- What Is the NIS2 Directive?
- How Do NIS2 Requirements Map to Controls, Owners, and Evidence?
- What Fines and Enforcement Actions Does NIS2 Carry?
- What Are the Implementation Steps for NIS2 Compliance?
- What Is the Current State of NIS2 Transposition and Enforcement?
- What Are the Limitations of NIS2 Compliance Programs?
- Audit-Ready Checklist for NIS2 Compliance
- What Would Encryption Consulting Recommend?
- Frequently Asked Questions
NIS2 compliance means meeting Directive (EU) 2022/2555’s cybersecurity risk-management, governance, and incident-reporting requirements if your organization qualifies as an “essential” or “important” entity across 18 in-scope EU sectors. It matters because national fines reach €10 million or 2% of global turnover, and the Commission is actively pursuing member states over incomplete transposition in 2026. Recommended action: confirm your entity classification first, then map each NIS2 article to a specific control, owner, and evidence artifact rather than a generic policy statement.
Key Takeaways
- NIS2 (Directive (EU) 2022/2555) replaced the original NIS Directive on January 16, 2023, expanding scope from 7 sectors to 18 and introducing direct fines of up to €10 million or 2% of global turnover for essential entities.
- As of May 2026, 23 of 27 EU member states have transposed NIS2 into national law by the European Commission’s own count, though the original transposition deadline was October 17, 2024.
- The Commission has opened infringement procedures against member states that missed the deadline, and enforcement has entered a new phase in 2026 with some states referred toward the Court of Justice of the EU over incomplete transposition.
- Articles 20, 21, and 23 are the three articles that carry the most operational weight: governance and management accountability, cybersecurity risk-management measures (including cryptography policy), and incident reporting timelines.
- NIS2’s cryptography requirement (Article 21(2)(h)) is a policy-and-procedure requirement, not a specific algorithm mandate, which means auditors look for a documented cryptography policy rather than a checklist of approved ciphers.
Published: April 2025. Updated: August 2026. Reviewed by Encryption Consulting’s Compliance Advisory Team.
For the U.S. federal control catalog that NIS2’s risk-management measures often get benchmarked against, see Elevate Your Security with NIST 800-53. For how encryption obligations differ across privacy regimes generally, see Data Privacy Laws for Encryption. For the cryptographic inventory NIS2’s Article 21(2)(h) policy depends on, see How CBOM Differs from SBOM and Why It’s Crucial for Industry.
What Is the NIS2 Directive?
NIS2, Directive (EU) 2022/2555, is the EU’s cybersecurity law that replaced the original 2016 NIS Directive on January 16, 2023. It expands scope from 7 sectors to 18, removes NIS1’s split between Operators of Essential Services and Digital Service Providers, and instead classifies organizations as “essential” or “important” based on sector, size, and revenue. Unlike NIS1, which left enforcement largely to individual member states with no clearly defined fines, NIS2 sets direct financial penalties, assigns explicit accountability to management bodies, and standardizes incident-reporting timelines across the EU.


How Do NIS2 Requirements Map to Controls, Owners, and Evidence?
NIS2’s requirements are broad by design, so “we have a cybersecurity policy” doesn’t satisfy an auditor. Each article maps to a specific control, owner, and artifact:
| NIS2 requirement | Article | Control | Owner | Evidence artifact |
|---|---|---|---|---|
| Management accountability and oversight | Article 20 | Board-level cybersecurity training and a documented approval process for risk-management measures | Board / executive leadership | Training records, board meeting minutes approving security measures |
| Cryptography and encryption policy | Article 21(2)(h) | Documented cryptography policy covering algorithm selection, key management, and encryption use cases | Cryptography / security architecture team | Cryptography policy document, cryptographic asset inventory |
| Supply chain security | Article 21(2)(d) | Supplier risk assessments scoped to each direct supplier’s actual vulnerabilities | Procurement + security | Vendor risk register, supplier security questionnaires |
| Incident handling and reporting | Article 23 | 24-hour early warning, 72-hour initial assessment, and one-month final report process to the national CSIRT | Security incident response team | IR plan with the three-stage reporting workflow, past incident reports |
| Business continuity | Article 21(2)(c) | Tested backup, disaster recovery, and crisis management plan | IT operations / business continuity team | Backup test logs, disaster recovery runbook, tabletop exercise records |
What Fines and Enforcement Actions Does NIS2 Carry?
| Entity type | Maximum fine (€) | Maximum fine (% of global turnover) |
|---|---|---|
| Essential entities | At least €10,000,000 | At least 2% |
| Important entities | At least €7,000,000 | At least 1.4% |
Beyond direct fines, non-compliant management bodies can face personal liability and, in some member states, a temporary ban from management roles. The regulatory pressure isn’t theoretical: the European Commission has opened infringement procedures against member states over incomplete transposition, and enforcement entered a new phase in 2026 with some states referred toward the Court of Justice of the EU. That pressure flows downward, national regulators enforcing against organizations tend to move faster once their own government is under Commission scrutiny.


What Are the Implementation Steps for NIS2 Compliance?
- Determine whether your organization falls under NIS2’s 18 in-scope sectors and, if so, whether it meets the size and revenue thresholds for “essential” or “important” classification.
- Register with your national authority within the timeline that authority sets, since registration itself is a distinct NIS2 obligation, not just a compliance formality.
- Conduct a risk assessment against Article 21’s ten measures, including the cryptography and encryption policy requirement, and document current gaps.
- Assign a named owner and evidence artifact to each of the ten Article 21 measures before an audit, not during one.
- Build the three-stage incident-reporting workflow Article 23 requires: a 24-hour early warning, a 72-hour initial assessment, and a one-month final report to your national CSIRT.
- Brief the board specifically, since Article 20 makes management accountable by name, not the security team alone.
What Is the Current State of NIS2 Transposition and Enforcement?
NIS2’s original transposition deadline was October 17, 2024, but only four member states met it. As of May 2026, the European Commission counts 23 of 27 member states as having transposed the directive, though the Commission applies a stricter standard than some independent trackers, requiring all secondary legislation to be in place, not just the primary transposing law. The Commission has issued reasoned opinions calling on lagging member states to complete transposition, and enforcement has entered a new phase in 2026 with some states facing referral toward the Court of Justice of the EU. Organizations operating across multiple member states should expect continued variation in registration deadlines and enforcement timing until transposition is fully complete everywhere.
What Are the Limitations of NIS2 Compliance Programs?
- NIS2’s cryptography requirement is a policy-and-procedure mandate, not a specific algorithm list, which means “we use encryption somewhere” doesn’t satisfy Article 21(2)(h) without a documented policy behind it.
- Transposition inconsistency across member states means a genuinely NIS2-compliant program in one country may still need jurisdiction-specific registration or reporting adjustments in another.
- Supply chain security under Article 21(2)(d) extends liability to suppliers outside NIS2’s own scope, which most organizations underestimate until an audit surfaces an unassessed vendor.
- NIS2 doesn’t certify specific cryptographic modules or algorithms; complementary standards like FIPS 140-3 or Common Criteria cover that layer separately.
Audit-Ready Checklist for NIS2 Compliance
- Documented entity classification (essential or important) and registration confirmation with your national authority.
- A named owner and current evidence artifact for each of Article 21’s ten risk-management measures.
- A documented cryptography and encryption policy satisfying Article 21(2)(h), backed by a current cryptographic asset inventory.
- A tested three-stage incident-reporting workflow matching Article 23’s 24-hour, 72-hour, and one-month timelines.
- Board-level training records and meeting minutes showing management’s direct oversight under Article 20.
What Would Encryption Consulting Recommend?
Most organizations we assess have a general cybersecurity policy but nothing that satisfies Article 21(2)(h)’s cryptography-specific requirement, because no one owns cryptography policy as a distinct deliverable from the broader security policy. Our Encryption Advisory Services build that cryptography policy and the inventory behind it, our Compliance Advisory Services run the full Article 21 gap assessment and registration readiness review, and our implementation roadmap sequences the remediation work so it’s finished before your national authority’s deadline, not after.
Frequently Asked Questions
Has NIS2 fully replaced NIS1 everywhere in the EU?
Legally, yes, since January 16, 2023. Practically, as of May 2026, 23 of 27 member states have transposed it into national law, with the remainder still completing secondary legislation under Commission pressure.
What does NIS2 actually require regarding cryptography?
Article 21(2)(h) requires policies and procedures for the use of cryptography and, where appropriate, encryption. It’s a documented-policy requirement, not a mandated list of specific algorithms.
How much can NIS2 fines actually reach?
At least €10 million or 2% of global annual turnover for essential entities, and at least €7 million or 1.4% for important entities, whichever calculation is higher.
Does NIS2 apply to suppliers outside its direct scope?
Indirectly, yes. In-scope entities are responsible for assessing their direct suppliers’ cybersecurity practices under Article 21(2)(d), which extends practical obligations to vendors that aren’t independently in scope.
What are the reporting timelines for a significant incident?
A 24-hour early warning, a 72-hour initial assessment with incident details, and a final report within one month, all submitted to the organization’s national CSIRT under Article 23.
Need help closing the gap between your current security policy and NIS2’s Article 21 requirements? Talk to Encryption Consulting’s Compliance Advisory team.
References
- What Is the NIS2 Directive?
- How Do NIS2 Requirements Map to Controls, Owners, and Evidence?
- What Fines and Enforcement Actions Does NIS2 Carry?
- What Are the Implementation Steps for NIS2 Compliance?
- What Is the Current State of NIS2 Transposition and Enforcement?
- What Are the Limitations of NIS2 Compliance Programs?
- Audit-Ready Checklist for NIS2 Compliance
- What Would Encryption Consulting Recommend?
- Frequently Asked Questions
