Shop
nl

What Is the NIS2 Directive, and Why Does It Matter?

The NIS2 directive is the European Union's cybersecurity law framework for essential and important entities across critical sectors. Rather than applying directly, it instructs each Member State to transpose its requirements into national legislation. This blog explains what that means, how NIS2 is structured, and when it actually starts to bind organizations.

What Is the NIS2 Directive Exactly?

NIS2 is the European Union's cybersecurity directive for organizations in critical and important sectors. Unlike a regulation, a directive doesn't apply directly to those organizations; it instructs Member States to translate its requirements into national law first. Only once that national law takes effect do the actual obligations become binding for entities within scope.

Michiel Benda's The NIS2 Navigator's Handbook explains this clearly, describing NIS2 as “an instruction to the Member States to create a national law based on the requirements stipulated in the Directive rather than a law in itself” (section 1.2). Until a country adopts that law, scoped entities remain free from its obligations, as the handbook also notes.

Why Does NIS2 Distinguish Between Recitals and Provisions?

NIS2 combines recitals, numbered from 1 to 144, with legally binding provisions organized into chapters, articles, and paragraphs. Recitals explain the reasoning behind the rules, while provisions set the actual requirements. When the two conflict, the provisions always take precedence, keeping interpretation consistent across the entire directive.

As the handbook notes, “the content of operative provisions always overrules the content of any associated recitals: if recitals are inconsistent with a provision, then the text of the provision will take precedence” (section 1.1). Member States may use recitals to clarify unclear provisions when drafting national law, though direct transposition of the recitals themselves remains optional.

Explore the NIS2 Directive in Depth with The NIS2 Navigator's Handbook

For a full breakdown of recitals, provisions, chapters, and enforcement powers, read The NIS2 Navigator's Handbook by Michiel Benda.

More about this standard

How Does NIS2 Move From EU Directive to National Law?

NIS2 entered into force on 16 January 2023, giving Member States 21 months to transpose it into national legislation. National laws needed to be adopted by 17 October 2024, and organizations became bound by those laws from 18 October 2024 onward, without any further transition period once national legislation applied.

The handbook frames this period as effectively 21 months of preparation, since most NIS2 requirements transfer to national law largely unchanged. It also flags a real risk: Member States could translate the directive differently, leaving multinational organizations facing inconsistent obligations across the EU (section 1.2).

What Do the Nine Chapters of NIS2 Cover?

NIS2 is divided into nine chapters and three annexes, moving from general definitions and national frameworks to cybersecurity risk-management obligations, supervision, and enforcement. For entities in scope, Chapter IV is the most important chapter, since it sets out the actual risk-management measures and incident-reporting obligations organizations must meet.

  • Chapters I–III: scope, definitions, national frameworks, and Union-level cooperation.
  • Chapter IV: risk-management measures and reporting obligations for scoped entities.
  • Chapters V–VI: jurisdiction, registration, and voluntary information sharing.
  • Chapters VII–IX: supervision, enforcement, delegated acts, and final provisions.
  • Annexes I–III: sectors of high criticality, other critical sectors, and the correlation table to the original NIS Directive.
  • Section 1.3 of the handbook describes each chapter in more detail, showing how the structure moves from national obligations toward direct requirements for organizations.

What Powers Does the Competent Authority Have Under NIS2?

Each Member State's competent authority receives extensive supervisory and enforcement powers under NIS2, from audits and information requests to binding instructions and fines. Essential entities face proactive, regular scrutiny, while important entities are typically supervised reactively, based on incidents or complaints that come to the authority's attention.

Enforcement measure Essential entities Important entities
Binding instructions and warnings Yes Yes
Monitoring officer or suspension of authorization Yes Not applicable
Administrative fine Up to €10 mil. or 2% of global annual turnover Up to €7 mil. or 1.4% of global annual turnover

According to section 1.9 of the handbook, natural persons acting as legal representatives can also be held personally liable for failing to ensure compliance with these obligations.

A directive, not a law

NIS2 only becomes binding once a Member State has translated it into national legislation, so compliance ultimately depends on the law derived from it in your own country.

Frequently asked questions

NIS2 is a directive, not a regulation, so it does not apply directly to organizations. It instructs Member States to create national legislation based on its requirements. Only once a country's law is in force, from 18 October 2024 at the latest, do scoped entities actually have to comply.

Chapter IV, on cybersecurity risk-management measures and reporting obligations, is described in The NIS2 Navigator's Handbook as the most important chapter for entities in scope. It sets out the concrete requirements organizations must implement, while other chapters mainly address national frameworks, cooperation, supervision, and enforcement mechanisms.

The competent authority can issue warnings, binding instructions, and, for essential entities, appoint a monitoring officer or suspend authorizations. Administrative fines can reach up to €10 million or 2% of global turnover for essential entities, and up to €7 million or 1.4% for important entities, alongside possible personal liability for managers.

The book behind this article

The NIS2 Navigator’s Handbook

The NIS2 Navigator’s Handbook

€ 59,90