NIS2

Also called NIS2 Directive, Directive (EU) 2022/2555, network and information security

ComposedNot built

NIS2 raises cybersecurity obligations across a much wider slice of the European economy than its predecessor, and it makes management personally accountable for meeting them.

The scope expansion is the story

The original directive covered a narrow set of operators. NIS2 extends to sectors including digital infrastructure, ICT service management, and providers of trust services, and it distinguishes essential from important entities with different supervisory regimes. Many organisations discovered they were in scope for the first time.

Why the transposition delay matters practically

A directive is not directly applicable. It becomes binding through each Member State's own law, and those laws differ in scope thresholds, reporting deadlines and penalties. A vendor selling across borders faces a set of related but non-identical regimes rather than one.

Where Solidus stands

Out of scope, because the entity that would be in scope does not exist yet. Worth tracking rather than acting on, and worth being honest that entering the EU as a legal entity changes this from a reading exercise into an obligation.

Where it comes from

Someone else specified this. Solidus assembles it.

Directive (EU) 2022/2555, with a transposition deadline of 17 October 2024. Being a directive rather than a regulation, it takes effect through national law, and most Member States missed the deadline; the Commission opened infringement proceedings across 2024 and 2025, so the national regimes are still landing at different speeds.

How to check this

Solidus has not built this. The entry explains the concept.

The directive is public on EUR-Lex. The national implementation that would apply to Solidus does not yet have a subject, because the entity that would be in scope does not yet exist.

Related

NIS2 · Solidus Lexicon