Views: 2
NIS2: A Complete
Article-by-Article Guide
NIS2 is the EU’s landmark cybersecurity directive — and the most significant expansion of cybersecurity obligations in Europe since GDPR. This guide breaks down every article in plain language: what it means, what your organisation must do, and which policies and controls to implement.
Why NIS2 Matters — and Who It Covers
NIS2 replaces the original Network and Information Security Directive (NIS1, 2016) and dramatically expands both the number of organisations in scope and the depth of obligations they face. It entered into force on 16 January 2023 and Member States were required to transpose it into national law by 17 October 2024.
The directive applies to medium and large organisations (50+ employees or €10M+ annual turnover) in 18 critical sectors — from energy, transport, and finance to digital infrastructure, managed services, healthcare, and public administration. DNS providers, cloud providers, and managed service providers (MSPs) are in scope regardless of size.
NIS2 introduces a two-tier classification: Essential Entities face proactive (ex-ante) supervision, while Important Entities face reactive (ex-post) supervision. Both tiers share the same core obligations — the difference is how regulators monitor you, and the level of fines that apply.
You may have seen a third entity type — Critical Entity — referenced in books and training materials. This classification does not come from NIS2. It comes from the companion CER Directive (EU 2022/2557 — Critical Entities Resilience), which was published alongside NIS2 as part of the same EU regulatory package. CER focuses on physical and operational resilience (protection from physical disruption, terrorism, natural hazards, sabotage), while NIS2 focuses on cybersecurity. An entity can hold classifications under both — for example, a major energy provider may be a Critical Entity under CER and an Essential Entity under NIS2 simultaneously. NIS2 and CER are complementary directives, not competing ones.
If you’re also implementing ISO 27001:2022, you already have a significant head start — it covers approximately 60–70% of the Article 21 security measure requirements.
All Articles by Chapter
NIS2 ↔ ISO 27001:2022 Alignment
ISO 27001:2022 is explicitly referenced in Article 25 as a recognised means of demonstrating NIS2 compliance. Here’s how the core Article 21 obligations map to ISO 27001 controls:
| NIS2 Art. 21 Requirement | ISO 27001:2022 Controls | Coverage |
|---|---|---|
| (a) Risk analysis & security policies | Clause 6.1, A.5.1, A.5.2, A.8.2 | |
| (b) Incident handling | A.5.24–A.5.28 | |
| (c) Business continuity, backup & DR | A.5.29, A.5.30, A.8.13, A.8.14 | |
| (d) Supply chain security | A.5.19–A.5.23 | |
| (e) Secure development & vulnerability management | A.8.8, A.8.25–A.8.29 | |
| (f) Effectiveness assessment & audits | Clause 9.1, 9.2, 9.3, A.5.35, A.5.36 | |
| (g) Cyber hygiene & training | A.6.3, A.8.2 | |
| (h) Cryptography & encryption | A.8.24 | |
| (i) HR security, access control, asset management | A.5.9–5.13, A.6.1–6.6, A.8.1–8.3 | |
| (j) MFA & communications security | A.5.17, A.8.5, A.8.20, A.8.22 |

