Split comparison illustration showing the evolution from NIS1 directive with 7 sectors to NIS2 with 18 sectors, shield and lock icons, navy and steel blue corporate design

From NIS to NIS2: 5 Changes That Directly Expand Your Compliance Obligations

Last verified: April 2026. Based on Directive (EU) 2022/2555 (NIS2) and Directive (EU) 2016/1148 (NIS1) via EUR-Lex.

The original NIS Directive (2016/1148) was the EU’s first binding cybersecurity law — a genuine step forward. But its core design flaw became apparent almost immediately: member states had wide discretion to decide which organisations counted as “operators of essential services.” They used that discretion very differently. A mid-sized water utility in one country faced strict obligations; an equivalent organisation across the border might fall entirely outside scope. The directive’s review, published in 2020, confirmed the problem: implementation had diverged so significantly that cross-border coordination was difficult and enforcement was uneven [1].

NIS2 (Directive 2022/2555) — which replaced NIS1 on 18 October 2024 — was designed to fix that. It does so by making almost everything stricter, broader, and more specific. Whether you’re upgrading existing NIS1 compliance or encountering these obligations for the first time, here are the five changes that directly affect what your organisation must do.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Change 1: Scope Expanded from 7 Sectors to 18

NIS1 covered operators of essential services in six sectors — energy, transport, banking, financial market infrastructure, health, and drinking water — plus digital service providers (cloud services, online marketplaces, and search engines) added with lighter requirements. That was the entire perimeter.

NIS2 scope qualification flowchart showing 18 sectors plus size thresholds automatically placing organisations in scope
NIS2 expands from 7 to 18 sectors and replaces discretionary national definitions with a single standardized size threshold formula.

NIS2 adds eleven new sectors [3]:

  • Public administration (central and regional government bodies)
  • Space
  • Postal and courier services
  • Waste management
  • Manufacture of chemicals
  • Food production, processing, and distribution
  • Manufacture of medical devices, electronics, machinery, and motor vehicles
  • Digital providers (social networking platforms, data centre services, CDN providers, managed security service providers)
  • Research organisations

The size threshold is also now standardised. NIS1 left the definition of “operator” largely to member states. NIS2 sets a direct rule: medium-sized and large entities in any of the 18 covered sectors are automatically in scope. The thresholds are 50 or more employees, or €10 million or more in annual turnover [2]. Organisations below both thresholds are generally exempt — with limited exceptions for entities whose disruption would carry disproportionate risk regardless of size.

Operational impact: If your organisation is in manufacturing, food production, waste management, or public administration — sectors absent from NIS1 — you may face NIS2 obligations for the first time. The scope and applicability page covers the full sector list and size-cap exemptions.

Change 2: Essential vs Important Replaces the OES/DSP Split

Under NIS1, “operators of essential services” and “digital service providers” operated under different supervisory regimes. DSPs had lighter ex-post oversight — regulators investigated mainly after incidents occurred. OES had heavier, proactive supervision. The split made sense in theory, but in practice it created ambiguity around which classification applied and motivated regulatory arbitrage.

NIS2 two-tier entity classification diagram comparing Essential and Important entity qualification, supervision, and penalty exposure
The OES and DSP split is abolished: classification under NIS2 is determined entirely by sector annex and organisational size.

NIS2 replaces this with a cleaner two-tier system based on sector and size [2]:

  Essential Entities Important Entities
Who Large entities in Annex I sectors (energy, transport, health, digital infrastructure, banking, water, public admin) Medium entities in Annex I sectors + large/medium entities in Annex II sectors (postal, waste, chemicals, food, manufacturing, digital providers)
Supervision Active, proactive oversight including on-site inspections Reactive — authorities typically act in response to incidents or complaints
Maximum fine €10 million or 2% of global annual turnover €7 million or 1.4% of global annual turnover

The classification matters immediately because it determines your supervisory risk profile. Essential entities can expect proactive audits; important entities are more likely to face scrutiny only after something goes wrong. Both tiers must implement the same Article 21 security measures — the difference is primarily in oversight intensity and maximum penalty exposure.

Operational impact: Identifying your tier should be one of the first steps in any NIS2 implementation project. See the full requirements overview to understand what your classification means for your compliance workload.

Change 3: Article 21 Gives You a Specific Security Checklist

NIS1 required “appropriate and proportionate” security measures — a standard that sounds reasonable but gave organisations enormous latitude to define “appropriate” for themselves. The result was highly variable security levels across in-scope entities, with no consistent baseline.

NIS2 Article 21 mandatory security baseline showing four pillars: governance, technical defenses, resilience, and ecosystem security
Article 21 ends the era of flexible appropriate defenses — 10 specific mandatory measures now apply to every in-scope entity.

NIS2 Article 21(2) defines ten specific categories of security measure that every in-scope entity must implement [2]:

  1. Policies on risk analysis and information system security
  2. Incident handling
  3. Business continuity, including backup management, disaster recovery, and crisis management
  4. Supply chain security — including security in relationships with direct suppliers and service providers
  5. Security in network and information system acquisition, development, and maintenance
  6. Policies and procedures to assess the effectiveness of cybersecurity risk-management measures
  7. Basic cyber hygiene practices and cybersecurity training
  8. Policies on the use of cryptography and, where appropriate, encryption
  9. Human resources security, access control policies, and asset management
  10. Multi-factor authentication or continuous authentication solutions

Supply chain security (item 4) deserves particular attention. It was not a mandatory requirement under NIS1 and represents a meaningful increase in scope: you are now responsible for assessing and managing the cybersecurity practices of your direct suppliers and service providers, not just your own internal systems. This has direct implications for procurement processes and supplier contracts.

Operational impact: These ten measures translate directly into the documentation your organisation needs to produce. The NIS2 compliance checklist maps each measure to specific deliverables and the policy templates that support them.

Change 4: Incident Reporting Gets a Timer

NIS1 required notification of significant incidents “without undue delay” — a phrase that sounds clear but produced different timelines across member states. Some national authorities expected notification within 24 hours; others accepted several days. For incidents affecting multiple countries, this inconsistency made coordinated response genuinely difficult.

NIS2 Article 23 incident reporting timeline showing three-stage countdown: 24-hour early warning, 72-hour notification, and 1-month report
The 24-hour early warning to your national CSIRT needs no comprehensive data — just awareness that a significant incident occurred.

NIS2 Article 23(4) replaces that ambiguity with three hard deadlines [2]:

  • Within 24 hours: Early warning to your national CSIRT. This is a preliminary notification — you don’t need full information yet, only notification that a significant incident is occurring or has occurred.
  • Within 72 hours: Incident notification with an initial assessment: severity level, whether the incident is ongoing, and any available indicators of compromise.
  • Within one month: Final report with root cause analysis, mitigation measures taken, and cross-border impact assessment where applicable.

An incident qualifies as “significant” under Article 23(3) if it causes severe operational disruption to your services or considerable damage to other parties [2]. The 72-hour timeline is not accidental — it deliberately mirrors GDPR’s personal data breach notification requirement, recognising that cyber incidents and data breaches regularly overlap.

Operational impact: Meeting a 24-hour early warning requirement without a pre-defined incident response process and communication chain is extremely difficult under real incident conditions. The incident reporting guide covers what needs to be in place before an incident occurs.

Change 5: Management Is Now Personally Accountable

Under NIS1, cybersecurity was essentially a technical function. Compliance failures were organisational — fines, if imposed, went to the entity. Board members had no specific obligations under the directive.

NIS2 management accountability map showing dual exposure of organizational fines and individual executive prohibition for cybersecurity failures
Article 20 makes management bodies personally liable: executives face temporary bans on management roles if gross negligence is established.

NIS2 Article 20(1) changes this explicitly: management bodies of essential and important entities must approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for infringements [2]. The directive also requires that management body members receive training on cybersecurity risk assessment and management practices to evaluate risk and make informed decisions.

The penalty framework makes the stakes concrete [2]:

  • Essential entities: administrative fines up to €10 million or 2% of total worldwide annual turnover, whichever is higher
  • Important entities: administrative fines up to €7 million or 1.4% of total worldwide annual turnover, whichever is higher
  • Individual accountability: national competent authorities may temporarily prohibit individuals from holding management roles where gross negligence in fulfilling NIS2 obligations is established

The fines apply to the entity; the temporary prohibition applies to individuals. Together, they create a personal liability dimension with no equivalent in NIS1. For organisations in financial services, the individual accountability provisions echo DORA’s approach — this is becoming the EU’s standard model for critical-sector regulation.

Operational impact: Boards and executive teams need to be briefed on NIS2 obligations, formally approve the risk management measures, and document that briefing. A board resolution and training record are the minimum evidence of due diligence you should have in place before a supervisory review.

What This Means in Practice

The five changes above follow a logical sequence. Scope comes first — if you weren’t subject to NIS1, you may be subject to NIS2. Classification comes next — your tier determines supervisory intensity and penalty exposure. Article 21 then gives you a concrete implementation framework. Incident reporting and management accountability complete the picture.

Organisations migrating from NIS1 compliance will find that the Article 21 measures overlap substantially with what they’ve already built, but gaps tend to appear in supply chain security documentation, formal board approval processes, and the incident reporting communication chain. Those are the areas worth auditing first.

If you’re just getting started, the NIS2 compliance checklist provides a structured starting point, and our free readiness check helps identify which Article 21 measures are already in place and where the gaps are.

Frequently Asked Questions

Is NIS1 still in force anywhere in the EU?
No. Directive (EU) 2016/1148 was formally repealed on 18 October 2024 when NIS2 became enforceable across all EU member states [1]. Organisations compliant under NIS1 should not assume that compliance carries over — the frameworks differ significantly, particularly on scope, security measures, and management accountability.

Does NIS2 apply to non-EU organisations?
Potentially, yes. NIS2 applies based on where services are provided, not solely where an organisation is headquartered. If your organisation provides services to entities or individuals in EU member states and meets the sector and size thresholds, you may fall within scope even if you are based outside the EU [2]. This is particularly relevant for managed service providers and cloud providers serving EU clients.

We were in scope under NIS1. Do we need to do anything differently under NIS2?
Almost certainly. NIS2’s ten mandatory Article 21 measures replace the flexible “appropriate and proportionate” standard with a specific baseline. Supply chain security, formal management approval processes, and the new incident reporting timelines are common gaps for organisations transitioning from NIS1 compliance programs. A structured gap analysis against Article 21 is the recommended starting point.

Sources

  1. Cybersecurity of network and information systems (NIS2 Legislative Summary) — EUR-Lex
  2. Directive (EU) 2022/2555 — EUR-Lex
  3. NIS2 Directive: securing network and information systems — European Commission

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: