | The entity’s classification under the directive and the applicable national rules. |
The category and the applicable national law inform how the supervisory framework applies. Do not infer a particular regulator, procedure, or penalty from the category alone; those operational details require checking the current law and guidance in the relevant Member State.
Rank #3
What cybersecurity measures does NIS2 require?
Article 21 requires essential and important entities to take appropriate and proportionate technical, operational, and organizational measures. The measures must manage risks to the security of the network and information systems used for the entity’s operations or services, and prevent or minimize the impact of incidents. The directive identifies these areas:
- Risk analysis and information-system security policies.
- Incident handling.
- Business continuity, including backup management, disaster recovery, and crisis management.
- Supply-chain security, including security aspects of relationships with direct suppliers and service providers.
- Security in the acquisition, development, and maintenance of network and information systems, including vulnerability handling and disclosure.
- Policies and procedures for assessing whether cybersecurity risk-management measures are effective.
- Basic cyber hygiene practices and cybersecurity training.
- Policies and procedures on cryptography and, where appropriate, encryption.
- Human-resources security, access-control policies, and asset management.
- Multi-factor or continuous authentication solutions, secure voice, video, and text communications, and secure emergency communications systems, where appropriate.
“Appropriate and proportionate” is the directive’s standard; it does not prescribe one identical technical setup for every entity. The right measures depend on the risks, the entity’s circumstances, applicable national rules, and any directly applicable implementing requirements. ENISA’s version 1.0 technical implementation guidance (2025) concerns requirements under Commission Implementing Regulation (EU) 2024/2690 for specified provider categories. It is not a universal substitute for assessing an organization’s legal obligations.
What are the NIS2 incident-reporting deadlines?
Article 23 applies its staged reporting sequence to a significant incident. An incident is significant if it has caused or is capable of causing severe operational disruption or financial loss for the entity, or considerable material or non-material damage to other persons. A cybersecurity event is not automatically reportable simply because it occurred; assess the legal threshold and the national reporting process.
| Stage | Deadline | What is required |
|---|---|---|
| Early warning | Without undue delay and within 24 hours after becoming aware of the significant incident | Indicate, where applicable, whether unlawful or malicious acts are suspected and whether the incident could have cross-border impact. |
| Incident notification | Without undue delay and within 72 hours after becoming aware of the significant incident | Update the early warning and provide an initial assessment of severity and impact, plus indicators of compromise where available. |
| Intermediate report | When requested by the CSIRT or competent authority | Provide an update as requested. |
| Final report | No later than one month after the incident notification | Submit the final report. If incident handling is still ongoing at that point, submit a progress report and the final report within one month after incident handling concludes. |
Notifications go to the CSIRT or, where applicable, the competent authority. The national authority or CSIRT provides the operational reporting route and procedures. NIS2 also addresses notifying affected recipients of services in relevant circumstances, so the organization may have communication duties beyond its report to the authority.
Best Value
What happens if an organization does not comply?
NIS2 requires Member States to establish supervision and enforcement arrangements. The directive distinguishes essential and important entities in that framework, but the applicable authority, procedures, and consequences must be checked in the relevant Member State’s current transposition. There is no single national fine or regulator that can safely be stated for every organization across the EU.
For an organization, a practical first step is to identify the competent authority or CSIRT for its jurisdiction and understand the national procedures that apply to its entity category. A determination of status or enforcement exposure requires the organization’s facts and the applicable national rules.
How does NIS2 interact with sector-specific EU laws?
Article 4 provides an equivalence mechanism for certain sector-specific EU legal acts. Where such an act imposes risk-management or incident-notification obligations with at least equivalent effect for entities it covers, relevant NIS2 provisions may not apply to those entities. That does not mean every organization in a regulated sector is automatically exempt: the sector-specific act, the obligations it imposes, and which entities it covers must be examined. Entities outside its coverage remain subject to NIS2 where they otherwise fall within the directive.
When did NIS2 take effect?
The directive required Member States to adopt and publish their transposition measures by 17 October 2024 and apply those measures from 18 October 2024. The entity-list milestone was 17 April 2025, with the lists to be reviewed regularly and at least every two years. These are EU-level dates set by Directive (EU) 2022/2555; for operational decisions, check the current national law, authority guidance, and reporting procedures in each relevant country.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

