NIS2 — Directive (EU) 2022/2555
A common level of cybersecurity across the union.
What we read it for
The act behind our operations pages: how a service is kept running, how a fault is logged and who has to be told.
Identity
| Type | Directive |
| Identifier | EU 2022/2555 |
| CELEX | 32022L2555 |
| Adopted | 2022-12-14 |
| In force | 2023-01-16 |
| Transposition deadline | 2024-10-17 |
45 articles in the base act
Structure
| Chapter | Act | Articles |
|---|---|---|
| I | General provisions | 1–6 |
| II | Coordinated cybersecurity frameworks | 7–13 |
| III | Cooperation at Union and international level | 14–19 |
| IV | Cybersecurity risk-management measures and reporting obligations | 20–25 |
| V | Jurisdiction and registration | 26–28 |
| VI | Information sharing | 29–30 |
| VII | Supervision and enforcement | 31–37 |
| VIII | Delegated and implementing acts | 38–39 |
| IX | Final provisions | 40–45 |
Articles
46 articles are read into the register, one address each.
- 1 · Subject matter
- 2 · Scope
- 3 · Essential and important entities
- 4 · Sector-specific Union legal acts
- 5 · Minimum harmonisation
- 6 · Definitions
- 7 · National cybersecurity strategy
- 8 · Competent authorities and single points of contact
- 9 · National cyber crisis management frameworks
- 10 · Computer security incident response teams (CSIRTs)
- 11 · Requirements, technical capabilities and tasks of CSIRTs
- 12 · Coordinated vulnerability disclosure and a European vulnerability database
- 13 · Cooperation at national level
- 14 · Cooperation Group
- 15 · CSIRTs network
- 16 · European cyber crisis liaison organisation network (EU-CyCLONe)
- 17 · International cooperation
- 18 · Report on the state of cybersecurity in the Union
- 19 · Peer reviews
- 20 · Governance
- 21 · Cybersecurity risk-management measures
- 22 · Union level coordinated security risk assessments of critical supply chains
- 23 · Reporting obligations
- 24 · Use of European cybersecurity certification schemes
- 25 · Standardisation
- 26 · Jurisdiction and territoriality
- 27 · Registry of entities
- 28 · Database of domain name registration data
- 29 · Cybersecurity information-sharing arrangements
- 30 · Voluntary notification of relevant information
- 31 · General aspects concerning supervision and enforcement
- 32 · Supervisory and enforcement measures in relation to essential entities
- 33 · Supervisory and enforcement measures in relation to important entities
- 34 · General conditions for imposing administrative fines on essential and important entities
- 35 · Infringements entailing a personal data breach
- 36 · Penalties
- 37 · Mutual assistance
- 38 · Exercise of the delegation
- 39 · Committee procedure
- 40 · Review
- 41 · Transposition
- 42 · Amendment of Regulation (EU) No 910/2014
- 43 · Amendment of Directive (EU) 2018/1972
- 44 · Repeal
- 45 · Entry into force
- 46 · Addressees
Language versions
EUR-Lex publishes the act in every official language. These are the direct addresses for the languages this site is written in.
Norwegian is not an official EU language. Norwegian readers use the national register.
National law
One line per country. A line exists only when a primary source has been read; otherwise the national register is linked instead.
| National law | Identifier | Official text |
|---|---|---|
| Sweden: Cybersäkerhetslag | SFS 2025:1506 | Official text |
| Finland: Kyberturvallisuuslaki | 124/2025 | Official text |
| Germany: BSI-Gesetz (NIS-2-Umsetzungsgesetz) | BSIG | Official text |
| Norway: Lov om finansavtaler (finansavtaleloven) | LOV-2020-12-18-146 | Official text |
| Denmark: Lov om betalinger | LOV nr 652 af 08/06/2017 | Official text |
| United Kingdom: Outside this jurisdiction | — | National register |
National implementing measures on EUR-Lex
Supervision
Official text
EU acts, read down to the national law
ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.
Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.