Directive (EU) 2022/2555 replaced the 2016 NIS directive. Member States had until 17 October 2024 to transpose it, and several missed that date, so the text that applies to an entity is its national transposition rather than the directive itself.
Who is in scope
Entities are classed as essential or important, by sector and by size. The sector list is far wider than under NIS: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, space, postal services, waste management, chemicals, food, manufacturing of certain products, digital providers and research. The size threshold generally brings in medium and large entities, with exceptions that catch smaller ones in critical roles.
What it requires
Risk management measures covering policy, incident handling, business continuity, supply chain security, secure acquisition and development, cryptography, access control and multi-factor authentication. Incident reporting in stages: an early warning within 24 hours of becoming aware of a significant incident, a notification within 72 hours, and a final report within one month. Management bodies have to approve and supervise the measures, can be required to follow training, and can be held liable.
Sanctions
Up to 10 million euro or 2 % of worldwide annual turnover for essential entities, whichever is higher, and up to 7 million euro or 1.4 % for important entities.
Where the work usually sits
Two places, in practice. Proving the supply chain requirement reaches actual suppliers, through contracts and evidence rather than a policy statement. And having a detection and escalation path that can produce a defensible early warning within 24 hours, nights and weekends included.