NIS2 (Directive (EU) 2022/2555)
NIS2 (Directive (EU) 2022/2555) is the EU directive on the cybersecurity of essential and important entities. It obliges companies in 18 sectors to implement risk management, reporting processes and management accountability — unlike the CRA, it regulates organisations, not products. NIS2 replaces the first NIS Directive of 2016 and has been in force since January 2023; the deadline for transposition into national law expired on 17 October 2024.
Who falls under NIS2?
NIS2 distinguishes two categories with different levels of supervision:
| Category | Example sectors | Supervision |
|---|---|---|
| Essential entities | Energy, transport, health, water, digital infrastructure, banking | Proactive supervision, stricter sanctions |
| Important entities | Manufacturing (incl. machinery, electronics, vehicles), chemicals, food, digital services, postal services | Reactive supervision |
As a rule of thumb, the directive applies from medium company size — from 50 employees or 10 million euros in annual turnover — provided the company operates in one of the covered sectors. For individual types of entities, such as providers of critical digital infrastructure, it applies regardless of size. Compared with the first NIS Directive, NIS2 considerably widens the circle of those affected: large parts of the manufacturing industry in particular are covered for the first time.
What does NIS2 require?
The core is risk management measures (Article 21): affected entities must demonstrably implement, among other things, risk analyses and security policies, incident handling, business continuity, supply chain security, vulnerability management, cryptography and multi-factor authentication. Added to this are reporting obligations for significant security incidents: early warning within 24 hours, notification within 72 hours, final report within one month.
A distinctive feature is management accountability: the management bodies must approve the risk management measures, oversee their implementation and undergo training themselves — and can be held responsible for violations. Under NIS2, cybersecurity is no longer a delegable IT task, but a matter for top management.
In the event of violations, essential entities face fines of up to 10 million euros or 2 % of worldwide annual turnover, important entities up to 7 million euros or 1.4 % — whichever amount is higher applies.
NIS2 and the Cyber Resilience Act
NIS2 and the CRA are complementary: NIS2 demands secure organisations and processes from operators, the CRA demands secure products from manufacturers. The connection is concrete: entities subject to NIS2 must assess the security of their supply chain — CRA-compliant products with CE marking make exactly this evidence easier. And the national CSIRTs designated under NIS2 are at the same time the bodies to which manufacturers will address their CRA notifications under Article 14 from September 2026.
NIS2 in practice: clarify applicability, use structures twice
Since NIS2 is a directive, it does not apply directly but via national implementation laws — in Germany, this implementation has been delayed well beyond the deadline, and affected companies must register with the BSI under the German implementation act. The first step is therefore the applicability check: sector, size, role in the supply chain. Anyone who also manufactures products with digital elements should think about NIS2 and CRA preparation together: incident response processes, vulnerability management and reporting channels can be built once and used for both regulations.


