Requirements GuideEU

NIS2 Requirements

A practical map of the NIS2 duties teams usually need to operationalize: scope classification, management-body accountability, Article 21 cybersecurity measures, Article 23 incident reporting, and evidence records.

Use it to turn the directive text and implementing regulation into an owner-backed requirements register for security, legal, risk, procurement, incident-response, and country operations teams.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
6

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

NIS2 requirements begin with a service-level scope decision. Identify the legal entity, exact Annex row, SME or size-independent basis, essential or important tier, Article 26 jurisdiction, and national implementing law. Covered entities then need management-body governance, under Article 21, and significant-incident reporting under Article 23. If a sector-specific Union act has equivalent risk-management or incident-notification requirements, Article 4 displaces only the corresponding NIS2 provisions and their supervision and enforcement rules for the covered entities.

Section 1

Decide whether NIS2 applies before assigning requirements

Article 2 generally applies NIS2 to public or private entities of a type listed in Annex I or Annex II that qualify as medium-sized enterprises or exceed the medium-sized ceilings and provide services or carry out activities in the Union. Calculate size from annual work units, turnover or balance-sheet total, and the required partner and linked-enterprise aggregation. The Directive also includes specified entities regardless of size, including public electronic communications providers, trust service providers, TLD registries, DNS service providers, entities providing domain name registration services, certain sole providers and high-impact entities, public administration entities, and critical entities under Directive (EU) 2022/2557.

Article 3 then classifies in-scope entities as essential or important. Large Annex I entities, qualified trust service providers, TLD name registries, DNS service providers, certain public communications providers, public administration entities, and entities identified by Member States under Article 2(2) can be essential. Other in-scope Annex I or Annex II entities that are not essential are important.

Member States had to adopt and publish their transposition measures by 17 October 2024 and apply them from 18 October 2024. NIS2 is a directive, so the EU text sets the required result while national law supplies the local procedures, authority routes, and additional provisions. On 8 July 2026, the Commission said that Ireland, Spain, France, and the Netherlands had not notified full transposition; verify the current national position before assigning a country requirement.

  • Record the legal entity, Member State, service, sector, and Annex I or Annex II subsector before mapping controls.
  • Keep the size-cap analysis separate from special-case rules that apply regardless of size.
  • Document whether a sector-specific Union act is at least equivalent in effect for risk-management or significant-incident notification, which entities and duties it covers, and which NIS2 provisions remain.
  • Reassess scope after acquisitions, new EU services, sector changes, supplier changes, or Member State identification decisions.
Section 2

Put governance and accountability in the requirements register

Article 20 requires Member States to ensure that management bodies of essential and important entities approve the used to comply with Article 21, oversee implementation, and can be held liable for the entity's Article 21 infringements under the applicable national liability rules. Management-body members must follow training; regular employee training is encouraged.

Name both the executive approval owner and the operational control owner. The register should show how management reviews risk, approves measures, sees compliance-monitoring results, and receives incident or remediation updates.

  • Save management-body approval records for the Article 21 risk-management measures.
  • Track management-body training separately from general staff cybersecurity training.
  • Assign operational owners for security, incident response, continuity, supplier risk, access control, asset management, and evidence retrieval.
  • Keep board or management reporting packs aligned with the same control and incident records used by compliance teams.
Section 3

Map Article 21 cybersecurity risk-management measures to controls

Article 21 requires appropriate and proportionate technical, operational, and organisational measures to manage risks to network and information systems and to prevent or minimise incident impact on service recipients and other services. The measures must use an all-hazards approach and be proportionate to risk exposure, entity size, incident likelihood and severity, and societal and economic impact.

At minimum, the register should map Article 21(2)(a) through (j): risk analysis and information-system security policies; incident handling; business continuity, backup management, disaster recovery, and crisis management; supply-chain security for direct suppliers and service providers; secure acquisition, development, maintenance, vulnerability handling, and disclosure; effectiveness assessment; cyber hygiene and training; cryptography and encryption where appropriate; HR security, access control, and asset management; and multi-factor or continuous authentication plus secure communications where appropriate.

  • For each Article 21 requirement, record the control owner, system or service boundary, policy or procedure, testing method, and evidence location.
  • For supply chain security, include direct supplier and service-provider contracts, cybersecurity clauses, vulnerability-specific review, and secure-development checks.
  • For business continuity, connect backup, disaster recovery, and crisis-management evidence to services covered by the NIS2 scope decision.
  • For effectiveness assessment, keep monitoring results, security-test findings, remediation tickets, and management reports together.
Section 4

Add Article 23 incident reporting and recipient communications

Article 23 requires essential and important entities to notify the CSIRT or competent authority, without undue delay, of significant incidents. A has caused or is capable of causing severe operational disruption of services or financial loss for the entity, or considerable material or non-material damage to other natural or legal persons.

The workflow should preserve the Directive's sequence: early warning without undue delay and within 24 hours of awareness, incident notification without undue delay and within 72 hours, intermediate reports if requested, and a final report not later than one month after the incident notification. For ongoing incidents, the entity provides a progress report at that time and a final report within one month after handling. Trust service providers must submit the incident notification within 24 hours for significant incidents affecting their trust services.

  • Define when the entity becomes aware of a and who can start the reporting clock.
  • Capture severity, impact, indicators of compromise where available, suspected unlawful or malicious acts, and possible cross-border impact.
  • Prepare recipient communications for significant incidents or significant cyber threats where NIS2 requires notice or practical measures for affected recipients.
  • Map national reporting channels and authority names by Member State instead of relying only on the EU-level article text.
Section 5

Use the implementing regulation where it applies

Commission Implementing Regulation (EU) 2024/2690 lays down technical and methodological requirements for Article 21(2) measures and further specifies significant-incident cases for DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, online marketplaces, online search engines, social networking services platforms, and trust service providers.

For those provider types, the requirements register should not stop at Article 21's high-level categories. Use the Regulation's annex to detail the policies, risk framework, risk treatment, event detection, supply-chain policy, supplier register, secure acquisition, security testing, patch and vulnerability handling, cyber hygiene, cryptography, access control, asset classification, and physical or environmental security evidence. ENISA guidance is non-binding implementation support for that Regulation.

  • Mark whether each requirement is directly from NIS2 Article 21, the implementing regulation, national law, or internal policy.
  • Where a requirement is not appropriate, applicable, or feasible under the regulation's wording, document the reasoning in a comprehensible way.
  • For direct suppliers and service providers, keep selection criteria, contract clauses, SLA security terms, monitoring results, and registry updates.
  • Use ENISA guidance as implementation support, not as a substitute for the directive, implementing regulation, or Member State law.
Section 6

Evidence checklist for NIS2 requirements

The requirements register should produce an evidence checklist rather than a generic compliance statement. Connect each requirement to a legal source, service boundary, owner, implementation artifact, review cadence, and Member State authority path.

Keep the requirements register current when the entity changes services, sectors, EU countries, suppliers, digital provider status, incident process, or management-body approval route.

What are the main NIS2 requirements for covered entities?

Covered essential and important entities need scope and classification records, management-body governance under Article 20, under Article 21, significant-incident reporting under Article 23, and any additional national or sector-specific requirements that apply in the relevant Member State.

What evidence should teams keep for NIS2 requirements?

Keep the legal source, Member State basis, entity classification, Article 21 control mapping, management approval, training records, supplier and service-provider evidence, security-test and remediation records, incident-clock logs, authority notifications, recipient communications, and review triggers.

  • Scope file: legal entity, Member State, service, Annex sector, size-cap or special-case basis, essential or important classification, and sector-specific-law analysis.
  • Governance file: Article 20 approval, oversight records, management-body training, employee training, and liability escalation notes.
  • Control file: Article 21 control mapping, policies, risk assessment, risk treatment, business continuity, supplier security, vulnerability handling, testing, access control, asset management, and remediation records.
  • Incident file: significant-incident criteria, awareness timestamp, 24-hour early warning, 72-hour notification, intermediate reports, final report, recipient communications, and national channel evidence.
  • Covered-provider file: Regulation 2024/2690 applicability, technical requirement mapping, horizontal and provider-specific significant-incident criteria, recurring-incident review, supplier registry, contract clauses, and comprehensible reasoning where a requirement expressly allows an appropriateness, applicability, or feasibility decision.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Primary legal source for the requirements checklist across scope, governance, controls, incident reporting, and entity lists.
"cybersecurity risk-management measures and reporting obligations"
enisa.europa.eu
Referenced sections
  • ENISA implementation guidance for the 2024 regulation, including examples of evidence and implementation practices.
"Technical Implementation Guidance"
Related guides

Explore more topics

Are managed service providers in scope of NIS2?
NIS2 scope answer for managed service providers and managed security service providers, including service definition, size-cap checks, entity status, and jurisdiction evidence.
EU NIS2 Directive applicability test for entity scope
Stepwise NIS2 applicability test for Annex I and Annex II sectors, medium and large entities, size-independent cases, essential or important classification, jurisdiction, and evidence.
EU NIS2 Directive deadlines and compliance calendar | Article 23 clocks
NIS2 compliance calendar for EU transposition, Article 3 and 27 registration updates, Article 23 incident reports, technical measures, and the 2027 review.
NIS2 24-hour early warning: what to send and when
Under NIS2 Article 23, covered essential and important entities submit an early warning within 24 hours of becoming aware of a significant incident.
NIS2 72-hour incident notification FAQ
NIS2 incident-notification deadline, required initial assessment, evidence, follow-up, and the 24-hour trust-service-provider exception.
NIS2 Annex I and Annex II Sector Scoping Guide
Map NIS2 Annex I and Annex II sectors, entity types, size-cap rules, and essential versus important entity classification with official EU sources.
NIS2 Article 21 control baseline and evidence checklist
Build a NIS2 Article 21 control baseline from the Directive's minimum cybersecurity risk-management measures, proportionality test, supplier duties, and evidence expectations.
NIS2 Article 21 control-by-control evidence checklist
Map NIS2 Article 21 risk-management measures to evidence records for governance, incident handling, continuity, supply chain, testing, cyber hygiene, cryptography, access, assets, and authentication.
NIS2 Article 21 Gap Assessment Workflow: controls, evidence, and owners
Assess NIS2 Article 21 cybersecurity risk-management gaps by mapping current controls to Article 21(2), ownership, evidence, supplier risk, and management review.
NIS2 Article 23 incident notification workflow
Map NIS2 Article 23 reporting duties for significant incidents: 24-hour early warning, 72-hour notification, intermediate reports, final report, recipients, and evidence.
NIS2 Compliance Checklist: scope, controls, reporting
This NIS2 compliance checklist helps confirm scope, entity classification, management-body duties, Article 21 controls, Article 23 reporting, and evidence.
NIS2 Compliance Guide: scope, controls, reporting, and evidence
A practical NIS2 compliance guide for mapping entity scope, Article 21 risk measures, Article 23 incident reporting, management accountability, and evidence records.
NIS2 Country Implementation Matrix: Authorities, Portals, and Local Deltas
Build an operational NIS2 country matrix for applicable national law, competent authorities, registration, incident portals, local implementation deltas, evidence, and review dates.
NIS2 entity classification FAQ
Plain-English FAQ comparing NIS2 essential entities and important entities, with Article 3 classification rules, shared Article 21 and 23 duties, supervision differences, and evidence to keep.
NIS2 Entity Classifier Workflow: essential vs important entity scoping
Classify whether an EU service is out of scope, an important entity, an essential entity, or needs national-authority review under the NIS2 Directive.
NIS2 entity supervision guide
Compare NIS2 essential and important entities by scope, Article 21 and 23 duties, Article 32 and 33 supervision, evidence, jurisdiction, and penalties.
NIS2 essential vs important entities: Article 3 scope and supervision guide
Classify NIS2 essential and important entities using Article 3, Annex I and II sector scope, size-cap rules, registration evidence, and the Article 32/33 supervision split.
NIS2 FAQ: scope, Article 21 controls, incident reporting, and penalties
NIS2 FAQ on entity scope, essential and important classification, Article 21 measures, Article 23 reporting, national implementation, and evidence.
NIS2 incident clock triage workflow
Triage a possible NIS2 significant incident by recording awareness time, severity, impact, authority route, recipient communications, and Article 23 reporting clocks.
NIS2 Incident Reporting Workflow: 24-hour, 72-hour, and final report steps
Build a NIS2 Article 23 incident reporting workflow with significance triage, CSIRT or authority notification steps, recipient communication, cross-border checks, and evidence records.
NIS2 Management Body Accountability: board duties, training, and evidence
A guide to NIS2 Article 20 management body accountability: approval of Article 21 measures, oversight, national liability rules, training, reporting lines, and evidence.
NIS2 Member State Transposition: What Teams Must Check
How to handle NIS2 Member State transposition: use Article 41 as the EU baseline, then verify national law, authority routing, registration, and incident-reporting details.
NIS2 National Transposition Tracker: EU Member State Evidence Register
Track NIS2 national transposition with Commission country pages, Article 41 dates, reasoned-opinion flags, source wording, authority contacts, and legal review triggers.
NIS2 penalties and fines: Article 34 maximum levels and factors
NIS2 Article 34 fine levels, calculation factors, enforcement measures, GDPR overlap, and national-law checks for essential and important entities.
NIS2 Registration and Authority Notification Guide
Map NIS2 Article 3 entity-list duties, Article 27 registry submissions, competent-authority contacts, and national registration portal evidence without inventing country deadlines.
NIS2 Size Cap Rule and Special Scope Cases
Apply the NIS2 medium-size test, group-data rules, regardless-of-size cases, exclusions, and essential-versus-important classification.
NIS2 size-cap rule: when medium and large entities are in scope
Plain-language FAQ on the NIS2 size-cap rule: medium and large Annex I or II entities, SME thresholds, regardless-of-size exceptions, and evidence to keep.
NIS2 Supply Chain Security Program: Article 21 Guide
Apply NIS2 Article 21 to direct suppliers and service providers, and distinguish its general duty from Regulation 2024/2690's digital-entity controls.
NIS2 vs CER Directive comparison: cyber obligations and critical-entity resilience
Compare NIS2 and the CER Directive using cited rows for scope, triggers, evidence, incident handling, supervision, and shared critical-entity work.
NIS2 vs DORA: scope, overlap, and evidence for EU cyber compliance
Compare NIS2 and DORA for EU cyber compliance: covered entities, when DORA replaces NIS2 duties for financial entities, incident reporting, evidence, and supervisory handoffs.
NIS2 vs GDPR breach reporting: EU deadlines and overlap
Compare NIS2 significant-incident reporting with GDPR personal-data-breach reporting, including scope, 24-hour and 72-hour clocks, evidence, and overlap.
NIS2 vs ISO/IEC 27001: legal duties, ISMS evidence, and reuse limits
Compare NIS2 legal obligations with ISO/IEC 27001 ISMS requirements: scope, Article 21 controls, incident clocks, SoA evidence, audits, and certification reuse.
NIS2 vs ISO/IEC 27017: legal duties, cloud controls, and reuse limits
Compare NIS2 legal obligations with ISO/IEC 27017 cloud-service controls: entity scope, Article 21 measures, incident clocks, shared responsibility, evidence, and assurance limits.
NIS2 vs NIS1: what changed in EU cybersecurity compliance
Compare NIS2 with the repealed NIS1 Directive: expanded sectors, essential and important entities, management-body duties, Article 21 controls, Article 23 reporting, and supervision.