Quanovio

Directive (EU) 2022/2555CIR (EU) 2024/2690 · Annex

What NIS2 requires, and which parts a system can evidence.

Article 21(2) of the directive names ten risk-management measures in prose. Commission Implementing Regulation (EU) 2024/2690 turns them into an Annex of thirteen numbered points with sub-requirements — the only EU-wide enumeration specific enough to measure against, and the one an assessor cites.

Who it binds

CIR (EU) 2024/2690 applies directly to DNS providers, TLD name registries, cloud, data centre and content delivery providers, managed service and managed security service providers, online marketplaces, search engines, social networking platforms and trust service providers. Other essential and important entities meet Article 21 through the national law that transposes it. In either case the numbered controls are the technical reading of Article 21, which is why they are used here.

What it replaced, and when it applied

NIS2 replaced Directive (EU) 2016/1148, the first EU-wide cybersecurity law, which covered six sectors. It entered into force in January 2023. Member States had until 17 October 2024 to transpose it into national law, and NIS1 was repealed from 18 October 2024. So the obligation is not coming — it arrived, and it now reaches eighteen sectors instead of six.

The eighteen sectors

Annex I names the sectors of high criticality and Annex II the other critical sectors. Which annex you fall under, together with your size, determines whether you are an essential or an important entity — which changes how you are supervised and how large a fine can be, not which measures apply.

Annex ISectors of high criticality

  • Energy
  • Transport
  • Banking
  • Financial market infrastructures
  • Health
  • Drinking water
  • Waste water
  • Digital infrastructure
  • ICT service management (business-to-business)
  • Public administration
  • Space

Annex IIOther critical sectors

  • Postal and courier services
  • Waste management
  • Manufacture, production and distribution of chemicals
  • Production, processing and distribution of food
  • Manufacturing
  • Digital providers
  • Research

The thirteen points

Against each one, what a monitoring system can honestly say. Six are documents and decisions rather than events, and are reported as open with the evidence an assessor will request.

PointRequirementEvidenced by
1Policy on the security of network and information systemsDocuments and decisions
2Risk management policyDocuments and decisions
3Incident handlingMeasurement
4Business continuity and crisis managementPartly measurable
5Supply chain securityDocuments and decisions
6Security in network and information systems acquisition, development and maintenanceMeasurement
7Policies and procedures to assess the effectiveness of cybersecurity risk-management measuresDocuments and decisions
8Basic cyber hygiene practices and security trainingPartly measurable
9CryptographyPartly measurable
10Human resources securityDocuments and decisions
11Access controlMeasurement
12Asset managementPartly measurable
13Environmental and physical securityDocuments and decisions

Approximately one third of the numbered controls are evidenced by measurement. A coverage claim that exceeds what a monitoring system can observe does not survive an assessment, so the remainder are reported as open rather than quietly counted as met.

ReportingArticle 23

The clock starts at awareness, not at detection.

A significant incident must be reported to the national CSIRT or competent authority in three stages. The deadlines run from the moment the entity becomes aware of the incident.

024 h72 h1 month
24 hours without undue delay and in any event within 24 hours of becoming aware of the significant incident, an early warning, which, where applicable, shall indicate whether the significant incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact;
72 hours without undue delay and in any event within 72 hours of becoming aware of the significant incident, an incident notification, which, where applicable, shall update the information referred to in point (a) and indicate an initial assessment of the significant incident, including its severity and impact, as well as, where available, the indicators of compromise;
1 month a final report not later than one month after the submission of the incident notification under point (b), including the following:

Quoted from Directive (EU) 2022/2555. This is the binding wording, not a summary of ours. Article 23(4)

Quanovio records first detection with its timestamp, which is what an assessor compares the filing against. Filing itself is a process you operate; no monitoring system can do it for you, and one that claims to is describing an alert.

Am I in scope?

Two things decide it: whether what you do is one of the eighteen sectors, and whether you are above the size ceilings. A handful of entities are in scope whatever their size. The wording below is the Directive's own; the assistant on this page will take you through it against your own organisation.

Article 2(1) — scope
1. This Directive applies to public or private entities of a type referred to in Annex I or II which qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC, or exceed the ceilings for medium-sized enterprises provided for in paragraph 1 of that Article, and which provide their services or carry out their activities within the Union. Article 3(4) of the Annex to that Recommendation shall not apply for the purposes of this Directive.
Recommendation 2003/361/EC, Article 2 of the Annex — the ceilings
1. The category of micro, small and medium-sized enterprises (SMEs) is made up of enterprises which employ fewer than 250 persons and which have an annual turnover not exceeding EUR 50 million, and/or an annual balance sheet total not exceeding EUR 43 million. 2. Within the SME category, a small enterprise is defined as an enterprise which employs fewer than 50 persons and whose annual turnover and/or annual balance sheet total does not exceed EUR 10 million.

Quoted from Recommendation 2003/361/EC, the act the Directive defers to for its ceilings. Recommendation 2003/361/EC

Article 3(1) — essential entities
1. For the purposes of this Directive, the following entities shall be considered to be essential entities: (a) entities of a type referred to in Annex I which exceed the ceilings for medium-sized enterprises provided for in Article 2(1) of the Annex to Recommendation 2003/361/EC; (b) qualified trust service providers and top-level domain name registries as well as DNS service providers, regardless of their size; (c) providers of public electronic communications networks or of publicly available electronic communications services which qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC; (d) public administration entities referred to in Article 2(2), point (f)(i); (e) any other entities of a type referred to in Annex I or II that are identified by a Member State as essential entities pursuant to Article 2(2), points (b) to (e); (f) entities identified as critical entities under Directive (EU) 2022/2557, referred to in Article 2(3) of this Directive; (g) if the Member State so provides, entities which that Member State identified before 16 January 2023 as operators of essential services in accordance with Directive (EU) 2016/1148 or national law.
Article 3(2) — important entities
2. For the purposes of this Directive, entities of a type referred to in Annex I or II which do not qualify as essential entities pursuant to paragraph 1 of this Article shall be considered to be important entities. This includes entities identified by Member States as important entities pursuant to Article 2(2), points (b) to (e).
Article 2(2) — regardless of size
2. Regardless of their size, this Directive also applies to entities of a type referred to in Annex I or II, where: (a) services are provided by: (i) providers of public electronic communications networks or of publicly available electronic communications services; (ii) trust service providers; (iii) top-level domain name registries and domain name system service providers; (b) the entity is the sole provider in a Member State of a service which is essential for the maintenance of critical societal or economic activities; (c) disruption of the service provided by the entity could have a significant impact on public safety, public security or public health; (d) disruption of the service provided by the entity could induce a significant systemic risk, in particular for sectors where such disruption could have a cross-border impact; (e) the entity is critical because of its specific importance at national or regional level for the particular sector or type of service, or for other interdependent sectors in the Member State; (f) the entity is a public administration entity: (i) of central government as defined by a Member State in accordance with national law; or (ii) at regional level as defined by a Member State in accordance with national law that, following a risk-based assessment, provides services the disruption of which could have a significant impact on critical societal or economic activities.

Quoted from Directive (EU) 2022/2555. This is the binding wording, not a summary of ours. Article 2(1) — scope

Penalties

Essential entities €10,000,000 or 2%
4. Member States shall ensure that where they infringe Article 21 or 23, essential entities are subject, in accordance with paragraphs 2 and 3 of this Article, to administrative fines of a maximum of at least EUR 10 000 000 or of a maximum of at least 2 % of the total worldwide annual turnover in the preceding financial year of the undertaking to which the essential entity belongs, whichever is higher.
Important entities €7,000,000 or 1.4%
5. Member States shall ensure that where they infringe Article 21 or 23, important entities are subject, in accordance with paragraphs 2 and 3 of this Article, to administrative fines of a maximum of at least EUR 7 000 000 or of a maximum of at least 1,4 % of the total worldwide annual turnover in the preceding financial year of the undertaking to which the important entity belongs, whichever is higher.

Quoted from Directive (EU) 2022/2555. This is the binding wording, not a summary of ours. Article 34(4) and (5)

Article 20(1)
1. Member States shall ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infringements by the entities of that Article.

What the Directive builds around you

NIS2 is not only a set of obligations for entities. It also creates the structures those obligations report into, which is worth knowing before an incident rather than during one.

CSIRTs network

The national computer security incident response teams, networked across the Union to exchange information on cyber threats and respond to incidents. This is who your Article 23 notification goes to.

EU-CyCLONe

The European cyber crisis liaison organisation network, for coordinated management of large-scale incidents and crises, and for regular information exchange between Member States and EU institutions.

NIS Cooperation Group

A platform for strategic cooperation between Member States, the Commission and ENISA. It publishes non-binding guidelines and recommendations that shape how the Directive is implemented in practice.

National strategies

Each Member State must adopt a national cybersecurity strategy covering supply chain security, vulnerability management and cybersecurity education, and must maintain a list of operators of essential services.

It reached the boardroom

The Directive introduces accountability of top management for failure to comply with the cybersecurity risk-management measures. That is the change that moved this from an IT budget line to a board agenda item — approval and oversight are named duties, and Member States may hold management bodies personally liable.

What is changing

On 20 January 2026 the Commission proposed targeted amendments to NIS2 as part of a new cybersecurity package, intended to increase legal clarity and simplify compliance. The Commission's own estimate is that they will ease compliance for 28,700 companies, of which 6,200 are micro and small enterprises. The numbered requirements this product measures against are not withdrawn by that proposal.

ReferencesEUR-Lex · ENISA

Sources

Every figure, deadline and requirement title on this site is taken from the texts below. Where this site quotes, it quotes the official language version you are reading it in.

Which points can you currently evidence?

Describe your environment and you will receive a point-by-point statement, including the ones no system can measure for you.

See your coverage