NIS2 Directive compliance guide

A practical read of Directive (EU) 2022/2555: who is in scope, what Article 21 actually requires, how the 24/72-hour reporting clock works, and how to prove it.

Michael McCarroll 12 min read Updated June 2026

1. Scope and classification

NIS2 applies to essential entities (Annex I: energy, transport, banking, health, drinking water, digital infrastructure, ICT service management, public administration, space) and important entities (Annex II: postal, waste, chemicals, food, manufacturing, digital providers, research) (European Parliament and Council, 2022).

The size-cap rule generally excludes micro and small enterprises, but critical entities (DNS, TLD registries, trust service providers, public administration) are in scope regardless of size (Art. 2(2)).

2. Article 21 baseline measures

  • Risk analysis and information system security policies
  • Incident handling
  • Business continuity and crisis management
  • Supply chain security
  • Security in acquisition, development and maintenance
  • Policies and procedures to assess effectiveness
  • Basic cyber hygiene and training
  • Cryptography and encryption
  • Human resources security, access control and asset management
  • MFA, secured communications and emergency communications systems

Each measure maps to controls in ISO/IEC 27001:2022 Annex A, but NIS2 additionally requires the management body to approve and oversee them (Art. 20).

3. A five-step path to conformity

Step 1

Confirm entity classification

Document sector, size, service dependencies and Member State of main establishment. This determines which national competent authority you register with.
Step 2

Adopt an ISO 27001-aligned ISMS

Certification is not mandatory, but an ISO 27001 ISMS covers 8 of the 10 Article 21 measures out of the box (ENISA, 2024).
Step 3

Train the management body

Article 20(2) requires directors to follow cybersecurity training. Keep an attendance register — regulators have started asking for it.
Step 4

Wire the 24/72-hour incident channel

Pre-agree who calls the CSIRT, who drafts the early warning, and where the timestamped decision log lives. The clock starts at 'becoming aware', not at containment.
Step 5

Prove supply-chain oversight

Article 21(2)(d) requires you to evaluate suppliers' cybersecurity practices. A supplier security questionnaire tied to your risk register is the minimum viable evidence.

Run NIS2 evidence next to ISO 27001

NIS2 is not a management system standard — it's a directive that expects a management system to exist. Running ISO 27001 in the same workspace collapses the evidence burden.

ISO-STANDARD.app ships a ready-to-adopt ISO 27001 workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.

Free downloads for this topic

Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.

Frequently asked questions

Who is in scope of NIS2?
Essential and important entities in 18 sectors listed in Annexes I and II, generally with 50+ employees or €10m+ turnover — plus certain critical entities regardless of size (European Parliament and Council, 2022, Art. 2).
What are the reporting timelines?
An early warning within 24 hours of becoming aware of a significant incident, a full notification within 72 hours, and a final report within one month (European Parliament and Council, 2022, Art. 23).
What are the penalties?
Up to €10m or 2% of global turnover for essential entities, and €7m or 1.4% for important entities (European Parliament and Council, 2022, Art. 34).
Does ISO 27001 satisfy NIS2?
ISO 27001 covers most of the Article 21 measures, but NIS2 also imposes supply-chain, incident-reporting and governance duties that require additional evidence (ENISA, 2024).

References

  • ENISA (2024) NIS2 Technical Implementation Guidance. Heraklion: European Union Agency for Cybersecurity.
  • European Parliament and Council (2022) Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2). Official Journal of the European Union, L 333/80.
  • ISO (2022) ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements. Geneva: ISO.
Related guides
Trust & security
ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation
← All guidesHome →