Who is in scope
NIS2 covers medium and large organisations in sectors listed in its two annexes, such as energy, transport, banking, health, digital infrastructure, ICT service management, manufacturing and food. They are classified as essential or important entities, which determines how closely they are supervised.
Main obligations
Entities in scope must apply cybersecurity risk management measures, including incident handling, business continuity, supply chain security, access control, encryption and staff training. Management bodies must approve these measures and can be held accountable for failures.
Incident reporting
Significant incidents must be reported to the national CSIRT or authority in stages: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month.
Penalties
Fines can reach 10 million euros or 2% of global annual turnover for essential entities, and 7 million euros or 1.4% for important entities. Each EU country applies NIS2 through its own national law, which designates the supervisory authorities.




