Back to the navigator

NIS2

In force (staggered)

Directive (EU) 2022/2555 on measures for a high common level of cybersecurity (NIS 2 Directive)

As of: 2026-08-02 Maintained by: Ruth/Content

This applies to you if …

Core obligations

Keep reading — free

Unlock the full content

Enter and confirm your email address: you subscribe to the Signal Forge newsletter by FORGE and get instant access to this and all other registration-gated content. You can unsubscribe at any time.

Already registered? The link from your confirmation email unlocks this device again.

First steps

  • Check whether the entity is classified as essential or important (sector + size).
  • Compare existing cybersecurity measures against the NIS2 minimum requirements (gap analysis).
  • Set up an incident-response and reporting process aligned with the 24h/72h deadlines.
  • Check registration with the BSI — in Germany the registration deadline has already passed (06.03.2026); catch up on late registration and leadership training promptly.

Deadlines

  • 2024-10-17EU deadline for transposition into national law (Germany initially missed this deadline)
  • 2025-04-17Member States are to draw up lists of essential and important entities
  • 2025-12-06Germany: NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) entered into force
  • 2026-03-06Germany: end of the 3-month registration deadline for in-scope entities with the BSI

Penalty for non-compliance

Fines up to EUR 10 million or 2 % of worldwide annual turnover (essential entities) or up to EUR 7 million or 1.4 % (important entities); personal management liability possible.

Sources