Modulos Named in the Inaugural Gartner® Magic Quadrant™ for AI Governance PlatformsRead the

Press Release

EU regulations · NIS2 Directive

Enforcement is live; first fines are on the books

NIS2 Directive
Compliance Made
Manageable

Turn NIS2 obligations into assigned controls, linked evidence, and board-visible progress. National enforcement is live, first fines have been issued, and the Commission is taking laggard member states to the CJEU.

The EU tech law stack:EU AI ActGDPRNIS2DORACyber Resilience Act

What you need to know

  1. Medium and large entities in 18 sectors are in scope: 50 or more employees or over €10M turnover puts you in, and some digital and ICT service providers are covered regardless of size.
  2. The transposition deadline has passed, and the Article 21(2) measures and Article 23 reporting bite through enacted national law: first national fines have been issued, four member states were referred to the CJEU in July 2026, and your own jurisdiction's transposition sets the details.
  3. Fines reach at least €10M or 2% of worldwide turnover for essential entities, and management bodies can be held liable under Article 20 for failures on the Article 21 measures.
Owners: CISOs, security leaders, complianceRead the framework docs →
01

What is NIS2?

The NIS2 Directive (Directive (EU) 2022/2555) is the EU's updated cybersecurity legislation, replacing the original NIS Directive from 2016. It establishes a high common level of cybersecurity across the European Union, significantly expanding the scope from roughly 10,000 entities under NIS1 to over 160,000 under NIS2.

NIS2 introduces stricter requirements for risk management, incident reporting, supply chain security, and governance, including personal accountability for management bodies. Member States were required to transpose the directive into national law by October 2024.

02

Where things stand

The obligations are already live. What lies ahead is court enforcement against the laggard states and the first scheduled review.

Today

  1. 18 Oct 2024

    now in effect

    NIS2 applies; national enforcement live and first fines issued

  2. 15 Aug 2026

    now in effect

    Dutch transposition in force, closing one of the last gaps

  3. 17 Oct 2027

    in 12 months

    Article 40 Commission review; targeted amendments already in trilogue

Behind us: in force since January 2023; transposition deadline passed October 2024; reasoned opinions to 19 member states May 2025; Ireland, Spain, France, and the Netherlands referred to the CJEU July 2026.

03

Does NIS2 apply to you?

Pick your sector and size below for a first orientation. NIS2 uses a size-cap rule combined with sector classification for most entities. Certain digital and ICT service providers can also be in scope even when not established in the EU.

Quick scope check

Pick the row that fits you best. The verdict updates as you choose.

Sector
Size

Select a sector and a size to see where you would likely land.

This check gives orientation only; your actual scope turns on the Article 2 definitions and your national transposition.

The Article 2 size-cap rule

Organizations in covered sectors are in scope if they meet either threshold: 50 or more employees, or over €10M annual turnover or balance sheet.

Size doesn't matter for some. Article 2(2) lists exceptions where entities are in scope regardless of size, including DNS service providers, TLD name registries, trust service providers, and certain public electronic communications entities.

Annex I sectors

The sectors of high criticality, mostly essential entities. They face stricter supervision and a minimum maximum fine of at least €10M / 2%.

  • Energy
  • Transport
  • Banking
  • Financial market infrastructure
  • Health
  • Drinking water
  • Waste water
  • Digital infrastructure
  • ICT service management (B2B)
  • Public administration
  • Space

Annex II sectors

The other critical sectors, mostly important entities. They face reactive supervision and a minimum maximum fine of at least €7M / 1.4%.

  • Postal and courier services
  • Waste management
  • Chemicals
  • Food production & distribution
  • Manufacturing (medical devices, electronics, machinery, motor vehicles)
  • Digital providers (marketplaces, search engines, social networks)
  • Research organisations

Article 26 jurisdiction for certain non-EU providers

Article 26(1)(b) applies to specific non-EU digital and ICT providers offering services in the EU: DNS service providers, TLD name registries, domain name registration service providers, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, and providers of online marketplaces, online search engines, and social networking services. These entities must designate a representative in one Member State where services are offered.

Example: A US-based cloud provider serving EU customers can fall within Article 26 jurisdiction even without an EU office. It must appoint an EU representative and comply with NIS2 obligations that apply to its service category.

Which of the five reach you?

Answer for your company, and see the stack you actually manage. Most teams arrive here for one regulation and leave managing three.

Likely on your desk:EU AI ActGDPRNIS2DORACyber Resilience Act

You came for the NIS2. Tick what else is true and watch the stack grow.

A one-question check gives orientation only; actual scope turns on each regime's territorial, entity-size, and product tests.

04

What do you owe?

Article 21(2) of NIS2 prescribes 10 minimum cybersecurity risk-management measures that both Essential and Important entities must implement.

Risk analysis & security policies

Establish and maintain comprehensive risk analysis and information system security policies.

Incident handling

Prevention, detection, analysis, containment, response, and recovery from security incidents.

Business continuity

Backup management, disaster recovery, and crisis management procedures.

Supply chain security

Assess and manage security risks from direct suppliers and service providers.

Secure development & vulnerability handling

Security in network and information systems acquisition, development, and maintenance, including vulnerability handling and disclosure where appropriate.

Effectiveness assessment

Policies and procedures to regularly assess the effectiveness of cybersecurity measures.

Cyber hygiene & training

Basic cyber hygiene practices and cybersecurity training across staff. Article 20(2) makes specific cybersecurity training mandatory for management bodies on top.

Cryptography & encryption

Policies governing the use of cryptography and encryption where applicable.

Access control & HR security

Human resources security, access control policies, and comprehensive asset management.

Multi-factor authentication

MFA or continuous authentication, secured communications, and emergency systems.

05

What happens in an incident?

NIS2 introduces strict incident reporting obligations under Article 23. Organizations must report significant incidents in four stages.

StepDeadlineContent
Early warning24 h from becoming awareArticle 23(4)(a). Submit an early warning to the CSIRT or competent authority, indicating suspected unlawful or malicious cause and possible cross-border impact.
Incident notification72 h from becoming awareArticle 23(4)(b). Provide an initial assessment including severity, impact, and indicators of compromise; updates the early warning.
Intermediate reportOn request while the incident is being handledArticle 23(4)(c). On request from the CSIRT or competent authority, provide relevant status updates.
Final report1 month after the 72-hour notificationArticle 23(4)(d). Deliver root cause analysis, mitigation measures applied, and any cross-border impact. Article 23(4)(e) adds progress reports for ongoing incidents.
06

What happens if you get it wrong?

Article 34 sets minimum maximum administrative fines: member states must allow at least the figures below, and national law may set higher caps.

€10M / 2%

Essential entities

Article 34(4)

€7M / 1.4%

Important entities

Article 34(5)

Pick a global annual turnover to draw both tiers to scale.

Global turnover:
Essential entitiesup to €10M or 2% of global turnover, whichever is higher
€40M
€10M cap
Important entitiesup to €7M or 1.4% of global turnover, whichever is higher
€28M
€7M cap
0€10M€20M€30M€40M

At €2B global turnover the percentages set the ceiling: 2% is €40M and 1.4% is €28M. The notch marks the fixed €10M and €7M amounts they overtake.

The higher of the fixed amount and the percentage applies. Article 34 sets minimum maximums for infringements of the Article 21 measures and Article 23 reporting duties: member states must allow at least these fines and may go higher. Essential entities face proactive supervision under Article 32; important entities are supervised reactively under Article 33, after the fact.

Fines are not the only lever. Under Article 20, management bodies must approve and oversee the Article 21 cybersecurity risk-management measures and can be held liable for failures. For essential entities, authorities can also request a temporary ban on CEO or legal-representative duties under Article 32(5).

07

How regimes stack on one AI system

NIS2 regulates the infrastructure AI systems run on. Here is how one system accumulates duties across regimes.

Worked example · SYS-04 · credit-scoring model at an EU-serving bank

EU AI Acthigh-risk duties by 2 Dec 2027

Credit scoring is Annex III point 5(b): the model is a high-risk AI system.

  • Articles 9 to 17 high-risk stack
  • Conformity assessment
  • EU database registration
GDPRapplicable since 2018

Personal data runs through training, inputs, and outputs, and a solely automated credit denial is an Article 22 decision.

  • Lawful basis for each processing purpose
  • Article 35 DPIA
  • Data-subject rights incl. Article 22
DORAapplicable since Jan 2025

At a financial entity, the model is ICT supporting a critical or important function.

  • Chapter II ICT risk management
  • Major-incident reporting
  • Register of information entry
NIS2This pagetransposition passed Oct 2024

For financial entities NIS2 is largely disapplied: DORA is lex specialis under NIS2 Article 4. Run the same model at an energy or health company and the Article 21 measures attach instead.

  • Article 21 cybersecurity measures (where in scope)
  • 24h early warning, 72h notification
Cyber Resilience Actreporting from 11 Sep 2026

If the model ships to the bank as licensed software, it is a product with digital elements and the vendor carries manufacturer duties. Run purely as an internal model or hosted service, it stays outside the CRA and the entity regimes above cover it.

  • Annex I secure-by-design & vulnerability handling
  • Article 14 reporting (24h/72h)
  • Article 12 bridge to AI Act Article 15

The regimes overlap where the controls live. Map controls once, keep one evidence record, and reuse it across every regime that attaches; the Modulos platform is built on that working model.

EU AI ActCBUAE Consumer AISaudi AI Risk (SDAIA)FINMA AIMAS FEATUAE AI EthicsSingapore MGFColorado SB 26-189CCPA ADMTNYC Local Law 144ISO/IEC 42001NIST AI RMFprEN 18282EN 18286prEN 18228IEEE 7003GDPRUAE PDPLISO/IEC 27701ISO/IEC 27001NIS2DORACRAOWASP LLM Top 10OWASP Agentic Top 10Microsoft Supplier DPR

The regimes overlap where the controls live

The governance graph maps every control in the framework library to every regulation it serves. Where regimes map the same control, one implementation and one evidence record can support all of them, subject to each regime's own requirements, and most of NIS2's controls already serve at least one other framework.

119 / 152NIS2 controls already serve another framework
120controls shared among the five EU regimes

Framework library v1.0.32

08

How the work gets done

Modulos gives compliance and security teams one workflow for requirements, controls, evidence, reviews, and exports. This helps you move faster from legal text to operational execution with clearer ownership and stronger auditability.

Turn legal obligations into assigned work

Translate NIS2 obligations into structured requirements and mapped controls so teams know exactly what needs to be done and by whom.

Reuse controls where requirements overlap

Map one control to multiple requirements when obligations overlap, reducing duplicate implementation and evidence effort across governance programs.

Keep evidence tied to execution

Attach evidence directly to controls and keep a durable trail of updates, reviewers, and decisions connected to each requirement.

Prove governance decisions

Use review statuses and structured approvals to show who validated what, when, and on which basis before marking work complete.

Export point-in-time audit packs

Generate project and control exports plus supporting evidence files to build point-in-time packages for internal and supervisory review.

Keep scope stable as requirements evolve

Manage framework scope deliberately, including updates and freeze points, so compliance work remains stable as your program matures.

How NIS2 fits with other frameworks

Most security teams run NIS2 alongside other regimes rather than instead of them. Article 21(2) of NIS2 maps directly onto the controls in ISO/IEC 27001 for information security; ISO/IEC 42001 supports the AI-management portion indirectly. There is no formal presumption of conformity, but most mature security programs run NIS2 inside an ISO/IEC 27001 management system.

For financial sector entities, Article 4 of NIS2 disapplies equivalent NIS2 risk-management and incident-reporting provisions where the Digital Operational Resilience Act (DORA) covers the same matter. NIS2 governance and supply-chain provisions that are not covered by DORA may still apply alongside.

For AI systems specifically, the EU AI Act and GDPR sit alongside NIS2 with overlapping risk-management and supply-chain expectations. Risk operating models such as the NIST AI RMF support the Article 21(2)(a) risk-analysis duty without substituting for it.

On the product side, the Cyber Resilience Act secures the software and hardware NIS2 entities buy and ship. The regimes complement each other: NIS2 regulates the organization and the CRA the product, but a vendor that is also an essential or important entity answers to both, including separate reporting tracks once CRA reporting starts on 11 September 2026.

For US-attestation work, SOC 2 control sets often share evidence with NIS2 cybersecurity-measure controls, especially around access, change, and incident management.

09

FAQ about NIS2

The NIS2 Directive (Directive (EU) 2022/2555) is the EU’s updated cybersecurity legislation, replacing the original NIS Directive of 2016. It expands the scope of regulated entities, raises baseline cybersecurity requirements, and tightens incident reporting obligations. EU member states had to transpose NIS2 into national law by 17 October 2024.

By industry

How this applies in your sector

See how this plays out in the sectors where it drives the most AI governance work:

Where the NIS2 work goes next

Talk to an expert

Walk through the Article 21(2) measures with someone who has taken security programs through them.

Book a NIS2 demo

Keep exploring on your own

The framework docs cover NIS2 measure by measure, and the governance graph shows the overlap with ISO/IEC 27001 and DORA.