Directive (EU) 2022/2555CIR (EU) 2024/2690 · Annex
Article 21(2) of the directive names ten risk-management measures in prose. Commission Implementing Regulation (EU) 2024/2690 turns them into an Annex of thirteen numbered points with sub-requirements — the only EU-wide enumeration specific enough to measure against, and the one an assessor cites.
CIR (EU) 2024/2690 applies directly to DNS providers, TLD name registries, cloud, data centre and content delivery providers, managed service and managed security service providers, online marketplaces, search engines, social networking platforms and trust service providers. Other essential and important entities meet Article 21 through the national law that transposes it. In either case the numbered controls are the technical reading of Article 21, which is why they are used here.
NIS2 replaced Directive (EU) 2016/1148, the first EU-wide cybersecurity law, which covered six sectors. It entered into force in January 2023. Member States had until 17 October 2024 to transpose it into national law, and NIS1 was repealed from 18 October 2024. So the obligation is not coming — it arrived, and it now reaches eighteen sectors instead of six.
Annex I names the sectors of high criticality and Annex II the other critical sectors. Which annex you fall under, together with your size, determines whether you are an essential or an important entity — which changes how you are supervised and how large a fine can be, not which measures apply.
Annex ISectors of high criticality
Annex IIOther critical sectors
Against each one, what a monitoring system can honestly say. Six are documents and decisions rather than events, and are reported as open with the evidence an assessor will request.
| Point | Requirement | Evidenced by | |
|---|---|---|---|
| 1 | Policy on the security of network and information systems | Documents and decisions | |
| 2 | Risk management policy | Documents and decisions | |
| 3 | Incident handling | Measurement | |
| 4 | Business continuity and crisis management | Partly measurable | |
| 5 | Supply chain security | Documents and decisions | |
| 6 | Security in network and information systems acquisition, development and maintenance | Measurement | |
| 7 | Policies and procedures to assess the effectiveness of cybersecurity risk-management measures | Documents and decisions | |
| 8 | Basic cyber hygiene practices and security training | Partly measurable | |
| 9 | Cryptography | Partly measurable | |
| 10 | Human resources security | Documents and decisions | |
| 11 | Access control | Measurement | |
| 12 | Asset management | Partly measurable | |
| 13 | Environmental and physical security | Documents and decisions |
Approximately one third of the numbered controls are evidenced by measurement. A coverage claim that exceeds what a monitoring system can observe does not survive an assessment, so the remainder are reported as open rather than quietly counted as met.
ReportingArticle 23
A significant incident must be reported to the national CSIRT or competent authority in three stages. The deadlines run from the moment the entity becomes aware of the incident.
Quoted from Directive (EU) 2022/2555. This is the binding wording, not a summary of ours. Article 23(4)
Quanovio records first detection with its timestamp, which is what an assessor compares the filing against. Filing itself is a process you operate; no monitoring system can do it for you, and one that claims to is describing an alert.
Two things decide it: whether what you do is one of the eighteen sectors, and whether you are above the size ceilings. A handful of entities are in scope whatever their size. The wording below is the Directive's own; the assistant on this page will take you through it against your own organisation.
1. This Directive applies to public or private entities of a type referred to in Annex I or II which qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC, or exceed the ceilings for medium-sized enterprises provided for in paragraph 1 of that Article, and which provide their services or carry out their activities within the Union. Article 3(4) of the Annex to that Recommendation shall not apply for the purposes of this Directive.
1. The category of micro, small and medium-sized enterprises (SMEs) is made up of enterprises which employ fewer than 250 persons and which have an annual turnover not exceeding EUR 50 million, and/or an annual balance sheet total not exceeding EUR 43 million. 2. Within the SME category, a small enterprise is defined as an enterprise which employs fewer than 50 persons and whose annual turnover and/or annual balance sheet total does not exceed EUR 10 million.
Quoted from Recommendation 2003/361/EC, the act the Directive defers to for its ceilings. Recommendation 2003/361/EC
1. For the purposes of this Directive, the following entities shall be considered to be essential entities: (a) entities of a type referred to in Annex I which exceed the ceilings for medium-sized enterprises provided for in Article 2(1) of the Annex to Recommendation 2003/361/EC; (b) qualified trust service providers and top-level domain name registries as well as DNS service providers, regardless of their size; (c) providers of public electronic communications networks or of publicly available electronic communications services which qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC; (d) public administration entities referred to in Article 2(2), point (f)(i); (e) any other entities of a type referred to in Annex I or II that are identified by a Member State as essential entities pursuant to Article 2(2), points (b) to (e); (f) entities identified as critical entities under Directive (EU) 2022/2557, referred to in Article 2(3) of this Directive; (g) if the Member State so provides, entities which that Member State identified before 16 January 2023 as operators of essential services in accordance with Directive (EU) 2016/1148 or national law.
2. For the purposes of this Directive, entities of a type referred to in Annex I or II which do not qualify as essential entities pursuant to paragraph 1 of this Article shall be considered to be important entities. This includes entities identified by Member States as important entities pursuant to Article 2(2), points (b) to (e).
2. Regardless of their size, this Directive also applies to entities of a type referred to in Annex I or II, where: (a) services are provided by: (i) providers of public electronic communications networks or of publicly available electronic communications services; (ii) trust service providers; (iii) top-level domain name registries and domain name system service providers; (b) the entity is the sole provider in a Member State of a service which is essential for the maintenance of critical societal or economic activities; (c) disruption of the service provided by the entity could have a significant impact on public safety, public security or public health; (d) disruption of the service provided by the entity could induce a significant systemic risk, in particular for sectors where such disruption could have a cross-border impact; (e) the entity is critical because of its specific importance at national or regional level for the particular sector or type of service, or for other interdependent sectors in the Member State; (f) the entity is a public administration entity: (i) of central government as defined by a Member State in accordance with national law; or (ii) at regional level as defined by a Member State in accordance with national law that, following a risk-based assessment, provides services the disruption of which could have a significant impact on critical societal or economic activities.
Quoted from Directive (EU) 2022/2555. This is the binding wording, not a summary of ours. Article 2(1) — scope
4. Member States shall ensure that where they infringe Article 21 or 23, essential entities are subject, in accordance with paragraphs 2 and 3 of this Article, to administrative fines of a maximum of at least EUR 10 000 000 or of a maximum of at least 2 % of the total worldwide annual turnover in the preceding financial year of the undertaking to which the essential entity belongs, whichever is higher.
5. Member States shall ensure that where they infringe Article 21 or 23, important entities are subject, in accordance with paragraphs 2 and 3 of this Article, to administrative fines of a maximum of at least EUR 7 000 000 or of a maximum of at least 1,4 % of the total worldwide annual turnover in the preceding financial year of the undertaking to which the important entity belongs, whichever is higher.
Quoted from Directive (EU) 2022/2555. This is the binding wording, not a summary of ours. Article 34(4) and (5)
1. Member States shall ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infringements by the entities of that Article.
NIS2 is not only a set of obligations for entities. It also creates the structures those obligations report into, which is worth knowing before an incident rather than during one.
The national computer security incident response teams, networked across the Union to exchange information on cyber threats and respond to incidents. This is who your Article 23 notification goes to.
The European cyber crisis liaison organisation network, for coordinated management of large-scale incidents and crises, and for regular information exchange between Member States and EU institutions.
A platform for strategic cooperation between Member States, the Commission and ENISA. It publishes non-binding guidelines and recommendations that shape how the Directive is implemented in practice.
Each Member State must adopt a national cybersecurity strategy covering supply chain security, vulnerability management and cybersecurity education, and must maintain a list of operators of essential services.
The Directive introduces accountability of top management for failure to comply with the cybersecurity risk-management measures. That is the change that moved this from an IT budget line to a board agenda item — approval and oversight are named duties, and Member States may hold management bodies personally liable.
On 20 January 2026 the Commission proposed targeted amendments to NIS2 as part of a new cybersecurity package, intended to increase legal clarity and simplify compliance. The Commission's own estimate is that they will ease compliance for 28,700 companies, of which 6,200 are micro and small enterprises. The numbered requirements this product measures against are not withdrawn by that proposal.
ReferencesEUR-Lex · ENISA
Every figure, deadline and requirement title on this site is taken from the texts below. Where this site quotes, it quotes the official language version you are reading it in.
Describe your environment and you will receive a point-by-point statement, including the ones no system can measure for you.