Skip to content
Wednesday, August 26, 2026
KAJ NEWSCYBER · PRIVACY · SECURITY
Home / Tech News
Tech News

What NIS2 actually requires, in plain terms

The EU's NIS2 directive expands mandatory cybersecurity practices to thousands more organizations — here is who is covered, what the rules demand, and what the fines look like.

Asha Venkataswamy, · January 18, 2026 · 4 min read
ShareXFacebookLinkedInTelegramEmail
Compliance team reviewing security policy documents in a meeting room

NIS2 is the European Union's expanded cybersecurity directive that obliges a wide range of essential and important organizations — from hospitals and utilities to food processors, postal services, and managed IT providers — to maintain baseline security measures, report serious incidents within tight deadlines, and answer for management-level failures, with fines reaching €10 million or 2% of global turnover. It entered into force in 2023, with member states translating it into national law through 2024 and enforcement activity ramping through 2025 and into 2026. If your organization operates in the EU or provides services into it, the practical question is not whether the rules apply but which registration, reporting, and security obligations your national authority now enforces.

KAJ News publishes information, not legal advice; compliance determinations require counsel familiar with your jurisdiction's implementing law.

Who is covered?

NIS2 replaces the 2016 directive of the same family and roughly quadruples the population of regulated entities. It sorts them into two tiers. Essential entities include energy, transport, banking, health, drinking water, wastewater, digital infrastructure, public administration, and space. Important entities capture a longer tail: postal services, waste management, chemicals, food production and distribution, manufacturing, digital providers, and research. The size thresholds generally kick in above 50 employees or €10 million turnover, but size exemptions vanish for special sectors like healthcare and public administration. Crucially for the supply chain, managed service providers and data-center operators are covered regardless of customer size — which is how NIS2 reaches small firms through their enterprise customers.

What must covered organizations actually do?

Article 21 lists ten minimum measures, which read like a distilled security-basics checklist:

None of this is exotic. The directive mostly forces organizations to do documented, verifiable versions of what mature operators already do — and to prove it when asked.

What are the reporting deadlines?

Incident reporting runs on a strict clock once an incident is judged significant: an early warning within 24 hours, an incident notification within 72 hours covering initial assessment and indicators of compromise, and a final report within one month on root cause and mitigation. Significant incidents are those causing or capable of causing severe operational disruption or financial loss, or affecting others through the victim's services. That 24-hour early warning is the deadline most organizations are not operationally ready to meet — it presumes someone is already watching, with a drafted notification path to the national CSIRT.

Who is personally accountable, and what are the penalties?

Management bodies must approve security measures and can be held responsible for infringements — and member states are required to require training for management. Essential entities face fines up to €10 million or 2% of worldwide annual turnover, whichever is higher; important entities up to €7 million or 1.4%. Essential entities additionally face supervisory powers that include temporary suspension of certifications or authorizations and, for persistent failure, temporary bans on individuals exercising managerial functions. The directive also protects whistleblowers who report vulnerabilities or breaches.

What does NIS2 mean for non-EU companies?

Three spillover paths matter. First, EU-based subsidiaries and branches of foreign firms are directly covered. Second, covered EU entities must assess their suppliers' security, so vendors everywhere receive NIS2-shaped questionnaires and contract clauses. Third, the directive pattern is spreading — the EU's Cyber Resilience Act adds product-security duties, and other jurisdictions keep citing NIS2 as a model. As of 2026, the realistic posture for any vendor serving European customers is to meet the Article 21 list on paper and in practice, because the due-diligence chain transmits the obligation even where the law itself does not.

Frequently Asked Questions

When did NIS2 take effect?
The directive entered into force in January 2023; member states had until October 2024 to transpose it into national law, and enforcement has been ramping since, with national registers and authority activity visible through 2025 and 2026. Each country's deadline details differ.
Does NIS2 apply to companies outside the EU?
Directly, to EU subsidiaries and to certain providers offering services within the Union. Indirectly, to almost any vendor selling to a covered entity, because Article 21 supply-chain security forces customers to audit their providers.
What is the maximum fine under NIS2?
For essential entities, up to €10 million or 2% of worldwide annual turnover, whichever is higher; for important entities, up to €7 million or 1.4%. National implementing laws set the final numbers and procedures.
How fast must incidents be reported?
A significant incident triggers an early warning within 24 hours of awareness, a fuller notification within 72 hours, and a final report within one month — all to the designated national authority or CSIRT.