Skip to main content
    Pritect

    Regulation

    NIS2
    From legal text to evidence

    The NIS2 Directive raises the baseline for cybersecurity across the EU and widens the sectors it reaches. Because it is a directive, what binds an entity is the national law that transposes it, so the duties below are the Union floor rather than the final text you comply with.

    Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive)

    CELEX
    32022L2555
    Official Journal
    OJ L 333, 27.12.2022, p. 80 to 152
    Articles
    46
    Jurisdiction
    🇪🇺 Europe
    Status
    In force
    Read the text on EUR-Lex

    From the Official Journal to a tracked obligation

    Three stages, and the legal text is not rewritten at any of them.

    1. 01

      The article

      The Official Journal text, transcribed word for word and checked against a hash of the source it came from. Nothing is paraphrased, and nothing is written from memory.

    2. 02

      The clause

      Each article becomes one clause in the catalogue, carrying its official heading, its citation and any deadline the text sets. This is the layer the platform reads, and it is shared across every tenant.

    3. 03

      Your obligation

      You adopt the clauses that apply to you, and each becomes a tracked obligation of your own: an owner, an applicability decision, a review date, and the evidence that it is being met.

    Where an article sets a reporting clock, the deadline the Incident Centre counts down is computed from that clause and starts when the text says it starts, rather than from a duration typed into the product.

    Key dates

    Entry into force and the day the obligations start to bite are different dates, so each one is listed separately against the article that sets it.

    1. 14 Dec 2022

      Adopted by the Parliament and the Council

    2. 27 Dec 2022

      Published in the Official Journal

    3. 16 Jan 2023

      Entered into force

      Art. 45

    4. 17 Oct 2024

      Member State transposition deadline

      Art. 41(1)

    5. 18 Oct 2024

      National measures apply from

      Art. 41(1)

    The articles that create work

    The obligation-bearing articles Pritect tracks, under the headings the Official Journal prints.

    46
    Articles
    4
    Tracked

    The directive runs to 46 articles. Pritect decomposes 4 of them clause by clause into obligations you can adopt, own and evidence: the Chapter IV duties that fall on an essential or important entity itself, covering management body accountability, the risk management measures, the reporting chain and the use of certification schemes. The rest are deliberately not decomposed, because they are addressed to Member States, the Commission and Union bodies rather than to you. Articles 1 to 19 set the subject matter, scope and definitions and build the national and Union level frameworks, from national strategies and competent authorities to the CSIRTs network, the Cooperation Group and coordinated vulnerability disclosure, Article 22 assigns coordinated supply chain risk assessments to the Cooperation Group, and Articles 25 to 46 cover standardisation, jurisdiction and registration, information sharing, supervision and enforcement, delegated acts and the final provisions. The set grows as the catalogue is extended.

    Risk management and reporting duties

    Chapter IV, Art. 20 to 25

    • Art. 20Governance
    • Art. 21Cybersecurity risk-management measures
    • Art. 23Reporting obligations
    • Art. 24Use of European cybersecurity certification schemes

    Article headings are reproduced verbatim from the Official Journal and stay in English in every language, because a citation has to remain quotable. They are transcribed from the published text; the subject-matter review that makes them authoritative inside the product is still pending.

    Common questions

    The questions teams ask first, answered plainly.

    Who does NIS2 apply to?
    The directive covers essential and important entities in the sectors listed in its annexes, from energy, transport, banking, health, water and digital infrastructure through to public administration, postal services, waste, chemicals, food, manufacturing and digital providers. Size thresholds matter and Member States may go further. Pritect records which sector and which category places you in scope.
    How quickly do we have to report an incident?
    Article 23 sets a staged chain for a significant incident: an early warning without undue delay and within twenty-four hours of becoming aware, an incident notification within seventy-two hours, and a final report within one month. Pritect starts every one of them from awareness, which is the moment the article names.
    What does NIS2 require of the management body?
    Article 20 requires the management body to approve the cybersecurity risk management measures, to oversee their implementation, and to be capable of being held liable for the entity's infringements. Its members must follow training, and the entity is encouraged to offer similar training to employees. Pritect keeps the approval and the training records against the measures they cover.
    What measures does Article 21 require?
    Article 21 takes an all-hazards approach and sets a minimum list: policies on risk analysis and information system security, incident handling, business continuity and crisis management, supply chain security, security in acquisition, development and maintenance including vulnerability handling, policies to assess effectiveness, basic cyber hygiene and training, cryptography, human resources security and access control, and multi-factor authentication or continuous authentication. Proportionality is judged on the entity's exposure, its size, and the likelihood and severity of incidents.
    Does the directive apply to us directly?
    No. A directive binds Member States, which transpose it into national law, and it is that national law an entity complies with. Transposition dates and national variations differ, so Pritect treats the articles here as the Union floor and records the national regime that actually governs each entity.

    This page summarises publicly available legal text so you can orient yourself. It is not legal advice.

    See it against your own records

    Bring one processing activity, one supplier and one open request. We will show you where each of them lands.