This comparison helps separate current NIS2 obligations from the repealed NIS1 framework, especially scope, entity classification, governance, risk-management controls, incident reporting, registration, and supervision.
Based on the NIS2 Directive, the NIS1 Directive, and the European Commission NIS2 overview.
Directive (EU) 2022/2555 () repealed Directive (EU) 2016/1148 (NIS1) from 18 October 2024. NIS2 broadened sector coverage, replaced the operator-of-essential-services model with essential and important entity tiers, added management-body duties, specified a minimum risk-management baseline, and introduced staged incident reporting. Reuse old evidence only after mapping it to the current directive and the applicable national law.
Side-by-side comparison
NIS2 vs NIS1: practical compliance differences
This comparison helps separate current duties from legacy NIS1 records and to decide which older evidence needs remapping.
The current EU cybersecurity framework for essential and important entities, with Article 20 governance, Article 21 risk-management measures, Article 23 reporting, registration, and differentiated supervision.
Second framework
NIS1 Directive
The earlier EU cybersecurity directive for operators of essential services and digital service providers; repealed from 18 October 2024 but still useful for interpreting legacy records.
Applies to public or private entities of types listed in Annex I or Annex II that meet the size-cap rule, plus specific regardless-of-size categories and Member State special cases.
Applied to Member State-identified operators of essential services in seven Annex II sector groups and to online marketplaces, online search engines, and cloud computing services as Annex III digital services. Micro and small enterprises were excluded from the digital-service-provider requirements.
Essential and important entities must act, and their management bodies must approve cybersecurity risk-management measures, oversee implementation, and follow training.
Operators of essential services and digital service providers carried the security and notification duties, while Member States, competent authorities, single points of contact, and CSIRTs ran the national framework.
The trigger starts with Annex I or Annex II entity type, medium-sized-or-larger status unless an exception applies, essential or important classification, and any national registration or list process.
For operators of essential services, the trigger depended on Member State identification using the essential-service, network-dependency, and significant-disruption tests. For digital service providers, it depended on offering an Annex III service in the Union, subject to the micro- and small-enterprise exclusion.
NIS1 required appropriate and proportionate technical and organisational measures and notification without undue delay. Operators reported incidents with a significant impact on continuity of essential services; digital service providers reported incidents with a substantial impact on their Annex III service.
Keep Article 2 and Article 3 classification, entity-list or registration details where applicable, Article 20 approvals and training, Article 21 control evidence, Article 23 reports, supplier-risk evidence, and supervision correspondence.
Keep NIS1 national designation records, lists of essential services, security policies, audit evidence, incident notifications, and communications with competent authorities or CSIRTs.
Member States had to adopt and publish transposition measures by 17 October 2024 and apply them from 18 October 2024. Article 23 uses a 24-hour early warning, 72-hour incident notification, and final-report sequence for significant incidents.
NIS1 required Member States to transpose by 9 May 2018, identify operators of essential services by 9 November 2018, and use national incident-notification rules before repeal.
gives competent authorities supervisory and enforcement powers for essential and important entities, with proactive-style powers for essential entities and ex post supervision for important entities.
NIS1 gave competent authorities powers to assess operators of essential services and take ex post action for digital service providers, with penalties set through national implementing rules.
maps many NIS1 topics forward: security measures, incident notification, competent-authority requests, standards, penalties, and review all have correlation-table links to NIS2 articles.
Reuse older evidence only after confirming the current article, national rule, owner, and evidence quality; do not treat correlation as automatic compliance.
For , write the current sector, entity classification, Member State, national law or authority path, Article 20/21/23 duties, evidence owner, and reassessment trigger.
For NIS1, write what the record proves historically: operator or digital-service-provider status, security measure, incident notification, authority correspondence, or old national deadline.
Close the migration only when every legacy NIS1 item is either remapped to a current duty, retained as historical evidence, or removed from the active compliance plan.
Applies to public or private entities of types listed in Annex I or Annex II that meet the size-cap rule, plus specific regardless-of-size categories and Member State special cases.
Applied to Member State-identified operators of essential services in seven Annex II sector groups and to online marketplaces, online search engines, and cloud computing services as Annex III digital services. Micro and small enterprises were excluded from the digital-service-provider requirements.
Essential and important entities must act, and their management bodies must approve cybersecurity risk-management measures, oversee implementation, and follow training.
Operators of essential services and digital service providers carried the security and notification duties, while Member States, competent authorities, single points of contact, and CSIRTs ran the national framework.
The trigger starts with Annex I or Annex II entity type, medium-sized-or-larger status unless an exception applies, essential or important classification, and any national registration or list process.
For operators of essential services, the trigger depended on Member State identification using the essential-service, network-dependency, and significant-disruption tests. For digital service providers, it depended on offering an Annex III service in the Union, subject to the micro- and small-enterprise exclusion.
NIS1 required appropriate and proportionate technical and organisational measures and notification without undue delay. Operators reported incidents with a significant impact on continuity of essential services; digital service providers reported incidents with a substantial impact on their Annex III service.
Keep Article 2 and Article 3 classification, entity-list or registration details where applicable, Article 20 approvals and training, Article 21 control evidence, Article 23 reports, supplier-risk evidence, and supervision correspondence.
Keep NIS1 national designation records, lists of essential services, security policies, audit evidence, incident notifications, and communications with competent authorities or CSIRTs.
Member States had to adopt and publish transposition measures by 17 October 2024 and apply them from 18 October 2024. Article 23 uses a 24-hour early warning, 72-hour incident notification, and final-report sequence for significant incidents.
NIS1 required Member States to transpose by 9 May 2018, identify operators of essential services by 9 November 2018, and use national incident-notification rules before repeal.
gives competent authorities supervisory and enforcement powers for essential and important entities, with proactive-style powers for essential entities and ex post supervision for important entities.
NIS1 gave competent authorities powers to assess operators of essential services and take ex post action for digital service providers, with penalties set through national implementing rules.
maps many NIS1 topics forward: security measures, incident notification, competent-authority requests, standards, penalties, and review all have correlation-table links to NIS2 articles.
Reuse older evidence only after confirming the current article, national rule, owner, and evidence quality; do not treat correlation as automatic compliance.
For , write the current sector, entity classification, Member State, national law or authority path, Article 20/21/23 duties, evidence owner, and reassessment trigger.
For NIS1, write what the record proves historically: operator or digital-service-provider status, security measure, incident notification, authority correspondence, or old national deadline.
Close the migration only when every legacy NIS1 item is either remapped to a current duty, retained as historical evidence, or removed from the active compliance plan.
NIS1 was the EU's first horizontal cybersecurity directive for network and information systems. Member States identified operators of essential services in energy, transport, banking, financial-market infrastructure, health, drinking-water supply and distribution, and digital infrastructure. NIS1 separately covered three digital services: online marketplaces, online search engines, and cloud computing services. replaced that model with a broader framework for essential and important entities in Annex I and Annex II sectors.
For compliance planning after 18 October 2024, use and the applicable Member State transposition law. Keep NIS1 records as historical evidence or as inputs that must be remapped to current Article 20, Article 21, Article 23, registration, supervision, and national requirements; repeal did not convert an old designation or control into proof of NIS2 compliance.
Use for current entity classification, sector mapping, risk-management measures, incident reporting, and supervision.
Use NIS1 to understand older operator-of-essential-services and digital-service-provider records that may still exist in audits, registers, or control libraries.
Do not assume a NIS1 designation or exemption settles scope; rerun the Annex I or Annex II, size-cap, and special-case analysis.
NIS1 covered Member State-identified operators of essential services only where the service was essential to critical societal or economic activities, depended on network and information systems, and an incident would have a significant disruptive effect. It separately covered online marketplaces, online search engines, and cloud computing services as digital service providers. uses Annex I and Annex II entity types, generally applies the medium-size cap, and adds regardless-of-size and Member State identification routes. The two scope tests are not interchangeable.
also moves accountability upward. Management bodies of essential and important entities must approve cybersecurity risk-management measures, oversee implementation, and follow training, while Article 21 lists a minimum set of measures covering risk analysis, incident handling, business continuity, supply chain security, vulnerability handling, effectiveness assessment, cyber hygiene, cryptography, access control, asset management, and authentication.
Replace NIS1 operator-of-essential-services checks with essential-or-important entity classification.
Add management-body approval, oversight, and training evidence where applies.
Map each technical control to the relevant Article 21 measure instead of citing a generic NIS security program.
Use the current Article 23 incident sequence instead of NIS1's 'without undue delay' notification model and its separate substantial-impact factors for digital service providers.
Start with Article 2 and Article 3: identify whether the entity is public or private, whether it belongs to a type in Annex I or Annex II, whether the size-cap rule applies, and whether a special rule brings the entity in regardless of size. Then classify the entity as essential or important under Article 3.
NIS1 evidence can identify legacy services and authority history, but it cannot replace the current classification. NIS2 required Member States to establish lists of essential and important entities and domain name registration service providers by 17 April 2025 and to review and update those lists at least every two years.
Record the Annex I or Annex II sector, subsector, and entity type.
Document the size-cap conclusion and any special case that applies regardless of size.
Identify the Member State jurisdiction, registration route, and authority contact when applicable.
Trigger reassessment when services, countries, customers, suppliers, or corporate size facts materially change.
A NIS1-era control library may still contain useful security policies, audit results, incident logs, and authority correspondence. The migration task is to relabel each item against the current duty it supports, or mark it as historical only.
For , keep entity classification, registration details where required, management-body approval and training records, Article 21 control evidence, supplier-risk files, incident-notification clock logs, final reports, and supervision correspondence. The evidence owner should be able to retrieve the record and explain the cited reason it exists.
Separate legal interpretation ownership from operational control ownership.
Attach the article, national transposition reference, or authority request to each evidence item.
Keep legacy NIS1 records with a status label: reused under , superseded, or retained for history.
Make incident evidence show the 24-hour early warning, 72-hour notification, intermediate updates if requested, and final report when Article 23 applies.
This NIS2 vs NIS1 guide is a cited implementation workflow
Sorena can help convert legacy NIS1 records into NIS2 scope decisions, owner assignments, Article 21 evidence requests, incident-reporting workflows, and national-transposition review steps.
Binding NIS1 text for operators of essential services, digital service providers, security requirements, incident notification, national implementation, and historical comparison with NIS2.
Binding NIS2 text for scope, essential and important entity classification, Article 20 governance, Article 21 risk-management measures, Article 23 reporting, supervision, enforcement, transposition, and repeal of NIS1.
"high common level of cybersecurity across the Union"
Commission implementing regulation setting technical and methodological requirements for selected NIS2 digital infrastructure and ICT service management entities.