---
title: "EU NIS2 Directive (EU) 2022/2555"
canonical_url: "https://www.sorena.io/artifacts/eu/nis2-directive"
source_url: "https://www.sorena.io/artifacts/eu/nis2-directive"
author: "Sorena AI"
description: "A practical EU NIS2 Directive artifact based on Directive (EU) 2022/2555, Article 21 cybersecurity risk-management measures, Article 23 reporting, and Implementing Regulation (EU) 2024/2690 where applicable."
published_at: "2026-02-23"
updated_at: "2026-07-16"
keywords:
  - "NIS2 Directive"
  - "Directive (EU) 2022/2555"
  - "Article 21 controls"
  - "Article 23 incident reporting"
  - "Implementing Regulation (EU) 2024/2690"
  - "NIS2"
  - "Cybersecurity risk management"
  - "Incident reporting"
  - "Article 21"
  - "Transposition"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# EU NIS2 Directive (EU) 2022/2555

A practical EU NIS2 Directive artifact based on Directive (EU) 2022/2555, Article 21 cybersecurity risk-management measures, Article 23 reporting, and Implementing Regulation (EU) 2024/2690 where applicable.

![EU NIS2 timeline and compliance planning preview](https://cdn.sorena.io/cdn-cgi/image/format=auto/cheatsheets/prod/sorena-ai-nis2-timeline-small.jpg?v=cheatsheets%2Fprod)

*NIS2* *Free Resource*

## EU NIS2 Directive Timeline and Compliance Guide

NIS2 is an EU directive for cybersecurity governance, risk management and significant-incident reporting. It can cover public or private entities that provide an Annex I or Annex II service or activity in the Union, usually when they are medium-sized or larger, plus specific entities captured regardless of size.

Start with the legal entity and service, then test sector, size and special cases, classify the entity as essential or important, identify the competent Member State, and map Articles 20, 21 and 23. The Directive is the EU baseline; national implementing law controls local registration, authority routes, procedure and penalties.

[Run the NIS2 applicability test](/artifacts/eu/nis2-directive/applicability-test.md)

## What you can decide faster

- **In scope or out of scope**: Map the actual service to an Annex I or Annex II entity type, apply the SME size calculation and linked-enterprise facts, then test the regardless-of-size and sector-specific-law rules. Inclusion on a national list is evidence to track, not a substitute for this legal analysis.
- **Essential vs important**: Both tiers have Articles 20, 21 and 23 duties. The main EU-level difference is supervision: essential entities can face ex ante and ex post supervision under Article 32, while important entities are supervised ex post under Article 33.
- **Controls + reporting**: Approve and oversee proportionate Article 21 measures, including supply-chain security, and prepare Article 23 reporting for significant incidents. Regulation (EU) 2024/2690 adds detailed rules only for the digital, ICT-management and trust-service entities it names.

By Sorena AI | Based on official EU sources | Updated July 2026

### Quick scan

*NIS2*

- **Scope**: Map the legal entity and service to Annex I or II, calculate size, check special inclusions and exclusions, then determine establishment and jurisdiction.
- **Controls**: Management bodies approve and oversee appropriate and proportionate Article 21 measures. Apply Regulation 2024/2690 only to its named entity types.
- **Reporting**: For a significant incident, preserve the awareness decision and route the 24-hour early warning, 72-hour notification, requested updates, and final or progress report through the applicable national channel.

Use the EU text for the baseline, then validate each in-scope entity against the applicable national law, competent authority, registration route and incident-reporting channel.

| Value | Metric |
| --- | --- |
| 16 Jan 2023 | In force |
| 17 Oct 2024 | Transposition |
| 17 Apr 2025 | Entity lists |
| 2024/2690 | Implementing act |

**Key highlights:** Essential vs important | Article 21 baseline | 24h/72h reporting

## Primary sources

- [Directive (EU) 2022/2555 (NIS 2 Directive)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555&ref=sorena.io) - Binding EU baseline for scope, entity classification, management-body accountability, cybersecurity measures, incident reporting, jurisdiction, registration, supervision and enforcement.
- [Commission Implementing Regulation (EU) 2024/2690](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ%3AL_202402690&ref=sorena.io) - Detailed Article 21 technical and methodological requirements and Article 23 significance criteria for the digital, ICT-management and trust-service entity types named in the Regulation.
- [European Commission - NIS2 transposition in EU countries](https://digital-strategy.ec.europa.eu/en/policies/nis-transposition?ref=sorena.io) - Commission state of play and country links; national implementing law and authority guidance remain necessary for country-specific conclusions.

*Recommended reading path*

## Choose the next NIS2 decision

New to NIS2? Start with the legal entity, service, sector, size and Member State nexus. Once scope and tier are documented, move to governance, controls, incident reporting, national implementation or the comparison you need.

### 1. Start here: scope, sector and entity tier

Decide whether the Directive covers the entity and service, whether a size-independent rule applies, whether the entity is essential or important, and which Member State route needs validation.

1. [EU NIS2 Directive applicability test for entity scope](/artifacts/eu/nis2-directive/applicability-test.md): Stepwise NIS2 applicability test for Annex I and Annex II sectors, medium and large entities, size-independent cases, essential or important classification, jurisdiction, and evidence.
2. [NIS2 Annex I and Annex II Sector Scoping Guide](/artifacts/eu/nis2-directive/annex-i-and-ii-sector-scoping.md): Map NIS2 Annex I and Annex II sectors, entity types, size-cap rules, and essential versus important entity classification with official EU sources.
3. [NIS2 Size Cap Rule and Special Scope Cases](/artifacts/eu/nis2-directive/size-cap-and-special-cases.md): Determine whether NIS2 applies under the medium-size rule, regardless-of-size special cases, critical entity rule, and Member State registration lists.
4. [NIS2 Entity Classifier Workflow: essential vs important entity scoping](/artifacts/eu/nis2-directive/entity-classifier-workflow.md): Classify whether an EU service is out of scope, an important entity, an essential entity, or needs national-authority review under the NIS2 Directive.
5. [NIS2 essential vs important entities: Article 3 scope and supervision guide](/artifacts/eu/nis2-directive/scope-essential-vs-important.md): Classify NIS2 essential and important entities using Article 3, Annex I and II sector scope, size-cap rules, registration evidence, and the Article 32/33 supervision split.
6. [NIS2 Registration and Authority Notification Guide](/artifacts/eu/nis2-directive/registration-and-authority-notification.md): Map NIS2 Article 3 entity-list duties, Article 27 registry submissions, competent-authority contacts, and national registration portal evidence without inventing country deadlines.

### 2. Governance, controls, evidence and enforcement

Translate the classification into management-body decisions, proportionate Article 21 measures, supply-chain controls, evidence records, supervisory readiness and penalty analysis.

7. [NIS2 essential vs important entities: supervision regime and audit evidence requirements](/artifacts/eu/nis2-directive/essential-vs-important-supervision.md): Compare NIS2 essential and important entities by scope, Article 21 and 23 duties, Article 32 and 33 supervision, evidence, jurisdiction, and penalties.
8. [NIS2 Management Body Accountability: board duties, training, and evidence](/artifacts/eu/nis2-directive/management-body-accountability.md): cited guide to NIS2 Article 20 management body accountability: approval of Article 21 measures, oversight, liability, training, reporting lines, and evidence.
9. [NIS2 Article 21 control baseline and evidence checklist](/artifacts/eu/nis2-directive/article-21-control-baseline.md): Build a NIS2 Article 21 control baseline from the Directive's minimum cybersecurity risk-management measures, proportionality test, supplier duties, and evidence expectations.
10. [NIS2 Article 21 control-by-control evidence checklist](/artifacts/eu/nis2-directive/article-21-control-by-control-evidence.md): Map NIS2 Article 21 risk-management measures to evidence records for governance, incident handling, continuity, supply chain, testing, cyber hygiene, cryptography, access, assets, and authentication.
11. [NIS2 Article 21 Gap Assessment Workflow: controls, evidence, and owners](/artifacts/eu/nis2-directive/article-21-gap-assessment-workflow.md): Assess NIS2 Article 21 cybersecurity risk-management gaps by mapping current controls to Article 21(2), ownership, evidence, supplier risk, and management review.
12. [NIS2 supply chain security program: Article 21 controls, contracts, and evidence](/artifacts/eu/nis2-directive/supply-chain-security-program.md): Build a NIS2 Article 21 supply chain security program for direct suppliers and service providers: policy, supplier criteria, contract clauses, monitoring, registry evidence, and cited checks.
13. [NIS2 Requirements: scope, Article 21 controls, reporting, and evidence](/artifacts/eu/nis2-directive/requirements.md): Map NIS2 requirements for essential and important entities: scope classification, management-body duties, Article 21 cybersecurity measures, Article 23 incident reporting, and evidence records.
14. [NIS2 Compliance Checklist: scope, controls, reporting](/artifacts/eu/nis2-directive/checklist.md): This NIS2 compliance checklist helps confirm scope, entity classification, management-body duties, Article 21 controls, Article 23 reporting, and evidence.
15. [NIS2 Compliance Guide: scope, controls, reporting, and evidence](/artifacts/eu/nis2-directive/compliance.md): A practical NIS2 compliance guide for mapping entity scope, Article 21 risk measures, Article 23 incident reporting, management accountability, and evidence records.
16. [NIS2 penalties and fines: Article 34 caps for essential and important entities](/artifacts/eu/nis2-directive/penalties-and-fines.md): NIS2 penalties and fines explained for EU essential and important entities, including Article 34 fine ceilings, Article 21 and 23 triggers, national transposition, and evidence to keep.

### 3. Significant-incident triage and reporting

Build the significance decision, awareness timestamp, national authority route, staged Article 23 submissions, recipient communications and defensible incident evidence before a crisis.

17. [NIS2 Article 23 incident notification workflow](/artifacts/eu/nis2-directive/article-23-notification.md): Map NIS2 Article 23 reporting duties for significant incidents: 24-hour early warning, 72-hour notification, intermediate reports, final report, recipients, and evidence.
18. [NIS2 incident clock triage workflow](/artifacts/eu/nis2-directive/incident-clock-triage-workflow.md): Triage a possible NIS2 significant incident by recording awareness time, severity, impact, authority route, recipient communications, and Article 23 reporting clocks.
19. [NIS2 Incident Reporting Workflow: 24-hour, 72-hour, and final report steps](/artifacts/eu/nis2-directive/incident-reporting-workflow.md): Build a NIS2 Article 23 incident reporting workflow with significance triage, CSIRT or authority notification steps, recipient communication, cross-border checks, and evidence records.

### 4. Dates and national implementation

Separate EU-level dates and historical infringement steps from the current national law, registration mechanism, authority instructions and operational country overlay that apply to each entity.

20. [EU NIS2 Directive deadlines and compliance calendar | Article 23 clocks](/artifacts/eu/nis2-directive/deadlines-and-compliance-calendar.md): cited NIS2 compliance calendar covering 17 October 2024 transposition, 18 October 2024 application, Article 27 registry data, Article 3 entity lists, Article 23 incident-reporting clocks, and Member State transposition watch items.
21. [NIS2 Country Implementation Matrix: Authorities, Portals, and Local Deltas](/artifacts/eu/nis2-directive/country-transposition-tracker.md): Build an operational NIS2 country matrix for applicable national law, competent authorities, registration, incident portals, local implementation deltas, evidence, and review dates.
22. [NIS2 National Transposition Tracker: EU Member State Evidence Register](/artifacts/eu/nis2-directive/national-transposition-tracker.md): Track NIS2 national transposition with Commission country pages, Article 41 dates, reasoned-opinion flags, source wording, authority contacts, and legal review triggers.

### 5. Compare regimes or answer a focused question

Keep NIS2 duties separate from CER, DORA, GDPR, NIS1 and voluntary ISO evidence, or use the FAQ when you already know the question you need to resolve.

23. [NIS2 vs CER Directive comparison: cyber obligations and critical-entity resilience](/artifacts/eu/nis2-directive/nis2-vs-cerc.md): Compare NIS2 and the CER Directive using cited rows for scope, triggers, evidence, incident handling, supervision, and shared critical-entity work.
24. [NIS2 vs DORA: scope, overlap, and evidence for EU cyber compliance](/artifacts/eu/nis2-directive/nis2-vs-dora.md): Compare NIS2 and DORA for EU cyber compliance: covered entities, when DORA replaces NIS2 duties for financial entities, incident reporting, evidence, and supervisory handoffs.
25. [NIS2 vs GDPR breach reporting: EU deadlines and overlap](/artifacts/eu/nis2-directive/nis2-vs-gdpr-breach-reporting.md): Compare NIS2 significant-incident reporting with GDPR personal-data-breach reporting, including scope, 24-hour and 72-hour clocks, evidence, and overlap.
26. [NIS2 vs ISO/IEC 27001: legal duties, ISMS evidence, and reuse limits](/artifacts/eu/nis2-directive/nis2-vs-iso-27001.md): Compare NIS2 legal obligations with ISO/IEC 27001 ISMS requirements: scope, Article 21 controls, incident clocks, SoA evidence, audits, and certification reuse.
27. [NIS2 vs ISO/IEC 27017: legal duties, cloud controls, and reuse limits](/artifacts/eu/nis2-directive/nis2-vs-iso-27017.md): Compare NIS2 legal obligations with ISO/IEC 27017 cloud-service controls: entity scope, Article 21 measures, incident clocks, shared responsibility, evidence, and assurance limits.
28. [NIS2 vs NIS1: what changed in EU cybersecurity compliance](/artifacts/eu/nis2-directive/nis2-vs-nis1.md): Compare NIS2 with the repealed NIS1 Directive: expanded sectors, essential and important entities, management-body duties, Article 21 controls, Article 23 reporting, and supervision.
29. [NIS2 FAQ: scope, Article 21 controls, incident reporting, and penalties](/artifacts/eu/nis2-directive/faq.md): cited NIS2 FAQ for teams deciding whether they are in scope, whether they are essential or important entities, which Article 21 cybersecurity measures apply, how Article 23 incident reporting works, and what penalties and evidence records to plan for.

### 6. More guides

Additional guidance related to this artifact.

30. [Are managed service providers in scope of NIS2?](/artifacts/eu/nis2-directive/faq/managed-service-provider-scope.md): NIS2 scope answer for managed service providers and managed security service providers, including service definition, size-cap checks, entity status, and jurisdiction evidence.
31. [FAQ: NIS2 essential vs important entity classification and registration obligations](/artifacts/eu/nis2-directive/faq/essential-vs-important-entities.md): Plain-English FAQ comparing NIS2 essential entities and important entities, with Article 3 classification rules, shared Article 21 and 23 duties, supervision differences, and evidence to keep.
32. [NIS2 24-hour early warning: what to send and when](/artifacts/eu/nis2-directive/faq/24-hour-early-warning.md): Under NIS2 Article 23, covered essential and important entities submit an early warning within 24 hours of becoming aware of a significant incident.
33. [NIS2 72-hour incident notification FAQ](/artifacts/eu/nis2-directive/faq/72-hour-incident-notification.md): Direct answer on the NIS2 72-hour incident notification: when it is due, what it updates, what it must include, and how to preserve evidence.
34. [NIS2 Member State Transposition: What Teams Must Check](/artifacts/eu/nis2-directive/faq/member-state-transposition.md): How to handle NIS2 Member State transposition: use Article 41 as the EU baseline, then verify national law, authority routing, registration, and incident-reporting details.
35. [NIS2 size-cap rule: when medium and large entities are in scope](/artifacts/eu/nis2-directive/faq/size-cap-rule.md): Plain-language FAQ on the NIS2 size-cap rule: medium and large Annex I or II entities, SME thresholds, regardless-of-size exceptions, and evidence to keep.

## Key dates for NIS2 compliance planning

*NIS2 Timeline*

Track adoption, transposition, entity list deadlines, the 2024 implementing regulation, the 2025 Commission enforcement step on late transposition, and the 2026 targeted amendment proposal while keeping your local overlays current.

*Next step*

## Turn NIS2 scoping, controls, and reporting into an assessment workflow

Use the timeline as the entry point for an NIS2 work plan: confirm Annex I or Annex II scope, record essential or important entity status, assign Article 21 control owners, and prepare the Article 23 incident reporting clock for the Member State authorities that apply to your services.

- Create a scope record for each service, legal entity, Member State, Annex sector, size-cap result, and any regardless-of-size trigger.
- Translate Article 20 and Article 21 into management approvals, risk-management measures, control owners, and evidence requests.
- Prepare incident triage so significant incidents can move from early warning to notification to final report within the NIS2 reporting sequence.
- Track national transposition overlays separately from the EU-level dates because portals, supervisory routes, and penalty rules are Member State specific.

- [Open Assessment Autopilot](/solutions/assessment.md): Convert NIS2 scope, Article 21 measures, and reporting duties into owned tasks, evidence requests, and review checkpoints.
- [Open Research Copilot](/solutions/research-copilot.md): Research scope, timing, Article 4 overlap, and Member State implementation questions with cited outputs.
- **Download timeline**: Share NIS2 transposition, entity-list, implementing-act, and review milestones across teams.
- [Talk through implementation](/contact.md): Review NIS2 applicability, control evidence, incident reporting handoffs, and national implementation dependencies.

## Compliance Timeline

| Date | Event | Category | Reference |
| --- | --- | --- | --- |
| 2020-12-16 | Commission publishes NIS2 proposal | Legislative History | [COM(2020) 823](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A52020PC0823&ref=sorena.io#:~:text=Brussels%2C%2016.12.2020%20COM%282020%29%20823%20final) |
| 2021-12-03 | NIS2 Council agrees its position | Legislative History | [Source](https://www.consilium.europa.eu/en/press/press-releases/2021/12/03/strengthening-eu-wide-cybersecurity-and-resilience-council-agrees-its-position/?ref=sorena.io) |
| 2022-05-13 | NIS2 political agreement reached | Legislative History | [Source](https://www.consilium.europa.eu/en/press/press-releases/2022/05/13/renforcer-la-cybersecurite-et-la-resilience-a-l-echelle-de-l-ue-accord-provisoire-du-conseil-et-du-parlement-europeen/?ref=sorena.io) |
| 2022-07-13 | NIS2 ITRE committee adopts agreed text | Legislative History | [Source](https://www.europarl.europa.eu/legislative-train/theme-a-europe-fit-for-the-digital-age/file-review-of-the-nis-directive?ref=sorena.io#:~:text=adopted%20by%20the%20ITRE%20committee%20on%2013%20July%202022) |
| 2022-11-10 | NIS2 Parliament plenary adoption | Legislative History | [Source](https://www.europarl.europa.eu/news/en/press-room/20221107IPR49608/cybersecurity-parliament-adopts-new-law-to-strengthen-eu-wide-resilience?ref=sorena.io#:~:text=MEPs%20adopted%20the%20text%20with%20577%20votes%20to%206%2C%20with%2031%20abstentions.) |
| 2022-11-28 | NIS2 Council formal adoption | Legislative History | [Source](https://www.consilium.europa.eu/en/press/press-releases/2022/11/28/eu-decides-to-strengthen-cybersecurity-and-resilience-across-the-union-council-adopts-new-legislation/?ref=sorena.io) |
| 2022-12-14 | NIS2 final act signed by co-legislators | Official Publication | [Source](https://www.europarl.europa.eu/legislative-train/theme-a-europe-fit-for-the-digital-age/file-review-of-the-nis-directive?ref=sorena.io#:~:text=signed%20by%20both%20co%2Dlegislators%20on%2014%20December%202022) |
| 2022-12-27 | NIS2 published in Official Journal | Official Publication | [OJ L 333, 27.12.2022](https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng?ref=sorena.io#:~:text=OJ%20L%20333%2C%2027.12.2022) |
| 2023-01-16 | NIS2 entry into force | Official Publication | [Source](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A02022L2555-20221227&ref=sorena.io#:~:text=This%20Directive%20shall%20enter%20into%20force%20on%20the%20twentieth%20day%20following%20that%20of%20its%20publication) |
| 2023-01-16 | NIS2 delegated-act power period begins | Commission Deliverables | [Arts. 24(2), 38(2)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A02022L2555-20221227&ref=sorena.io) |
| 2023-07-17 | NIS2 Commission deadline for Article 4 guidelines | Commission Deliverables | [Art. 4(3)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A52023XC0918%2801%29&ref=sorena.io#:~:text=the%20Commission%20shall%2C%20by%2017%20July%202023%2C%20provide%20guidelines) |
| 2023-09-14 | NIS2 guidelines on Article 3(4) published | Commission Deliverables | [2023/C 324/02](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ%3AC%3A2023%3A324%3AFULL&ref=sorena.io) |
| 2023-09-18 | NIS2 guidelines on Article 4(1)-(2) published | Commission Deliverables | [2023/C 328/02](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A52023XC0918%2801%29&ref=sorena.io#:~:text=pursuant%20to%20Article%204%283%29%20of%20Directive%20%28EU%29%202022/2555%2C%20the%20Commission%20shall%2C%20by%2017%20July%202023%2C%20provide%20guidelines) |
| 2023-12-22 | Corrigendum: Article 19(1) deadline wording | Corrigendum | [Art. 19(1)](https://eur-lex.europa.eu/eli/dir/2022/2555/corrigendum/2023-12-22/oj/eng?ref=sorena.io#:~:text=for%3A%20%E2%80%9CThe%20Cooperation%20Group%20shall%2C%20on%2017%20January%202025%E2%80%9D%20read%3A%20%E2%80%9Cby%2017%20January%202025%E2%80%9D) |
| 2024-02-01 | NIS2 Cooperation Group work programme due | Cooperation & Networks | [Art. 14(7)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32022L2555&ref=sorena.io#:~:text=By%201%20February%202024%20and%20every%20two%20years%20thereafter%2C%20the%20Cooperation%20Group%20shall%20establish%20a%20work%20programme) |
| 2024-07-17 | EU-CyCLONe first report due | Cooperation & Networks | [Art. 16(7)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A02022L2555-20221227&ref=sorena.io#:~:text=By%2017%20July%202024%20and%20every%2018%20months%20thereafter%2C%20EU-CyCLONe%20shall%20submit%20to%20the%20European%20Parliament%20and%20to%20the%20Council%20a%20report%20assessing%20its%20work.) |
| 2024-10-17 | Implementing Regulation 2024/2690 adopted | Implementing Acts | [Reg. (EU) 2024/2690; Arts. 21(5), 23(11)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ%3AL_202402690&ref=sorena.io) |
| 2024-10-17 | NIS2 transposition deadline | National Transposition | [Art. 41(1)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32022L2555&ref=sorena.io#:~:text=By%2017%20October%202024%2C%20Member%20States%20shall%20adopt%20and%20publish%20the%20measures) |
| 2024-10-18 | Implementing Regulation 2024/2690 published in OJ | Implementing Acts | [OJ L 2024/2690](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ%3AL_202402690&ref=sorena.io) |
| 2024-10-18 | NIS1 repealed, NIS2 measures apply | National Transposition | [Arts. 41-44](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A02022L2555-20221227&ref=sorena.io) |
| 2024-11-07 | Implementing Regulation 2024/2690 enters into force | Implementing Acts | [OJ L 2024/2690](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ%3AL_202402690&ref=sorena.io#:~:text=This%20Regulation%20shall%20enter%20into%20force%20on%20the%20twentieth%20day%20following%20that%20of%20its%20publication) |
| 2024-11-28 | Commission opens transposition infringement procedures | Enforcement & Infringements | [Art. 258 TFEU](https://digital-strategy.ec.europa.eu/en/news/commission-calls-23-member-states-fully-transpose-nis2-directive?ref=sorena.io) |
| 2025-01-17 | NIS2 registry information submission due | National Obligations | [Art. 27(2)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32022L2555&ref=sorena.io#:~:text=Member%20States%20shall%20require%20entities%20referred%20to%20in%20paragraph%201%20to%20submit%20the%20following%20information%20to%20the%20competent%20authorities%20by%2017%20January%202025) |
| 2025-01-17 | NIS2 Member States notify penalty rules | National Obligations | [Art. 36](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A02022L2555-20221227&ref=sorena.io#:~:text=Member%20States%20shall%2C%20by%2017%20January%202025%2C%20notify%20the%20Commission%20of%20those%20rules) |
| 2025-01-17 | NIS2 CSIRTs network progress report due | Cooperation & Networks | [Art. 15(4)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A02022L2555-20221227&ref=sorena.io#:~:text=By%2017%20January%202025%2C%20and%20every%20two%20years%20thereafter%2C%20the%20CSIRTs%20network%20shall) |
| 2025-01-17 | NIS2 peer-review methodology due | Cooperation & Networks | [Art. 19(1)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A02022L2555-20221227&ref=sorena.io#:~:text=The%20Cooperation%20Group%20shall%2C%20by%2017%20January%202025%2C%20establish) |
| 2025-04-17 | NIS2 entity list established | National Obligations | [Art. 3(3)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555&ref=sorena.io#:~:text=By%2017%20April%202025%2C%20Member%20States%20shall%20establish%20a%20list%20of%20essential%20and%20important%20entities) |
| 2025-04-17 | NIS2 aggregate entity data notification | National Obligations | [Art. 3(5)](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32022L2555&ref=sorena.io#:~:text=By%2017%20April%202025%20and%20every%20two%20years%20thereafter%2C%20the%20competent%20authorities%20shall%20notify) |
| 2025-05-07 | Commission sends reasoned opinions to 19 Member States | Enforcement & Infringements | [Art. 258 TFEU](https://ec.europa.eu/commission/presscorner/detail/en/inf_25_982?ref=sorena.io) |
| 2025-06-26 | ENISA technical implementation guidance published | Cooperation & Networks | [Version 1.0](https://www.enisa.europa.eu/publications/nis2-technical-implementation-guidance?ref=sorena.io) |
| 2026-01-20 | Commission proposes NIS2 amendment | Legislative History | [COM(2026) 13](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A52026PC0013&ref=sorena.io) |
| 2027-10-17 | Commission review of NIS2 | Commission Deliverables | [Art. 40](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A02022L2555-20221227&ref=sorena.io#:~:text=By%2017%20October%202027%20and%20every%2036%20months%20thereafter%2C%20the%20Commission%20shall%20review) |

**Event details:**

- **2020-12-16 - Commission publishes NIS2 proposal**: European Commission publishes the NIS2 proposal COM(2020) 823 final, proposing measures for a high common level of cybersecurity across the Union.
- **2021-12-03 - NIS2 Council agrees its position**: Council agrees its position (general approach) to start negotiations with the European Parliament.
- **2022-05-13 - NIS2 political agreement reached**: Council and European Parliament reach provisional political agreement on NIS2.
- **2022-07-13 - NIS2 ITRE committee adopts agreed text**: EP Industry, Research and Energy (ITRE) committee adopts the agreed text after trilogue.
- **2022-11-10 - NIS2 Parliament plenary adoption**: European Parliament adopts NIS2 in plenary: 577 in favour, 6 against, 31 abstentions.
- **2022-11-28 - NIS2 Council formal adoption**: Council of the EU formally adopts NIS2.
- **2022-12-14 - NIS2 final act signed by co-legislators**: NIS2 Directive signed by both co-legislators on 14 December 2022.
- **2022-12-27 - NIS2 published in Official Journal**: Directive (EU) 2022/2555 published in the Official Journal of the European Union (OJ L 333, 27.12.2022).
- **2023-01-16 - NIS2 entry into force**: NIS2 enters into force on the 20th day following OJ publication (16 January 2023). Member States have until 17 October 2024 to transpose.
- **2023-01-16 - NIS2 delegated-act power period begins**: The Commission power to adopt delegated acts under Article 24(2) applies for five years from 16 January 2023 and is tacitly extended unless the European Parliament or Council opposes under Article 38.
- **2023-07-17 - NIS2 Commission deadline for Article 4 guidelines**: Commission deadline to provide guidelines clarifying the application of Article 4(1) and Article 4(2).
- **2023-09-14 - NIS2 guidelines on Article 3(4) published**: Commission publishes Guidelines on the application of Article 3(4) with a data-collection template for establishing entity lists.
- **2023-09-18 - NIS2 guidelines on Article 4(1)-(2) published**: Commission publishes Guidelines on equivalence with sector-specific Union legal acts, pursuant to Article 4(3) (deadline was 17 Jul 2023).
- **2023-12-22 - Corrigendum: Article 19(1) deadline wording**: Corrigendum changes Article 19(1) deadline wording from 'on' to 'by' 17 January 2025 for the Cooperation Group peer-review methodology.
- **2024-02-01 - NIS2 Cooperation Group work programme due**: Cooperation Group must establish a work programme by 1 February 2024 and every two years thereafter.
- **2024-07-17 - EU-CyCLONe first report due**: EU-CyCLONe must submit a report assessing its work to the European Parliament and Council by 17 July 2024 and every 18 months thereafter.
- **2024-10-17 - Implementing Regulation 2024/2690 adopted**: Commission adopts Implementing Regulation (EU) 2024/2690 under Articles 21(5) and 23(11), laying down technical and methodological cybersecurity risk-management requirements and significant-incident criteria for DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, online marketplace providers, online search engine providers, social networking service platform providers, and trust service providers.
- **2024-10-17 - NIS2 transposition deadline**: Member States must adopt and publish national transposition measures by 17 October 2024. Measures apply from 18 October 2024.
- **2024-10-18 - Implementing Regulation 2024/2690 published in OJ**: Commission Implementing Regulation (EU) 2024/2690 is published in the Official Journal on 18 October 2024.
- **2024-10-18 - NIS1 repealed, NIS2 measures apply**: Directive (EU) 2016/1148 (NIS1) is repealed with effect from 18 October 2024 and national NIS2 measures apply from this date. Article 19 of eIDAS and Articles 40 and 41 of the European Electronic Communications Code are also deleted with effect from 18 October 2024.
- **2024-11-07 - Implementing Regulation 2024/2690 enters into force**: Commission Implementing Regulation (EU) 2024/2690 enters into force on the twentieth day following its Official Journal publication (published 18 October 2024).
- **2024-11-28 - Commission opens transposition infringement procedures**: The Commission sends letters of formal notice to 23 Member States for failing to fully transpose NIS2; the Member States had two months to respond and complete transposition.
- **2025-01-17 - NIS2 registry information submission due**: Member States must require entities referred to in Article 27(1) to submit registry information to competent authorities by 17 January 2025.
- **2025-01-17 - NIS2 Member States notify penalty rules**: Member States must notify the Commission of their national penalty rules and enforcement measures by 17 January 2025.
- **2025-01-17 - NIS2 CSIRTs network progress report due**: CSIRTs network must adopt a report assessing progress in operational cooperation by 17 January 2025 and every two years thereafter.
- **2025-01-17 - NIS2 peer-review methodology due**: Cooperation Group must establish the peer-review methodology and organisational aspects by 17 January 2025.
- **2025-04-17 - NIS2 entity list established**: Member States must establish a list of essential and important entities (and entities providing domain name registration services) by 17 April 2025.
- **2025-04-17 - NIS2 aggregate entity data notification**: Competent authorities must notify the Commission and Cooperation Group of aggregate list data (number of essential and important entities per sector) by 17 April 2025 and every two years thereafter.
- **2025-05-07 - Commission sends reasoned opinions to 19 Member States**: The Commission sends reasoned opinions to 19 Member States for failing to notify full NIS2 transposition; they had two months to respond before possible referral to the Court of Justice.
- **2025-06-26 - ENISA technical implementation guidance published**: ENISA publishes the NIS2 Technical Implementation Guidance (version 1.0) supporting implementation of Implementing Regulation (EU) 2024/2690.
- **2026-01-20 - Commission proposes NIS2 amendment**: Commission publishes proposal to amend NIS2 (simplification and alignment). This is a proposal, not yet law.
- **2027-10-17 - Commission review of NIS2**: The Commission shall review the functioning of the NIS2 Directive by 17 October 2027 and every 36 months thereafter, and submit a report to the European Parliament and Council.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/eu/nis2-directive.md
