Updated: 21 July 2026
What is the NIS2 Directive and who does it cover? NIS2 (Directive (EU) 2022/2555) entered into force on 16 Jan 2023 and required Member States to transpose it by 17 Oct 2024. It is the EU’s baseline cybersecurity framework for organisations operating in 18 critical sectors – far broader than the original NIS Directive. Most boards still raise the NIS2 question too late, assuming it only touches obvious critical infrastructure. In practice, food manufacturers, digital service providers, waste management operators, postal services, manufacturers and managed service providers can all fall within scope. Fines for essential entities can reach EUR 10 million or 2% of global annual turnover, whichever is higher (Article 34 NIS2).
NIS2 essential or important entity compliance – at a glance:
- NIS2 covers 18 critical sectors across the EU – the list extends far beyond energy, banking and healthcare into food, manufacturing, waste management, digital providers and ICT service management.
- The size threshold for most sectors: at least 50 employees or more than EUR 10 million annual turnover or balance sheet total brings an entity into scope.
- Essential entities face proactive supervision; important entities face predominantly reactive supervision. Both categories have hard obligations under Articles 20, 21 and 23.
- Article 20 requires management bodies to approve and oversee cybersecurity risk-management measures and to follow training – boards must demonstrate informed cyber oversight, not merely receive IT briefings.
- Fines: essential entities – up to EUR 10 million or 2% of global annual turnover; important entities – up to EUR 7 million or 1.4% (Article 34 NIS2).
- Incident reporting timelines (Article 23): early warning within 24 hours, full notification within 72 hours, final report within one month.
- Patronusec conducts NIS2 applicability assessments and gap analyses for organisations in essential and important sectors – helping establish classification, jurisdiction-specific requirements and implementation priorities before the regulator does.
Table of Contents
How do you determine whether your organisation is an essential or important entity under NIS2?
Whether your organisation is an essential or important entity under NIS2 is one of the first questions to answer before planning compliance work.
Apply three filters in sequence: sector, size and special status. Getting them wrong can mean a year preparing for the wrong regulation.
Step 1 – Sector: Does your organisation operate in a sector listed in Annex I (high criticality) or Annex II (other critical sectors) of Directive (EU) 2022/2555? NIS2 covers 18 critical sectors across the EU – and the list is broader than most boards expect.
Step 2 – Size: The medium-size threshold is the practical starting point for most sectors: at least 50 employees or more than EUR 10 million annual turnover or balance sheet total. The large-entity threshold (at least 250 employees or more than EUR 50 million turnover or balance sheet total) matters for the essential/important classification. The Directive also contains special cases – certain digital service providers, trust service providers, public electronic communications providers, DNS service providers and TLD registries can be in scope regardless of size.
Step 3 – National transposition: A sector check at EU level is only the starting point. National transposition laws can widen or reshape the detail – registration routes, supervisory authority structures and the interaction with sector-specific rules differ materially by country.
Patronusec Insight: The most common error we observe is skipping Step 3. Organisations check the EU Directive scope, declare compliance and stop – failing to account for the fact that the national transposition act may change thresholds, require registration or impose obligations beyond the Directive minimum. As part of our NIS2 applicability assessments, we analyse both Directive requirements and national law in each jurisdiction where the client operates simultaneously.
What are the 18 sectors covered by NIS2 (Annexes I and II)?
| Annex | Sector | What it covers in practice |
|---|---|---|
| Annex I | Energy | Electricity, district heating and cooling, oil, gas, hydrogen |
| Annex I | Transport | Air, rail, water and road transport operators and infrastructure |
| Annex I | Banking | Credit institutions |
| Annex I | Financial market infrastructures | Trading venues, CCPs and similar market infrastructure |
| Annex I | Health | Hospitals, clinics, laboratories, healthcare providers |
| Annex I | Drinking water | Suppliers and distributors |
| Annex I | Waste water | Collection, disposal and treatment entities |
| Annex I | Digital infrastructure | IXPs, DNS, TLD registries, data centres, cloud, trust services, public electronic communications |
| Annex I | ICT service management | Managed service providers and managed security service providers |
| Annex I | Public administration | Central and, in some Member States, regional |
| Annex I | Space | Operators of ground-based infrastructure supporting space services |
| Annex II | Postal and courier services | Operators handling postal or parcel delivery |
| Annex II | Waste management | Collection, transport, recovery and disposal operators |
| Annex II | Manufacture/production/distribution of chemicals | Chemical industry entities |
| Annex II | Food | Production, processing and distribution |
| Annex II | Manufacturing | Medical devices, computer/electronics, machinery, motor vehicles, other transport equipment |
| Annex II | Digital providers | Online marketplaces, search engines, social networking platforms |
| Annex II | Research | Research organisations carrying out critical or strategic work |
What are the 10 security measures required by NIS2 Article 21?
Article 21 is the operational core of NIS2. Boards should treat it as a mandatory agenda, not a menu.
| Article 21 measure | What it means in practice | Complexity |
|---|---|---|
| 1. Risk analysis and information system security policies | Documented cyber risk-management policy and repeatable risk assessment methodology | Moderate |
| 2. Incident handling | Detection, triage, escalation, containment, eradication, recovery and lessons learned | Moderate |
| 3. Business continuity, backup, disaster recovery and crisis management | Cyber scenarios built into BCM plans – not a separate binder | Specialist |
| 4. Supply-chain security | Assessment of the cybersecurity posture of direct suppliers and ICT service providers | Specialist |
| 5. Security in network and information systems acquisition, development and maintenance | Secure development, patching, change control and vulnerability management | Specialist |
| 6. Policies and procedures to assess the effectiveness of cybersecurity risk-management measures | Internal audits, metrics, assurance reviews and tabletop exercises | Moderate |
| 7. Basic cyber hygiene and cybersecurity training | Awareness, secure configuration, patching discipline and trained staff – including management body training under Article 20 | Straightforward |
| 8. Policies and procedures regarding cryptography and, where appropriate, encryption | Encryption policy, key management, approved algorithms | Moderate |
| 9. Human resources security, access control policies and asset management | Joiners/movers/leavers, least privilege, MFA, role reviews and asset inventories | Moderate |
| 10. MFA or continuous authentication, secured voice/video/text communications | Modern identity and communications controls as a baseline, not an optional extra | Straightforward |
The incident reporting deadlines linked to Article 23 are equally specific: early warning within 24 hours of awareness, full incident notification within 72 hours, final report no later than one month after notification. Your incident response plan must support regulatory notification under time pressure, not only technical containment.
Unsure whether your organisation falls under NIS2 – or in which category?
In a free 30-minute session we assess NIS2 applicability: we establish the likely classification, identify the national-law checkpoints that matter for your jurisdictions and show where your evidence and governance are weakest – before the regulator does.
How does ISO 27001 reduce the effort required for NIS2 compliance?
Companies already building or maintaining ISO 27001 are not starting from zero – they are starting from structure. ISO/IEC 27001:2022 provides an information security management system, a risk methodology, internal audit, management review, control ownership and evidence discipline. Those are exactly the foundations NIS2 entities need when regulators ask how risk is assessed, how controls are chosen and what management approved.
The operational overlap is substantial. From our project experience, a company with a live ISO 27001 programme often finds that 40-60% of the organisational effort needed for NIS2 is already in place: risk analysis, supplier management, access control, incident response, BCM structure, asset inventories, audit evidence and management review mechanics.
ISO 27001 does not replace NIS2 – it accelerates it. ISO provides the management system; NIS2 adds sector-specific legal duties, classification, supervisory expectations and incident-reporting obligations.
Learn more about ISO 27001 certification and NIS2 compliance services.
Patronusec Insight: A common trap in combined ISO 27001 + NIS2 projects is assuming all 10 Article 21 measures are automatically covered by ISO 27001. They are not – NIS2 introduces specific obligations around incident reporting, entity classification and supervisory requirements that go beyond the scope of ISO certification. In engagements delivered through our vCISO model, we build an ISO-NIS2 gap-analysis mapping that identifies precisely what is missing – rather than duplicating work the client has already done.
FAQ – Essential or Important Entity
What is the difference between essential and important entities under NIS2?
Essential entities face more proactive supervision and higher maximum fines. Important entities are still fully in scope, but supervision is more often reactive. Both must implement Article 21 measures and meet Article 23 reporting duties.
What are the penalties for NIS2 non-compliance?
Member States must provide for fines of at least up to EUR 10 million or 2% of worldwide annual turnover for essential entities, and up to EUR 7 million or 1.4% for important entities – whichever figure is higher in each case (Article 34 NIS2).
Can a CEO be personally held liable under NIS2?
NIS2 requires Member States to ensure management bodies approve and oversee cyber risk measures and can be held liable under national law. The exact personal-liability mechanism depends on national transposition, but board accountability is explicit in Article 20 – including the possibility of temporary bans from management roles for essential entities.
When did NIS2 come into force and when must organisations comply?
The Directive entered into force on 16 Jan 2023. Member States were required to transpose it by 17 Oct 2024, but national implementation varies – organisations must check both the Directive and the applicable national law in each Member State where they operate.
What security measures does NIS2 Article 21 require?
Article 21 sets out 10 minimum measures: risk analysis and security policies, incident handling, business continuity and backup, supply-chain security, secure network and information systems, control effectiveness testing, cyber hygiene and training, cryptography, human resources security and access control, and MFA or continuous authentication.
How much does a NIS2 applicability assessment and gap analysis cost with Patronusec?
The cost depends on the number of jurisdictions in which the organisation operates, sector complexity and existing documentation (e.g. ISO 27001). After a free scope-assessment call we provide a fixed-price proposal. For organisations that already hold ISO 27001, we offer a dedicated ISO-NIS2 gap-analysis mapping that significantly reduces project time and cost.
How do you start working with Patronusec on NIS2?
The best starting point is a free 30-minute call in which we establish your sector, size and jurisdictions, identify classification risks and discuss the optimal implementation path. Contact us via the contact page or directly through the NIS2 service page.
NIS2 compliance – free scope assessment consultation
Patronusec delivers NIS2 applicability assessments and gap analyses for organisations in essential and important sectors. As an adviser with experience across DORA, ISO 27001 and PCI DSS, we help boards meet Articles 20 and 21 requirements without building from scratch.
In a free 30-minute consultation we will help you:
- Establish whether your organisation is an essential entity, important entity or out of scope
- Identify gaps between your current security posture and Article 21 requirements
- Clarify which national laws apply in your operational jurisdictions
- Plan the NIS2 implementation sequence for minimum effort and maximum regulatory coverage
Book a NIS2 consultation | NIS2 services | ISO 27001 | DORA compliance | vCISO