NIS2 Directive

Directive 2022/2555
European Union directive
TitleDIRECTIVE (EU) 2022/2555 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148
Other legislation
ReplacesNIS1
Current legislation

The Directive (EU) 2022/2555, commonly known as NIS2 (Network and Information Security) is a directive of the European Union aimed at protecting digital infrastructure, in particular critical infrastructure.

It broadened the sectors covered by EU network and information security rules and updated incident reporting and oversight compared to the NIS1. Member States were required to transpose NIS2 by 17 October 2024, and the earlier NIS Directive was repealed on 18 October 2024.[1]

Only 23 Member States have fully implemented the measures contained with the NIS Directive. Infringement proceedings against them to enforce the Directive have not taken place, and they are not expected to take place in the near future.[2] This failed implementation has led to the fragmentation of cybersecurity capabilities across the EU, with differing standards, incident reporting requirements and enforcement requirements being implemented in different Member States.

From the EFTA countries (to April 2026) only Liechtenstein has fully transposed the NIS2 Directive. While the EFTA commission is conducting preparations to transpose the directive into its legislation.[3]

National implementations

Czech Republic

It is implemented through the Act No. 264/2025 Coll. also called Zákon o kybernetické bezpečnosti (Cybersecurity law) and through another five implementing regulations.[4] The transposing legislation came into force on November 1st, 2025.[5]

Germany

It is implemented through the Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung.

Ireland

It is implemented through the National Cyber Security Bill.

The Netherlands

It is implemented through the Cyberbeveiligingswet (Cbw).

Slovakia

It is implemented through via an amendment of the Act No. 69/2018 Coll. also called Zákon o kybernetickej bezpečnosti a o zmene a doplnení niektorých zákonov (Law on Cybersecurity and change and amendment of certain laws).[6] It came into force on November 1st, 2025.[7]

Spain

Its not implemented in Spain yet.

Sweden

It is implemented through Cybersäkerhetslag (2025:1506).

Further reading

  • Kianpour, Mazaher; Earls Davis, Peter Alexander; Windekilde, Iwona Maria (2025-06-30). "Digital sovereignty in practice: analyzing the EU's NIS2 directive". International Journal of Information Security. 24 (4): 167. doi:10.1007/s10207-025-01090-4. ISSN 1615-5270.
  • "NIS2 Directive in Sweden: A Report on the Readiness of Swedish Critical Infrastructure | springerprofessional.de". link.springer.com. Retrieved 2026-04-15.

References

  1. ^ "NIS2 Directive: securing network and information systems". European Commission. 2025. Retrieved 25 October 2025.
  2. ^ "NIS Implementation Tracker".
  3. ^ "Factsheet - 32022L2555 | European Free Trade Association". www.efta.int. Retrieved 2026-04-27.
  4. ^ Sedlák, Jan. "Regulace podle NIS2: Vyhlášky ke kyberzákonu byly zveřejněny. Trash talk pokračuje, nařízení vlády se zaseklo". Lupa.cz (in Czech). Retrieved 2026-04-26.
  5. ^ "e-Sbírka". e-sbirka.gov.cz (in Czech). Retrieved 2026-04-26.
  6. ^ Drtina, Martin. "Regulace podle NIS2: Slováci k zákazům dodavatele novelu kyberzákona nepotřebují". Lupa.cz (in Czech). Retrieved 2026-04-26.
  7. ^ s.r.o, Tamatus. "NIS2 smernica – koho sa týka a ako sa pripraviť". www.predvolby.cz (in Slovak). Retrieved 2026-04-26.

Content Disclaimer

Informasi ini disarikan dari Wikipedia dan disajikan kembali untuk tujuan edukasi. Konten tersedia di bawah lisensi CC BY-SA 3.0. Kami tidak bertanggung jawab atas ketidakakuratan data yang bersumber dari kontribusi publik tersebut.

  1. The information displayed on this website is sourced in part or in whole from Wikipedia and has been adapted for the purpose of restating it. We strive to provide accurate and relevant information, however:
  2. There is no guarantee of absolute accuracy. Wikipedia is an open, collaborative project that can be edited by anyone, so information is subject to change.
  3. It is not intended to constitute professional advice. The content displayed is for informational and educational purposes only. For important decisions (e.g., medical, legal, or financial), please consult a professional.
  4. Content copyright. Wikipedia is licensed under the Creative Commons Attribution-ShareAlike License (CC BY-SA). This means that content may be reused with appropriate attribution and shared under a similar license.
  5. Responsible use. Any risk arising from the use of information from this website is entirely the responsibility of the user.