Network and Information Security Directive 2
NIS2 applies to essential and important entities across 18 sectors in the EU. Covered organizations must implement cybersecurity risk-management measures, report significant incidents in stages — 24-hour early warning, 72-hour notification, one-month final report — and hold management accountable. The transposition deadline was October 2024, but transposition remains incomplete in some member states, so exact duties and timing vary by country.
Updated 2026-08-30 · 21 tracked updates
NIS2 is the EU's updated directive on cybersecurity, replacing the original NIS Directive. It significantly expands the scope of sectors and entities covered, strengthens security requirements, and introduces more stringent enforcement measures.
Who Needs to Comply?
Essential and important entities across 18 sectors including energy, transport, banking, health, digital infrastructure, ICT service management, public administration, and space. Medium-sized and large organizations in these sectors.
Key Dates & Timeline
Entered into force January 2023. EU member states had until October 2024 to transpose into national law; transposition remains incomplete in some member states. Compliance deadlines vary by member state.
Upcoming Milestones
Article 5 prohibitions on realistic intimate synthetic content and CSAM-related AI practices apply
Digital Omnibus on AI amends the EU AI ActProviders of AI systems generating synthetic audio, image, video or text must comply with Article 50(2) marking steps if placed on market before 2 Aug 2026
Digital Omnibus on AI amends the EU AI ActBAIT continues for some firms during transition period before DORA replacement
BaFin DORA implementation guidance and filing proceduresRemaining FinmadiG transition ends for certain German institutions
BaFin DORA implementation guidance and filing proceduresCommission deadline to publish AI Act guidance on complementarity and proportionality for Annex I-sector AI systems
Digital Omnibus on AI amends the EU AI ActLatest NIS2 Updates
EBA, EIOPA and ESMA call for enhanced governance over frontier AI ICT risks in EU financial services
On 2026-07-31, the EU supervisory authorities called for stronger governance and consistent supervision to mitigate ICT risks from frontier AI models in the financial sector, signaling that firms should tighten controls now rather than wait for formal rule changes.
ESA call for enhanced governance and consistent supervision of frontier AI ICT risks
On 2026-07-31, EBA, EIOPA and ESMA called on EU financial-sector firms and supervisors to tighten governance and supervision of frontier AI-related ICT risks, signaling immediate expectations for stronger control frameworks under existing resilience obligations.
NIST AI RMF update process tied to White House AI Action Plan
NIST says the AI RMF 1.0 is being revised under the July 23, 2025 White House AI Action Plan, which means organizations relying on the framework should expect updated implementation guidance and profile changes rather than a static reference.
EU AI Office and supervisors call for enhanced governance for frontier AI in financial services
EU financial supervisors and the AI Office are signaling stronger governance and consistent supervision expectations for frontier AI models in the financial sector, so firms should treat this as an immediate AI Act implementation and risk-governance update rather than a future issue.
ESAs call for stronger governance over frontier AI ICT risks in EU finance
On 2026-07-31, the EBA, EIOPA and ESMA issued a joint statement urging a cross-sector, risk-based and consistent supervisory approach for frontier AI models because their ICT risks are now a live supervisory concern in the EU financial sector.
Digital Omnibus on AI amends the EU AI Act
Regulation (EU) 2026/1744 amends the AI Act and makes the new prohibitions on realistic intimate/deepfake-style synthetic content and the updated Article 50 transparency obligations operative from 2 December 2026, creating immediate implementation work for AI providers and deployers.
ESAs support ESRB warning on systemic cyber risks from frontier AI models
On 2026-07-07, the European Supervisory Authorities backed the ESRB’s warning that frontier AI models can create systemic cyber risks for financial markets, elevating AI cyber resilience as a supervisory priority.
EESC opinion on the AI Omnibus and Digital Omnibus simplification proposals
The EESC backed simplification of the AI Act and digital rulebook while warning that high-risk AI obligations are still expected to become binding as early as August 2026, so firms should not delay compliance planning pending omnibus negotiations.
NIST AI RMF critical infrastructure profile concept note
On 2026-04-07 NIST released a concept note for a trustworthy AI in critical infrastructure profile, indicating active profile development that regulated operators should monitor now.
ESAs publish first annual report on DORA major ICT-related incidents
On 2026-06-03, the EBA, EIOPA and ESMA published their first annual overview of major ICT-related incidents under DORA, underscoring that borderless ICT and AI-driven risks now require financial entities to tighten cybersecurity and incident-reporting readiness.
Jurisdiction Coverage
Related Frameworks
Key Topics
Frequently Asked Questions
Who must comply with NIS2 and what does it require?
NIS2 applies to essential and important entities across 18 sectors in the EU. Covered organizations must implement cybersecurity risk-management measures, report significant incidents in stages — 24-hour early warning, 72-hour notification, one-month final report — and hold management accountable. The transposition deadline was October 2024, but transposition remains incomplete in some member states, so exact duties and timing vary by country.
What is NIS2?
NIS2 is the European Union's updated Network and Information Security Directive. It establishes cybersecurity risk management and incident reporting obligations for organizations across critical sectors, replacing and expanding the original NIS Directive.
How does NIS2 differ from NIS1?
NIS2 significantly expands scope from 7 to 18 sectors, introduces size-based criteria for determining covered entities, strengthens risk management requirements, mandates faster incident reporting (24-hour early warning), and introduces personal liability for management bodies.
What are the penalties under NIS2?
Essential entities face fines up to 10 million euros or 2% of global annual turnover. Important entities face fines up to 7 million euros or 1.4% of global annual turnover. Management bodies can be held personally liable.
Keep exploring
This hub tracks published NIS2 actions at EU and national level; it is not legal advice, and national transpositions differ in scope and deadlines.