Skip to main content
← All posts·
Regulatory Compliance

What Is NIS2? The EU Cybersecurity Directive Explained for 2026

NIS2 Directive explained simply. Who it applies to, what it requires, the 10 minimum security measures, national transposition differences, penalties up to €10M or 2% of turnover, and how it intersects with DORA and the EU AI Act.

Luca Berton10 min read

NIS2 in 60 Seconds

NIS2 (Network and Information Security Directive 2) is the EU's updated cybersecurity law. It replaces the original NIS Directive (2016) with significantly broader scope, stricter requirements, and harsher penalties. EU member states had until 17 October 2024 to transpose it into national law.

In simple terms: NIS2 requires essential and important entities across 18 sectors to implement cybersecurity risk management measures and report significant incidents.

Who Does NIS2 Apply To?

18 Sectors, 2 Categories

Essential entities (11 sectors):

  • Energy (electricity, oil, gas, hydrogen, district heating)
  • Transport (air, rail, water, road)
  • Banking
  • Financial market infrastructures
  • Health (hospitals, reference labs, medical device manufacturers)
  • Drinking water
  • Waste water
  • Digital infrastructure (DNS, TLDs, cloud, data centres, CDNs, trust services)
  • ICT service management (B2B, managed services, managed security)
  • Public administration
  • Space

Important entities (7 sectors):

  • Postal and courier services
  • Waste management
  • Chemicals
  • Food production and distribution
  • Manufacturing (medical devices, electronics, machinery, motor vehicles)
  • Digital providers (online marketplaces, search engines, social networks)
  • Research organisations

Size threshold: Generally applies to medium-sized enterprises and above (50+ employees or €10M+ turnover).

The 10 Minimum Security Measures

Article 21(2) requires at minimum:

  1. Policies on risk analysis and information system security
  2. Incident handling
  3. Business continuity and crisis management
  4. Supply chain security
  5. Security in network and information systems acquisition, development, and maintenance
  6. Policies and procedures for assessing cybersecurity risk-management measures
  7. Basic cyber hygiene practices and cybersecurity training
  8. Policies and procedures for the use of cryptography and encryption
  9. Human resources security, access control policies, and asset management
  10. Use of multi-factor authentication, secured communications, and secured emergency communications
📘 Book

Kubernetes Recipes

A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).

Watch on Skillshare →

NIS2 vs DORA — What's the Difference?

AspectNIS2DORA
Legal formDirective (transposed nationally)Regulation (directly applicable)
Scope18 sectors, cross-economyFinancial sector only
FocusCybersecurity broadlyDigital operational resilience (ICT risk)
OverlapFinancial entities subject to DORA are exempt from NIS2 (lex specialis)DORA takes precedence for financial entities

Penalties

  • Essential entities: Up to €10,000,000 or 2% of total worldwide annual turnover, whichever is higher
  • Important entities: Up to €7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher
  • Management liability: NIS2 explicitly holds management bodies personally accountable. They must approve and oversee cybersecurity risk management measures.
🎓 Course

Learn Ansible Automation in 250+ Examples

Comprehensive Ansible training with real-world use cases.

Start on Educative →

NIS2 and AI Systems

AI systems that support essential or important services fall under NIS2 requirements. This means AI-powered network monitoring, predictive maintenance in energy, AI-driven diagnostics in healthcare, and similar applications need cybersecurity risk management, incident handling, and supply chain security measures.

NIS2
cybersecurity
directive
EU regulation
compliance
critical infrastructure
explained

Related Solution

Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 3-4 weeks.

Explore AI Readiness for Regulated Enterprises →

Need help applying this in your organization?

Get a free 30-minute assessment with actionable recommendations — whether we work together or not.

Book Your Free AI Platform Assessment

Or see AI readiness assessment scope & pricing

18+ years experience · Ex-Red Hat & Dell · Speaker at KubeCon EU 2026

Luca Berton

Written by

Luca Berton

CEO at Open Empower. 18+ years building enterprise infrastructure at JPMorgan Chase, Red Hat & Dell. Author of 9 technical books. Speaker at Red Hat Summit and KubeCon EU 2026. Instructor on Coursera, Pluralsight & Udemy.

Get more insights like this

Practical AI infrastructure and platform engineering guides — delivered to your inbox.

Subscribe to Newsletter →