NIS2
NIS2 Directive: Directive (EU) 2022/2555
NIS2 is an EU cybersecurity law requiring essential and important entities to manage security risks, report incidents, and hold management accountable.
Last verified Jul 17, 2026
Q&A
What is NIS2?
NIS2 is an EU cybersecurity law requiring essential and important entities to manage security risks, report incidents, and hold management accountable.
Who needs NIS2?
Medium and large organizations operating in the EU within covered sectors, including energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space, postal services, waste management, chemicals, food, manufacturing of critical products, and digital providers. Smaller companies can also be pulled in through supply-chain requirements imposed by covered customers.
How long does NIS2 take?
NIS2 compliance is continuous rather than a one-time audit. Organizations typically run a gap assessment against the national transposing law, implement the required risk-management measures over several months, and then maintain them under ongoing supervision. Essential entities should be prepared for regulator-initiated audits at any time.
How much does a NIS2 audit cost?
There is no fixed audit fee. Cost is driven by a gap assessment plus the implementation effort to meet the national transposing law; larger essential entities in regulated sectors should budget accordingly.
What does a NIS2 audit cover?
Rather than a single pass/fail certificate, NIS2 involves conformity assessment against the applicable national law: reviewing risk-management measures, incident-reporting processes, governance, and supply-chain controls. Assessments are often benchmarked against recognized standards such as ISO 27001, which regulators and auditors frequently use as a reference.
What it is
NIS2 is a European Union directive that raises the baseline for cybersecurity across critical and important sectors. It replaces the original 2016 NIS Directive and significantly widens both the range of organizations covered and the obligations placed on them. Because it is a directive, it takes legal force through each member state's own transposing legislation, so the precise rules, supervisory approach, and penalties depend on the country you operate in.
NIS2 sorts covered organizations into "essential" and "important" entities. Both must implement appropriate technical and organizational risk-management measures, but essential entities face more proactive supervision, including the possibility of audits initiated by the regulator, while important entities are generally supervised reactively after an incident or complaint.
Two obligations sit at the core. First, risk-management measures under Article 21, covering areas such as incident handling, business continuity, supply-chain security, and encryption. Second, incident reporting under Article 23, with an early warning due within 24 hours of becoming aware of a significant incident. NIS2 also makes senior management explicitly accountable for oversight of these measures.
Medium and large organizations operating in the EU within covered sectors, including energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space, postal services, waste management, chemicals, food, manufacturing of critical products, and digital providers. Smaller companies can also be pulled in through supply-chain requirements imposed by covered customers.
Rather than a single pass/fail certificate, NIS2 involves conformity assessment against the applicable national law: reviewing risk-management measures, incident-reporting processes, governance, and supply-chain controls. Assessments are often benchmarked against recognized standards such as ISO 27001, which regulators and auditors frequently use as a reference.
NIS2 compliance is continuous rather than a one-time audit. Organizations typically run a gap assessment against the national transposing law, implement the required risk-management measures over several months, and then maintain them under ongoing supervision. Essential entities should be prepared for regulator-initiated audits at any time.
There is no fixed audit fee. Cost is driven by a gap assessment plus the implementation effort to meet the national transposing law; larger essential entities in regulated sectors should budget accordingly.
There is no single NIS2 accreditation. Choose an assessor with demonstrable experience in the specific member state's transposing legislation, sector knowledge relevant to your entity type, and a strong information-security background. ISO 27001 lead-auditor credentials are a common and useful signal. Confirm which national jurisdiction's rules they are qualified to assess against.
Service pathways
Not every service under this framework is fully available today. Hover a pathway for context.
- Not yet operationalEU-wide NIS2 certificationNo EU-wide NIS2 certification exists. A January 2026 European Commission proposal floats certification-based compliance pathways, but as of today that's a proposal, not law.
- AvailableISO 27001 as evidentiary base
- AvailableNIS2 gap assessment against Article 21
Find NIS2 auditors by region
Browse independent NIS2 auditors serving each region.