Directive (EU) 2022/2555 · Last verified

NIS2 Directive

Directive (EU) 2022/2555 (NIS2): Article 2 sets out which entities are in scope; Member States had to transpose it by 17 October 2024. It applies to entities listed in Annexes I and II that meet size thresholds, or regardless of size in specific cases. Being a directive, it binds Member States, who transpose it into national law.

Citation
Directive (EU) 2022/2555
Jurisdiction
EU
Regulator
Competent authorities designated by each Member State; enforcement and administrative fines are set in national transposing law (Articles 32-34)
Last verified

What it is

It applies to entities listed in Annexes I and II that meet size thresholds, or regardless of size in specific cases. Being a directive, it binds Member States, who transpose it into national law.

Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive) ↗

Key dates

  • Adopted: — "Done at Strasbourg, 14 December 2022." (OJ L 333/142)
  • Entered into force: — Article 38(2): "…shall be conferred on the Commission for a period of five years from 16 January 2023." (OJ L 333/141) — the one place the Directive's text gives this date directly.
  • Transposition deadline: — Article 41(1): "By 17 October 2024, Member States shall adopt and publish the measures necessary to comply with this Directive." (OJ L 333/142)
  • Measures apply from: — Article 41(1): "They shall apply those measures from 18 October 2024."
  • Repeal of Directive (EU) 2016/1148: — Article 44: "Directive (EU) 2016/1148 is repealed with effect from 18 October 2024."

Scope

Article 2

1. This Directive applies to public or private entities of a type referred to in Annex I or II which qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC, or exceed the ceilings for medium-sized enterprises provided for in paragraph 1 of that Article, and which provide their services or carry out their activities within the Union.

Article 3(4) of the Annex to that Recommendation shall not apply for the purposes of this Directive.

2. Regardless of their size, this Directive also applies to entities of a type referred to in Annex I or II, where:

(a) services are provided by: (i) providers of public electronic communications networks or of publicly available electronic communications services; (ii) trust service providers; (iii) top-level domain name registries and domain name system service providers;

(b) the entity is the sole provider in a Member State of a service which is essential for the maintenance of critical societal or economic activities;

(c) disruption of the service provided by the entity could have a significant impact on public safety, public security or public health;

(d) disruption of the service provided by the entity could induce a significant systemic risk, in particular for sectors where such disruption could have a cross-border impact;

(e) the entity is critical because of its specific importance at national or regional level for the particular sector or type of service, or for other interdependent sectors in the Member State;

(f) the entity is a public administration entity: (i) of central government as defined by a Member State in accordance with national law; or (ii) at regional level as defined by a Member State in accordance with national law that, following a risk-based assessment, provides services the disruption of which could have a significant impact on critical societal or economic activities.

3. Regardless of their size, this Directive applies to entities identified as critical entities under Directive (EU) 2022/2557.

4. Regardless of their size, this Directive applies to entities providing domain name registration services.

5. Member States may provide for this Directive to apply to: (a) public administration entities at local level; (b) education institutions, in particular where they carry out critical research activities.

6. This Directive is without prejudice to the Member States' responsibility for safeguarding national security and their power to safeguard other essential State functions, including ensuring the territorial integrity of the State and maintaining law and order.

7. This Directive does not apply to public administration entities that carry out their activities in the areas of national security, public security, defence or law enforcement, including the prevention, investigation, detection and prosecution of criminal offences.

[Article 2 continues at paragraphs 8-14 — read the full article in the Official Journal.]

EUR-Lex — Directive (EU) 2022/2555 (Official Journal PDF) ↗

Penalties

Article 34(4); for important entities Article 34(5) sets EUR 7 000 000 or 1,4%

Member States shall ensure that where they infringe Article 21 or 23, essential entities are subject, in accordance with paragraphs 2 and 3 of this Article, to administrative fines of a maximum of at least EUR 10 000 000 or of a maximum of at least 2 % of the total worldwide annual turnover in the preceding financial year of the undertaking to which the essential entity belongs, whichever is higher.

Directive, not a directly-applicable regulation

Article 46

This Directive is addressed to the Member States.

Minimum harmonisation

Article 5

This Directive shall not preclude Member States from adopting or maintaining provisions ensuring a higher level of cybersecurity, provided that such provisions are consistent with Member States' obligations laid down in Union law.

Sources

Last verified:

This page is for information only and is not legal advice. It reproduces the regulation's own wording; always confirm against the primary source linked above and consult qualified counsel for how it applies to your organisation.

Cite this page

Attributing this record helps other researchers verify it independently.

"NIS2 Directive." Certifidex, FutureTechnologies. Last verified 29 August 2026. https://certifidex.com/regulations/nis2

All regulations →