What is NIS2?
The EU's network and information security directive. It sets baseline cybersecurity risk-management measures and a strict incident-reporting clock for organisations that member states designate as essential or important entities.
Medium and large organisations in eighteen named sectors — energy, transport, banking, health, digital infrastructure, ICT service management, public administration, manufacturing of certain products, and others. Each member state transposes it into national law, so the exact entity list is national.
From becoming aware of a significant incident.
A fuller assessment, including severity and impact.
From the submission of the 72-hour notification, not from discovery.
Dates that matter
- 17 January 2023Entered into force.
- 17 October 2024Transposition deadline for member states.
- PendingIreland has not yet transposed it — the National Cyber Security Bill 2024 is before the Oireachtas.
What people get wrong
The reporting clock is the part that catches people
Article 23 runs three stages, and the final report is anchored on the SUBMISSION of the 72-hour notification rather than on discovery. Getting that anchor wrong makes every deadline look earlier than it is. Three further Article 23 duties have no fixed clock at all — an intermediate report on request, a progress report where the incident is still ongoing when the final report falls due, and telling the recipients of your services, which is separate from notifying the CSIRT.
Management is personally on the hook
Article 20 makes management bodies approve the risk-management measures and oversee their implementation, and member states must provide that they can be held liable. This is not a delegation-to-IT regime.
The penalties are the headline, and they differ by entity type
Article 34 sets a maximum of at least €10 million or 2% of total worldwide annual turnover for essential entities, whichever is higher, and at least €7 million or 1.4% for important entities.
What Vivid Risk does with NIS2
Every scored control cites its Article 21 or 23 provision, read against the Official Journal text. The incident register models the Article 23 reporting clock.
The UK is not under NIS2 — it ceased to be a member state. UK organisations are assessed against the NCSC CAF instead.
Questions
Does NIS2 apply in the UK?
No. Directive (EU) 2022/2555 binds member states, and the UK ceased to be one. UK operators fall under the NIS Regulations 2018, assessed via the NCSC Cyber Assessment Framework, with the Cyber Security and Resilience Bill before Parliament to replace them.
Does Vivid Risk make me NIS2 compliant?
No. It is a self-assessment against the Article 21 measures with a citation on every scored control, plus an incident register that models the Article 23 clock. Compliance is determined by your national competent authority, not by a tool.
One assessment, every framework
The same answers produce your citations across every framework we cover at once, rather than one questionnaire per regulation.