NIS1 to NIS2 directive comparison — article-by-article cybersecurity compliance changes

Your NIS1 Compliance Is No Longer Enough: Article-by-Article Changes in NIS2 and What to Fix First

On 18 October 2024, Directive 2016/1148 — the original NIS Directive — was repealed. Not updated, not extended: repealed, and replaced wholesale by NIS2 (Directive (EU) 2022/2555). If your organisation built its cybersecurity compliance programme around NIS1 obligations, that legal framework no longer exists.

Most NIS1-vs-NIS2 guides treat this as a thematic upgrade: more sectors, stricter rules, bigger fines. That framing obscures the specific legal changes. A compliance officer cannot answer their auditor’s actual question — “Which Article 21(2) controls did your existing programme not address?” — from a five-point overview.

This article maps each major NIS1 provision to its NIS2 equivalent: scope (Articles 5 and 2–3), security measures (Articles 14 and 21(2)), incident reporting (Articles 14(3) and 23), management accountability (Article 20 — new in NIS2), and the penalty regime (Article 21 of NIS1 and Article 34 of NIS2). Whether you were previously an operator of essential services or operated outside NIS1 scope entirely, use this to identify exactly where your programme needs to change.

What NIS1 Required — The Baseline

NIS1 divided entities into two categories: operators of essential services (OES) — companies providing services essential to societal or economic activity in one of seven sectors (energy, transport, banking, financial market infrastructure, health, drinking water supply, and digital infrastructure) — and digital service providers (DSPs), covering online marketplaces, search engines, and cloud computing. Both categories faced the same core obligation under Articles 14 and 16 respectively: take “appropriate and proportionate technical and organisational measures to manage the risks posed to the security of network and information systems.”

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

No list of required controls. No specified technical baseline. “Appropriate and proportionate” left interpretation almost entirely to entities and their national regulators.

Incident notification under Article 14(3) followed the same pattern: notify “without undue delay” of incidents with a “significant impact on the continuity” of essential services. No timeline. No multi-stage structure. What counted as “significant” was assessed inconsistently across member states.

Penalties under Article 21 of NIS1 were left entirely to member states: the directive required only that they be “effective, proportionate and dissuasive” — with no EU-wide minimum or maximum. The result was a penalty landscape ranging from a few thousand euros in some jurisdictions to several million in others.

NIS1 was also deliberately narrow in scope. Member states individually identified which entities qualified as OES, producing fragmented national lists. Estimates put the number of actively obligated entities at roughly 10,000 to 15,000 across the EU.

Article-by-Article: What Changed from NIS1 to NIS2

The table below maps each major NIS1 provision to its NIS2 equivalent. All article references are to their respective directives: Directive 2016/1148 (NIS1) and Directive (EU) 2022/2555 (NIS2).

Dimension NIS1 (Directive 2016/1148) NIS2 (Directive 2022/2555) Direction of Change
Who is covered Art. 5: OES identified by each member state in 7 sectors; DSPs separately (Art. 16) Arts. 2–3: Essential + Important entities across 18 sectors; size- and sector-based thresholds ~10,000–15,000 → ~160,000 entities EU-wide
Security measures Art. 14(1): “appropriate and proportionate” — no prescribed control list Art. 21(2): 10 mandatory control domains (a)–(j); all-hazards approach From principle to prescription
Supply chain security Not addressed Art. 21(2)(d): mandatory direct supplier security management New obligation
MFA and cryptography Not specified Art. 21(2)(h): cryptography/encryption policy; Art. 21(2)(j): MFA where appropriate New technical minimum
Incident notification timeline Art. 14(3): “without undue delay” — no specific timeframe Art. 23: 24h early warning → 72h notification → 1-month final report Precision replaces ambiguity
Management accountability Not addressed — organisational level only Art. 20: management bodies must approve Art. 21 measures; personal liability enabled New personal accountability layer
Penalty ceiling Art. 21 (NIS1): member state discretion; no EU floor or ceiling Art. 34: Essential: €10M or 2% global turnover; Important: €7M or 1.4% Harmonised and materially higher
Supervision model Reactive — primarily incident-triggered Art. 32: Essential entities subject to proactive ex-ante supervision From reactive to proactive
DSP treatment Art. 16: separate, lighter obligation set No separate DSP category; subsumed into Essential/Important framework Tighter overall for digital service providers

From Operators of Essential Services to Essential and Important Entities

The scope change is the most consequential shift in NIS2, because it determines who is subject to all other obligations. See the full breakdown of NIS2 scope and applicability criteria and the Essential vs Important entity distinction.

Under NIS1, each member state individually identified operators of essential services using Article 5’s three-part test: the entity provides a service essential to societal or economic activities; that service depends on network and information systems; and a significant incident would have a significant disruptive effect. The process was biennial, produced fragmented national lists, and resulted in substantial variation between member states even within the same sector. Estimates place the total number of NIS1-obligated entities at roughly 10,000 to 15,000 EU-wide.

NIS2 replaces this with a rule-based approach. Under Articles 2 and 3, an entity is in scope if it is in an Annex I or Annex II sector and meets the size threshold — in most cases, medium-sized enterprises and above (50+ employees or €10M+ in annual turnover). Certain categories are included regardless of size: qualified trust service providers, DNS service providers, TLD name registries, and public electronic communications network providers. The result: approximately 160,000 entities now fall within NIS2 scope across the EU.

Within that scope, the Essential/Important distinction works as follows:

  • Essential entity: A large enterprise (250+ employees or €50M+ turnover) in an Annex I sector; or a specifically designated category regardless of size (DNS, TLD, qualified trust services, critical infrastructure operators); or a former NIS1 operator of essential services. Article 3(1) of NIS2 explicitly preserves OES status — legacy classification maps automatically to Essential entity.
  • Important entity: Any Annex I or Annex II entity that does not qualify as essential — typically medium-sized enterprises (50–249 employees, €10–50M turnover) in regulated sectors.

The practical consequence: organisations entirely outside NIS1 scope — medium-sized manufacturers, food producers, postal operators, waste management companies — are now inside NIS2 scope as Important entities, subject to Article 21 security measures, Article 23 incident reporting, and Article 34 penalty exposure from day one.

The Security Measures Gap — From “Appropriate” to Ten Mandatory Controls

The most significant operational change from NIS1 to NIS2 is the move from a principles-based security obligation to a prescriptive, auditable control list.

NIS1 Article 14(1) required “appropriate and proportionate technical and organisational measures.” No list of required controls. In practice, organisations with existing ISO 27001 certification or a coherent internal security policy could argue NIS1 compliance without gap-analysing against any defined standard.

NIS2 Article 21(2) changes that. It mandates at minimum ten control domains, all of which must be addressed:

  • (a) Risk analysis and information security policies
  • (b) Incident handling
  • (c) Business continuity — backup management, disaster recovery, crisis management
  • (d) Supply chain security, including direct supplier relationships
  • (e) Security in network and information systems acquisition, development, and maintenance, including vulnerability handling
  • (f) Policies to assess the effectiveness of cybersecurity risk-management measures
  • (g) Basic cyber hygiene practices and cybersecurity training
  • (h) Cryptography and encryption policies
  • (i) Human resources security, access control, and asset management
  • (j) Multi-factor authentication or continuous authentication, and secured communications

For organisations with robust NIS1 programmes, domains (a), (b), and (c) probably existed in some form. The genuinely new obligations — items NIS1 never required explicitly — are (d) supply chain, (f) effectiveness assessment, (g) formal training policy, (h) cryptography policy, and (j) MFA. These are the most likely sources of gap findings in a transition review.

The “all-hazards approach” required by Article 21(1) also shifts the scope of what counts: NIS1 focused on security of network and information systems in relation to their specific service. NIS2 requires a broader view encompassing physical and environmental risks affecting cyber resilience — a flood or power failure disrupting critical systems is within scope, not only cyber-specific threats.

For the Article 21(2)(d) supply chain requirement specifically, see the detailed guide to NIS2 supply chain security.

Incident Reporting — From “Without Undue Delay” to a Three-Stage Clock

NIS1’s Article 14(3) required notification “without undue delay” of incidents with “significant impact on the continuity” of essential services. No specific timeframe. No structure for what to report or when. The vague standard produced inconsistent practice: some organisations notified within hours, others within days or weeks.

NIS2 Article 23 replaces this entirely with a three-stage mandatory structure. For a full breakdown of reporting workflows and what qualifies as a significant incident, see the Article 23 incident notification guide and the overview of NIS2 incident reporting obligations.

Stage 1 — Early warning (within 24 hours of awareness): Submit a brief alert to your CSIRT or competent authority within 24 hours of becoming aware of a significant incident. The early warning must indicate whether the incident is suspected to involve unlawful or malicious acts and whether it could have cross-border impact. No root-cause analysis is required at this stage — the obligation is notification, not diagnosis.

Stage 2 — Incident notification (within 72 hours of awareness): An updated report with an initial assessment of severity, impact, indicators of compromise, and current status.

Stage 3 — Final report (within one month of the incident notification): A comprehensive document covering threat analysis, root cause, applied mitigations, actual impact, and any cross-border effects.

Two transition traps are worth flagging. First, the 24-hour clock starts at awareness, not at confirmation or root-cause identification. Organisations that spend the first 24 hours determining whether an incident is “really significant” before notifying will be in breach. The early warning obligation is designed to precede certainty. Second, the NIS2 early warning is 24 hours — not 72. Organisations familiar with GDPR’s 72-hour personal data breach notification sometimes conflate the two. They are different obligations with different triggers, different timelines, and different reporting channels.

Article 23 also includes an important protection: “The mere act of notification shall not subject the notifying entity to increased liability.” This removes a key disincentive to early reporting that operated under NIS1’s indefinite standard.

Governance and Management Liability — NIS2’s New Personal Dimension

Under NIS1, cybersecurity obligations were organisational. An entity had to implement measures, but no individual within it was personally accountable under the directive’s text.

NIS2 Article 20 changes this in two specific ways. First, management bodies — boards of directors, executive committees, and equivalent governance structures — must approve the cybersecurity risk-management measures required by Article 21. Not delegate, not endorse in principle: approve. The distinction matters for audit evidence. A board resolution or documented board-level sign-off on the cybersecurity programme is now a compliance artefact, not an optional best practice.

Second, member states must ensure that management body members can be held personally liable for entity violations of NIS2 obligations. The exact mechanism depends on national transposition, but the directive explicitly enables personal accountability — not just organisational. For sectors already carrying director-level liability (financial services, healthcare), this is familiar territory. For organisations newly caught by NIS2’s expanded scope — manufacturing, food production, postal services — the personal dimension is often the most surprising element of the directive.

Article 20(2) also mandates training: management body members must receive regular cybersecurity training to develop sufficient competence to understand and oversee their organisation’s cyber risks. This is a member state obligation, not a recommendation.

The immediate transition action is documented board approval of the Article 21 security programme. Many organisations technically compliant with NIS1 at the operational level will fail NIS2 at the governance level because there is no board-level approval on record.

Penalty Regime — From Member State Discretion to Harmonised Ceilings

NIS1’s Article 21 required member state penalties to be “effective, proportionate and dissuasive” — but set no EU-wide floor or ceiling. The result was significant divergence: fine levels for NIS1 breaches varied by orders of magnitude between member states, from a few thousand euros to several million. Enforcement strength was essentially a function of geography.

NIS2 Article 34 harmonises this by setting maximum ceilings that member states must implement as minimums. For a full breakdown of how fines are calculated and applied, see NIS2 penalties and enforcement.

  • Essential entities: administrative fines up to €10,000,000 or 2% of total worldwide annual turnover — whichever is higher
  • Important entities: administrative fines up to €7,000,000 or 1.4% of total worldwide annual turnover — whichever is higher

These figures are minimums that member states must implement; national law may set higher ceilings. Violations of Articles 21 (security measures) or 23 (incident reporting) trigger these thresholds. Enforcement decisions must account for severity, duration, prior violations, damage caused, intent, mitigation efforts, and cooperation levels.

The supervisory model also shifts materially. Article 32 subjects essential entities to proactive, ex-ante supervision — competent authorities can conduct on-site inspections, targeted security audits, and security scans without waiting for an incident. This represents a departure from NIS1’s largely reactive approach. Important entities remain subject to ex-post supervision under Article 33, meaning proactive audits require either a specific trigger or a targeted decision by the competent authority — a materially lighter compliance burden, though with the same penalty exposure when violations occur.

NIS1-to-NIS2 Transition Checklist

The changes above translate into specific actions. Effort ratings: High = multi-week project typically needing external input; Medium = internal sprint completable in 2–4 weeks; Low = completable in days with the right documentation.

# Action Effort NIS2 Article
1 Confirm entity classification (Essential or Important) and register with your national competent authority Low Arts. 2–3
2 Gap-assess your current security programme against all 10 Art. 21(2) control domains, focusing on (d), (f), (g), (h), and (j) which NIS1 did not require High Art. 21(2)
3 Build an incident response workflow with explicit 24h/72h/1-month owners and pre-approved escalation path Medium Art. 23
4 Map all direct suppliers, classify by criticality, and add NIS2 security clauses to contracts High Art. 21(2)(d)
5 Draft and adopt cryptography and MFA policies Medium Arts. 21(2)(h)(j)
6 Obtain documented board approval of the cybersecurity risk-management programme Low Art. 20
7 Schedule cybersecurity training for management body members Low Art. 20(2)
8 Implement an effectiveness-assessment process for security measures (KPIs, measurement methodology) Medium Art. 21(2)(f)

Frequently Asked Questions

Was my NIS1 compliance programme sufficient to satisfy NIS2?

Almost certainly not in full. The gaps are specific: NIS1’s “appropriate and proportionate measures” standard never required explicit coverage of supply chain security (Art. 21(2)(d)), cryptography policies (Art. 21(2)(h)), MFA (Art. 21(2)(j)), or effectiveness assessment (Art. 21(2)(f)). It also imposed no governance requirement — your management body was never formally required to approve the security programme. Any transition review should address these five domains explicitly.

If I was an OES under NIS1, am I now an essential entity under NIS2?

Yes. Article 3(1) of NIS2 explicitly includes entities “previously identified as operators of essential services” as essential entities under NIS2. Your classification is carried forward. Your obligations now encompass the full Article 21(2) control list, Article 23’s three-stage reporting, and Article 20’s management body accountability requirements — all of which exceed what NIS1 required.

What is the biggest operational change from NIS1 to NIS2?

For most compliance teams, incident reporting. The shift from an indefinite “without undue delay” to a mandatory 24-hour early warning fundamentally changes the operational posture required. An organisation without a monitoring function and a pre-approved escalation chain cannot reliably meet the 24-hour deadline. Building that capability is typically the highest-effort, highest-urgency item for formerly NIS1-compliant organisations.

When did NIS1 cease to be law?

NIS1 (Directive 2016/1148) was repealed on 18 October 2024, the date by which all EU member states were required to have transposed NIS2 into national law. From that date, NIS1 obligations no longer exist as an EU-law floor. Your obligations are now governed exclusively by your member state’s NIS2 transposition legislation.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: