All frameworks
    Regulatory auditEuropean Union, enforced by each member state's national competent authority

    NIS2

    NIS2 Directive: Directive (EU) 2022/2555

    NIS2 is an EU cybersecurity law requiring essential and important entities to manage security risks, report incidents, and hold management accountable.

    Last verified Jul 17, 2026

    Q&A

    What is NIS2?

    NIS2 is an EU cybersecurity law requiring essential and important entities to manage security risks, report incidents, and hold management accountable.

    Who needs NIS2?

    Medium and large organizations operating in the EU within covered sectors, including energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space, postal services, waste management, chemicals, food, manufacturing of critical products, and digital providers. Smaller companies can also be pulled in through supply-chain requirements imposed by covered customers.

    How long does NIS2 take?

    NIS2 compliance is continuous rather than a one-time audit. Organizations typically run a gap assessment against the national transposing law, implement the required risk-management measures over several months, and then maintain them under ongoing supervision. Essential entities should be prepared for regulator-initiated audits at any time.

    How much does a NIS2 audit cost?

    There is no fixed audit fee. Cost is driven by a gap assessment plus the implementation effort to meet the national transposing law; larger essential entities in regulated sectors should budget accordingly.

    What does a NIS2 audit cover?

    Rather than a single pass/fail certificate, NIS2 involves conformity assessment against the applicable national law: reviewing risk-management measures, incident-reporting processes, governance, and supply-chain controls. Assessments are often benchmarked against recognized standards such as ISO 27001, which regulators and auditors frequently use as a reference.

    What it is

    NIS2 is a European Union directive that raises the baseline for cybersecurity across critical and important sectors. It replaces the original 2016 NIS Directive and significantly widens both the range of organizations covered and the obligations placed on them. Because it is a directive, it takes legal force through each member state's own transposing legislation, so the precise rules, supervisory approach, and penalties depend on the country you operate in.

    NIS2 sorts covered organizations into "essential" and "important" entities. Both must implement appropriate technical and organizational risk-management measures, but essential entities face more proactive supervision, including the possibility of audits initiated by the regulator, while important entities are generally supervised reactively after an incident or complaint.

    Two obligations sit at the core. First, risk-management measures under Article 21, covering areas such as incident handling, business continuity, supply-chain security, and encryption. Second, incident reporting under Article 23, with an early warning due within 24 hours of becoming aware of a significant incident. NIS2 also makes senior management explicitly accountable for oversight of these measures.

    Who needs it

    Medium and large organizations operating in the EU within covered sectors, including energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space, postal services, waste management, chemicals, food, manufacturing of critical products, and digital providers. Smaller companies can also be pulled in through supply-chain requirements imposed by covered customers.

    What's audited

    Rather than a single pass/fail certificate, NIS2 involves conformity assessment against the applicable national law: reviewing risk-management measures, incident-reporting processes, governance, and supply-chain controls. Assessments are often benchmarked against recognized standards such as ISO 27001, which regulators and auditors frequently use as a reference.

    Typical timeline

    NIS2 compliance is continuous rather than a one-time audit. Organizations typically run a gap assessment against the national transposing law, implement the required risk-management measures over several months, and then maintain them under ongoing supervision. Essential entities should be prepared for regulator-initiated audits at any time.

    Typical cost

    There is no fixed audit fee. Cost is driven by a gap assessment plus the implementation effort to meet the national transposing law; larger essential entities in regulated sectors should budget accordingly.

    What to verify on an auditor

    There is no single NIS2 accreditation. Choose an assessor with demonstrable experience in the specific member state's transposing legislation, sector knowledge relevant to your entity type, and a strong information-security background. ISO 27001 lead-auditor credentials are a common and useful signal. Confirm which national jurisdiction's rules they are qualified to assess against.

    Service pathways

    Not every service under this framework is fully available today. Hover a pathway for context.

    • EU-wide NIS2 certification
      No EU-wide NIS2 certification exists. A January 2026 European Commission proposal floats certification-based compliance pathways, but as of today that's a proposal, not law.
      Not yet operational
    • ISO 27001 as evidentiary base
      Available
    • NIS2 gap assessment against Article 21
      Available

    Find NIS2 auditors by region

    Browse independent NIS2 auditors serving each region.