- EU implementing regulation that applies from 7 November 2024 and specifies Article 21 technical and methodological requirements and Article 23 significant-incident criteria for covered entity types.
"technical and methodological requirements"
Track the cited NIS2 dates that affect entity registration, Member State implementation, incident reporting, and recurring review work.
Assign legal, security, incident-response, procurement, and country owners to each date, trigger, filing route, and evidence record.
Structured answer sets in this page tree.
Cited legal and guidance references.
Use this calendar to separate EU dates that have passed from deadlines that start when an entity becomes aware of an incident or changes registration data. The Directive required Member States to apply national measures from 18 October 2024, but an entity's current duties, authority, portal, and any national registration date come from the implementing law in the Member State with jurisdiction. Confirm that national position before assigning a filing date.
Article 41 required Member States to adopt and publish their measures by 17 October 2024 and apply them from 18 October 2024. Article 44 repealed Directive (EU) 2016/1148 from 18 October 2024. These were deadlines for Member States, not a single EU filing date imposed directly on every entity.
For an organisation in scope, the working calendar should identify the Member State with jurisdiction under Article 26, then record its national implementing law, competent authority or CSIRT, registration process, incident-reporting route, and any local dates. A provider operating across borders may need a different jurisdiction analysis depending on its service type; do not assume that every Member State where customers are located receives the same filing.
Article 27 creates a separate registry workstream for DNS service providers, TLD name registries, entities providing domain name registration services, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, online marketplaces, online search engines, and social networking services platforms.
Member States had to require those entities to submit specified information to competent authorities by 17 January 2025. That date has passed, so a newly identified or unregistered entity should check the current national mechanism rather than treating the Directive's date as a new grace period. After submission, changes must be notified without delay and in any event within three months of the change.
Article 3 required Member States to establish a list of essential and important entities, plus entities providing domain name registration services, by 17 April 2025. Member States must review and, where appropriate, update the list regularly and at least every two years.
Two separate update clocks matter. An entity covered by the Article 3 list must notify changes to its submitted details without delay and within two weeks of the change. Competent authorities must report entity counts to the Commission and Cooperation Group every two years. The two-year authority cycle does not give an entity two years to correct its own details.
Article 23 starts when an essential or important entity becomes aware of a significant incident. An incident is significant if it caused or could cause severe operational disruption or financial loss for the entity, or considerable material or non-material damage to another person. National rules and, for specified digital providers, Implementing Regulation (EU) 2024/2690 add detail to that assessment.
Reports are due without undue delay and no later than the stated outer limits: an early warning within 24 hours, an incident notification within 72 hours, an intermediate report if requested, and a final report no later than one month after the incident notification. If the incident is still ongoing when the final report is due, submit a progress report then and the final report within one month after handling the incident. A trust service provider has a specific exception: its incident notification for a significant incident affecting its trust services is due within 24 hours, not 72.
also placed implementing-act work on the Commission. Article 21(5) required the Commission, by 17 October 2024, to adopt implementing acts for technical and methodological cybersecurity risk-management requirements for specified digital infrastructure, ICT service management, digital provider, and trust service provider categories.
Commission Implementing Regulation (EU) 2024/2690 has applied since 7 November 2024. For the entity types it covers, it specifies Article 21 technical and methodological requirements and Article 23 significance criteria. The calendar should therefore include control reviews and incident-threshold testing for those entities, with evidence for policies, assets, incident handling, access control, supply-chain controls, vulnerability handling, and the other requirements in the Regulation.
National implementation remained incomplete after the EU deadline. On 8 July 2026, the Commission decided to refer Ireland, Spain, France, and the Netherlands to the Court of Justice for failing to notify full transposition, and asked the Court to impose a lump sum and daily penalties until complete notification. This enforcement step concerns Member State transposition; it does not establish an entity's duties or excuse an entity from national measures already in force.
The longer-term EU review row is Article 40: by 17 October 2027 and every 36 months thereafter, the Commission must review the functioning of the Directive and report to the European Parliament and the Council. Compliance calendars should treat that as a policy-watch item, not an entity filing deadline.
Sorena can help maintain NIS2 dates, incident clocks, registry duties, country transposition watch items, and technical-control evidence in one compliance calendar.
Ask questions tied to cited sources about NIS2 Article 23 clocks, Article 27 registry data, Article 3 entity lists, transposition status, and technical-control evidence.
Review your NIS2 calendar, Member State authority routes, evidence gaps, and owner assignments with Sorena.
"technical and methodological requirements"
"By 17 October 2024"
"within 72 hours of becoming aware"
"by 17 January 2025"
"By 17 April 2025"
"By 17 October 2027"
"They shall apply those measures from 18 October 2024."
"high common level of cybersecurity across the Union"
"examples of evidence"
"application of Article 3(4)"
"The early warning should be followed by an incident notification"
"Member States had until 17 October 2024"
"without prejudice to the formal assessment"