What Is NIS2? The EU Cybersecurity Law Explained, and Who Is Being Sued Over It

nis2 - ai generated (2)
Takeaways
  • The Commission is suing four member states over NIS2, twenty-one months after the transposition deadline, a sign that the law’s first enforcement targets are governments rather than companies.
  • The directive covers 18 critical sectors and turns cybersecurity into a board-level liability, with fines that reach 2% of worldwide turnover.
  • NIS2 has applied since January 2023, before agentic AI could carry out an intrusion by itself, and none of its binding articles addresses an AI-driven attack.

On 8 July 2026, the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice of the European Union. Their offence was not a data breach or a botched procurement. It was failing to pass a law. Twenty-one months after the deadline, the four had still not written the NIS2 Directive into national legislation, and the Commission asked the court to impose a lump sum plus daily penalties that run until they comply.

That captures where NIS2 stands in the summer of 2026: the widest cyber rulebook the EU has ever drafted, and a rollout that has slid into legal chaos. Hanging over both is a question the law never anticipated, and one we come back to below. NIS2 was built for human attackers, in the last years before an AI could carry out an intrusion by itself.

What Is NIS2?

NIS2 is Directive (EU) 2022/2555, adopted in December 2022 and in force since 16 January 2023. The Commission describes it as the framework for a high common level of cybersecurity across the bloc. It replaced the original 2016 NIS Directive, which reached only a few hundred operators per country.

Because NIS2 is a directive rather than a regulation, it does not bind companies directly. Each member state had to pass its own law by 17 October 2024, naming its supervisory authority, its registration process and its penalties. That design choice explains most of what has gone wrong since. A company’s real duties depend on which country it sits in, and on whether that country has done its homework.

Who Does NIS2 Apply To?

Eighteen sectors, split into two tiers. The high-criticality list covers energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space. The second tier adds postal and courier services, waste management, chemicals, food, manufacturing, digital providers such as marketplaces and search engines, and research organisations.

The default threshold is 50 or more staff, or more than €10 million in annual turnover. Some entities are in scope whatever their size, including DNS providers, top-level domain registries and trust service providers. Each is classified as either essential or important: essential entities face proactive supervision, important ones are checked after the fact.

The practical effect is a step change in scale. Germany’s law brought roughly 29,500 organisations under supervision, up from about 4,500 under the old regime. France expects 15,000 or more, against roughly 500 before. This is the moment EU cybersecurity regulation stopped being a utilities problem and became a mid-sized-company problem.

What Does NIS2 Actually Require?

NIS2 requires three things, all in ascending order of how often they land boards in trouble.

First, security measures. Article 21 lists ten baselines: risk analysis, incident handling, business continuity and backups, supply chain security, secure development and vulnerability handling, effectiveness testing, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication.

Second, reporting. When a significant incident hits, Article 23 starts a clock: an early warning within 24 hours, a fuller notification within 72 hours, a final report within one month.

Third, and least understood, management liability. Article 20 requires management bodies to approve the security measures, oversee them and take training, and lets authorities hold senior managers personally accountable. Germany went further, requiring managers to implement the measures rather than merely sign them off. For anyone who sits on a board, this is the law’s sharp edge.

What Are the NIS2 Fines?

Essential entities: at least €10 million or 2% of worldwide annual turnover, whichever is higher. Important entities: at least €7 million or 1.4%. These are floors for the national maximums, not caps. A member state may set them higher, and several have.

When Does NIS2 Come Into Force, and Which Countries Have Implemented It?

This is where the tidy legal summary meets reality. The Commission’s enforcement has climbed a three-step ladder: letters of formal notice to non-compliant states in November 2024, reasoned opinions in May 2025, and the court referrals of July 2026.

Italy transposed early, in October 2024. Germany’s law took effect on 6 December 2025, more than a year late, with no transition period and a registration deadline of 6 March 2026. Poland’s law entered into force in April 2026. The Netherlands adopted its law on 7 July 2026, the day before the referral landed, and it entered into force on 15 August, which should make the Dutch case moot. France is furthest behind among the big economies: its bill has cleared the Senate but not the National Assembly, and its decrees are not expected before the end of 2026, though the regulator ANSSI has already opened its registration portal. Spain and Ireland have no law in force, with Dublin signalling completion by year end.

Step back, and the pattern is the point. The biggest compliance risk around NIS2 right now is not hackers. It is legal uncertainty. A company operating in five member states can face five different versions of the same directive.

Does NIS2 Apply to the UK?

Not directly. The UK left the EU before NIS2 was drafted, and it still runs the older Network and Information Systems Regulations 2018, its retained version of the original NIS Directive. But the gap is closing. The government’s Cyber Security and Resilience Bill, introduced to the Commons in November 2025, passed its Commons stages in June and had its second reading in the House of Lords on 14 July 2026. Parliament scheduled the Lords committee stage for 1 September, with Royal Assent expected before the year is out.

The bill deliberately tracks NIS2. It widens scope to managed service providers, data centres and designated critical suppliers, brings in a two-tier penalty regime, and imposes 24-hour and 72-hour incident reporting to sector regulators and the National Cyber Security Centre. British firms that assumed Brexit spared them the EU’s cyber rulebook are about to inherit a close cousin of it, though most of the detail will arrive later through secondary legislation, with full implementation not expected until 2028.

How Do NIS2, DORA and the Cyber Resilience Act Differ?

They are routinely confused, and they do different jobs.

NIS2 regulates organisations: how a hospital, a bank or a cloud provider manages its own security. The Cyber Resilience Act, Regulation (EU) 2024/2847, regulates products: any hardware or software with digital elements sold in the EU, from routers to apps. Its first hard deadline is close. From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents within 24 hours, through a single platform ENISA is standing up for the purpose. The full product-security and CE-marking regime applies from 11 December 2027, with fines up to €15 million or 2.5% of worldwide turnover.

Financial firms answer to a third rulebook, DORA, the sector’s own digital operational resilience regulation, which took priority for banks, insurers and their critical IT suppliers from January 2025. Our sister title examined what ignoring DORA costs.

The rough division: DORA for financial resilience, NIS2 for organisational security, the CRA for product security.

Is the EU About to Water NIS2 Down?

While it drags four governments to court over NIS2, the Commission is separately proposing to soften it. In a cybersecurity package it published on 20 January 2026, Brussels proposed amendments it says would ease compliance for 28,700 companies, including 6,200 micro and small firms, by clarifying scope and trimming reporting and registration burdens. The changes build on the single reporting point already floated in November’s Digital Omnibus.

The case for this is real. NIS2’s scope jump, from a few hundred operators to tens of thousands of mid-sized firms, was always going to catch companies with no security function and no budget to build one, and a rule nobody can comply with is not a security gain. But the timing is jarring. The same institution is asking a court to fine member states for not enacting a law it is busy softening, which hands the laggards an easy line: why rush to implement rules that are about to change? Enforcement and simplification are pulling in opposite directions, and the member states caught in the middle know it.

Does NIS2 Cover AI-Driven Attacks?

No, and the gap is getting harder to ignore. Nothing in the directive’s binding articles addresses an attack carried out or scaled by artificial intelligence. Where the technology appears at all, it is cast as a defensive tool. The Cyber Resilience Act’s one AI-related provision treats AI as a product to be secured, not an attacker to be defended against. Both laws were drafted before agentic AI could run an intrusion, a shift we examined after a vendor reported a near-autonomous attack on government systems in Asia.

The strongest counter is worth stating plainly, because it is the reason Brussels is relaxed. NIS2 is deliberately technology-neutral. Article 21’s obligations, incident handling, risk analysis, continuity, apply whether the intruder is a person or a model, so on this reading the law does not need to name AI to cover it. An organisation that must detect and report a significant incident carries that duty regardless of what wrote the exploit.

That argument holds for defence and breaks for everything else. Technology-neutral rules tell a company to handle incidents; they say nothing about attacks that arrive faster than a 24-hour clock, at a volume no human red team could produce, targeting the AI systems the same companies are racing to deploy. In July the Commission published an Action Plan on Cybersecurity and Artificial Intelligence that leans on NIS2 and CRA implementation. It is guidance, not law. For now, the EU’s answer to AI-enabled attacks is to ask member states to finish implementing rules written before the problem existed.

Where This Leaves You

NIS2 is the widest cybersecurity net the EU has cast, and its first two years tell a story nobody planned. Its most prominent enforcement targets so far are not negligent companies but the governments that failed to enact it, and the law it is fighting to impose is one Brussels is simultaneously trying to shrink. None of that makes the obligations optional. The registration windows are real, the reporting clocks are real, and the personal liability of managers is the part that will eventually produce headlines.

If you operate in one of the 18 sectors, the question is not whether NIS2 applies to you. It is which version of it your country has got around to writing, and whether the rulebook you comply with today survives contact with both the simplifiers and the machines.

Author: Ákos Szima

See Also:

What Is Sovereign AI?

What Did the EU’s Digital Omnibus Actually Delay in the AI Act?

What Is an Autonomous AI Attack, and Has One Actually Happened?

Frequently Asked Questions
What is NIS2 in simple terms?

NIS2 is the EU’s cybersecurity law, Directive 2022/2555. It requires medium and large organisations in 18 sectors, from energy and banking to food production and cloud services, to put ten baseline security measures in place, register with their national cyber authority, and report serious incidents within 24 hours. It replaced the 2016 NIS Directive, and member states had until 17 October 2024 to write it into national law.

Who does NIS2 apply to?

Organisations with at least 50 staff or €10 million in turnover in 18 listed sectors, split into essential entities (including energy, transport, banking, health, water, digital infrastructure and public administration) and important ones (including postal services, waste, chemicals, food, manufacturing, digital platforms and research). Some providers, such as DNS services, are covered regardless of size. In Germany alone, around 29,500 organisations fall under the law.

What are the NIS2 reporting deadlines?

Three steps: an early warning to the national authority or CSIRT within 24 hours of becoming aware of a significant incident, a full notification within 72 hours, and a final report within one month.

What are the penalties under NIS2?

National maximum fines must reach at least €10 million or 2% of worldwide annual turnover for essential entities, and at least €7 million or 1.4% for important entities, whichever is higher. Authorities can also hold senior management personally liable.

Which countries have not implemented NIS2?

As of August 2026, France, Spain and Ireland have not fully transposed NIS2. On 8 July 2026 the European Commission referred them, together with the Netherlands, to the EU Court of Justice, requesting a lump sum and daily penalties. The Netherlands’ law takes effect on 15 August 2026; Germany’s has applied since December 2025, Italy’s since October 2024.

Is NIS2 the same as the Cyber Resilience Act?

No. NIS2 regulates organisations’ security; the Cyber Resilience Act regulates products with digital elements. The CRA’s first obligation begins on 11 September 2026, when manufacturers must start reporting actively exploited vulnerabilities within 24 hours, and its full requirements apply from 11 December 2027.

Does NIS2 cover attacks carried out by AI?

No. NIS2’s binding provisions do not address AI-enabled attacks; AI appears only in non-binding recitals, as a defensive tool. The Commission’s July 2026 Action Plan on Cybersecurity and AI acknowledges the issue, but it is guidance rather than law.

Share this article

Latest news

Subscribe to our newsletter

More News