NIS2: A Complete Article-by-Article Reference

NIS2: A Complete Article-by-Article Reference

Views: 2

NIS2 Directive: Complete Article-by-Article Guide — TheCyberMatrix
EU Directive 2022/2555

NIS2: A Complete
Article-by-Article Guide

Category: Regulatory Compliance Coverage: All 46 Articles Applies to: Essential & Important Entities across the EU Effective: October 2024

NIS2 is the EU’s landmark cybersecurity directive — and the most significant expansion of cybersecurity obligations in Europe since GDPR. This guide breaks down every article in plain language: what it means, what your organisation must do, and which policies and controls to implement.

46Articles
9Chapters
18+Covered Sectors
€10MMax Fine (Essential)
24hEarly Warning Window

Why NIS2 Matters — and Who It Covers

NIS2 replaces the original Network and Information Security Directive (NIS1, 2016) and dramatically expands both the number of organisations in scope and the depth of obligations they face. It entered into force on 16 January 2023 and Member States were required to transpose it into national law by 17 October 2024.

The directive applies to medium and large organisations (50+ employees or €10M+ annual turnover) in 18 critical sectors — from energy, transport, and finance to digital infrastructure, managed services, healthcare, and public administration. DNS providers, cloud providers, and managed service providers (MSPs) are in scope regardless of size.

Key Principle

NIS2 introduces a two-tier classification: Essential Entities face proactive (ex-ante) supervision, while Important Entities face reactive (ex-post) supervision. Both tiers share the same core obligations — the difference is how regulators monitor you, and the level of fines that apply.

What About “Critical Entities”?

You may have seen a third entity type — Critical Entity — referenced in books and training materials. This classification does not come from NIS2. It comes from the companion CER Directive (EU 2022/2557 — Critical Entities Resilience), which was published alongside NIS2 as part of the same EU regulatory package. CER focuses on physical and operational resilience (protection from physical disruption, terrorism, natural hazards, sabotage), while NIS2 focuses on cybersecurity. An entity can hold classifications under both — for example, a major energy provider may be a Critical Entity under CER and an Essential Entity under NIS2 simultaneously. NIS2 and CER are complementary directives, not competing ones.

If you’re also implementing ISO 27001:2022, you already have a significant head start — it covers approximately 60–70% of the Article 21 security measure requirements.

🔴 Essential Entities
€10,000,000
or 2% of global annual turnover — whichever is higher.
Management may also face personal liability and a temporary ban from executive roles.
🔵 Important Entities
€7,000,000
or 1.4% of global annual turnover — whichever is higher.
Non-cooperation with supervisory authorities carries additional penalties.

All Articles by Chapter


NIS2 ↔ ISO 27001:2022 Alignment

ISO 27001:2022 is explicitly referenced in Article 25 as a recognised means of demonstrating NIS2 compliance. Here’s how the core Article 21 obligations map to ISO 27001 controls:

NIS2 Art. 21 Requirement ISO 27001:2022 Controls Coverage
(a) Risk analysis & security policiesClause 6.1, A.5.1, A.5.2, A.8.2
(b) Incident handlingA.5.24–A.5.28
(c) Business continuity, backup & DRA.5.29, A.5.30, A.8.13, A.8.14
(d) Supply chain securityA.5.19–A.5.23
(e) Secure development & vulnerability managementA.8.8, A.8.25–A.8.29
(f) Effectiveness assessment & auditsClause 9.1, 9.2, 9.3, A.5.35, A.5.36
(g) Cyber hygiene & trainingA.6.3, A.8.2
(h) Cryptography & encryptionA.8.24
(i) HR security, access control, asset managementA.5.9–5.13, A.6.1–6.6, A.8.1–8.3
(j) MFA & communications securityA.5.17, A.8.5, A.8.20, A.8.22