Network and Information Security Directive 2

NIS2 applies to essential and important entities across 18 sectors in the EU. Covered organizations must implement cybersecurity risk-management measures, report significant incidents in stages — 24-hour early warning, 72-hour notification, one-month final report — and hold management accountable. The transposition deadline was October 2024, but transposition remains incomplete in some member states, so exact duties and timing vary by country.

Updated 2026-08-30 · 21 tracked updates

NIS2 is the EU's updated directive on cybersecurity, replacing the original NIS Directive. It significantly expands the scope of sectors and entities covered, strengthens security requirements, and introduces more stringent enforcement measures.

21
Regulations Tracked
5
Jurisdictions
10
Upcoming Milestones
2026-08-30
Last Updated

Who Needs to Comply?

Essential and important entities across 18 sectors including energy, transport, banking, health, digital infrastructure, ICT service management, public administration, and space. Medium-sized and large organizations in these sectors.

Key Dates & Timeline

Entered into force January 2023. EU member states had until October 2024 to transpose into national law; transposition remains incomplete in some member states. Compliance deadlines vary by member state.

Upcoming Milestones

2026-12-02

Article 5 prohibitions on realistic intimate synthetic content and CSAM-related AI practices apply

Digital Omnibus on AI amends the EU AI Act
2026-12-02

Providers of AI systems generating synthetic audio, image, video or text must comply with Article 50(2) marking steps if placed on market before 2 Aug 2026

Digital Omnibus on AI amends the EU AI Act
2026-12-31

BAIT continues for some firms during transition period before DORA replacement

BaFin DORA implementation guidance and filing procedures
2027-01-01

Remaining FinmadiG transition ends for certain German institutions

BaFin DORA implementation guidance and filing procedures
2027-08-01

Commission deadline to publish AI Act guidance on complementarity and proportionality for Annex I-sector AI systems

Digital Omnibus on AI amends the EU AI Act

Latest NIS2 Updates

guidancehigh2026-08-30

EBA, EIOPA and ESMA call for enhanced governance over frontier AI ICT risks in EU financial services

On 2026-07-31, the EU supervisory authorities called for stronger governance and consistent supervision to mitigate ICT risks from frontier AI models in the financial sector, signaling that firms should tighten controls now rather than wait for formal rule changes.

guidancehigh2026-08-23

ESA call for enhanced governance and consistent supervision of frontier AI ICT risks

On 2026-07-31, EBA, EIOPA and ESMA called on EU financial-sector firms and supervisors to tighten governance and supervision of frontier AI-related ICT risks, signaling immediate expectations for stronger control frameworks under existing resilience obligations.

executive-actionmedium2026-08-16

NIST AI RMF update process tied to White House AI Action Plan

NIST says the AI RMF 1.0 is being revised under the July 23, 2025 White House AI Action Plan, which means organizations relying on the framework should expect updated implementation guidance and profile changes rather than a static reference.

guidancehigh2026-08-16

EU AI Office and supervisors call for enhanced governance for frontier AI in financial services

EU financial supervisors and the AI Office are signaling stronger governance and consistent supervision expectations for frontier AI models in the financial sector, so firms should treat this as an immediate AI Act implementation and risk-governance update rather than a future issue.

guidancehigh2026-08-02

ESAs call for stronger governance over frontier AI ICT risks in EU finance

On 2026-07-31, the EBA, EIOPA and ESMA issued a joint statement urging a cross-sector, risk-based and consistent supervisory approach for frontier AI models because their ICT risks are now a live supervisory concern in the EU financial sector.

amendmentcritical2026-07-26

Digital Omnibus on AI amends the EU AI Act

Regulation (EU) 2026/1744 amends the AI Act and makes the new prohibitions on realistic intimate/deepfake-style synthetic content and the updated Article 50 transparency obligations operative from 2 December 2026, creating immediate implementation work for AI providers and deployers.

guidancehigh2026-07-12

ESAs support ESRB warning on systemic cyber risks from frontier AI models

On 2026-07-07, the European Supervisory Authorities backed the ESRB’s warning that frontier AI models can create systemic cyber risks for financial markets, elevating AI cyber resilience as a supervisory priority.

guidancehigh2026-07-05

EESC opinion on the AI Omnibus and Digital Omnibus simplification proposals

The EESC backed simplification of the AI Act and digital rulebook while warning that high-risk AI obligations are still expected to become binding as early as August 2026, so firms should not delay compliance planning pending omnibus negotiations.

guidancemedium2026-06-21

NIST AI RMF critical infrastructure profile concept note

On 2026-04-07 NIST released a concept note for a trustworthy AI in critical infrastructure profile, indicating active profile development that regulated operators should monitor now.

guidancehigh2026-06-07

ESAs publish first annual report on DORA major ICT-related incidents

On 2026-06-03, the EBA, EIOPA and ESMA published their first annual overview of major ICT-related incidents under DORA, underscoring that borderless ICT and AI-driven risks now require financial entities to tighten cybersecurity and incident-reporting readiness.

Jurisdiction Coverage

Related Frameworks

Key Topics

Frequently Asked Questions

Who must comply with NIS2 and what does it require?

NIS2 applies to essential and important entities across 18 sectors in the EU. Covered organizations must implement cybersecurity risk-management measures, report significant incidents in stages — 24-hour early warning, 72-hour notification, one-month final report — and hold management accountable. The transposition deadline was October 2024, but transposition remains incomplete in some member states, so exact duties and timing vary by country.

What is NIS2?

NIS2 is the European Union's updated Network and Information Security Directive. It establishes cybersecurity risk management and incident reporting obligations for organizations across critical sectors, replacing and expanding the original NIS Directive.

How does NIS2 differ from NIS1?

NIS2 significantly expands scope from 7 to 18 sectors, introduces size-based criteria for determining covered entities, strengthens risk management requirements, mandates faster incident reporting (24-hour early warning), and introduces personal liability for management bodies.

What are the penalties under NIS2?

Essential entities face fines up to 10 million euros or 2% of global annual turnover. Important entities face fines up to 7 million euros or 1.4% of global annual turnover. Management bodies can be held personally liable.

Keep exploring

This hub tracks published NIS2 actions at EU and national level; it is not legal advice, and national transpositions differ in scope and deadlines.