Comply with the EU NIS2 Directive
What is NIS2?
NIS2 — Directive (EU) 2022/2555 — is the European Union's updated cybersecurity directive. It replaces the original 2016 NIS Directive and dramatically expands both the range of organizations in scope and the rigor of what they must do. The transposition deadline for Member States was October 17, 2024, and because national implementation and enforcement have rolled out unevenly, 2026 is a key year as the remaining requirements and supervisory regimes come fully into effect.
Unlike a regulation, a directive is implemented through national law, so the precise rules vary by Member State — but the baseline obligations below are common across the EU.
Who is in scope
NIS2 applies to medium and large organizations across roughly 18 sectors, including energy, transport, banking and financial market infrastructure, health, water, digital infrastructure, ICT service management, public administration, manufacturing, and food. In-scope organizations are classified as essential or important entities; essential entities face proactive supervision, while important entities are supervised reactively, and the distinction also affects the size of potential fines.
Core requirements
- Risk-management measures (Article 21) — a baseline set of ten measures including incident handling, business continuity and crisis management, supply-chain security, secure development and vulnerability handling, cryptography, access control, and multi-factor authentication.
- Incident reporting (Article 23) — for a significant incident, a 24-hour early warning, a 72-hour notification, and a one-month final report to the national CSIRT or competent authority.
- Governance and accountability — management bodies must approve and oversee cybersecurity measures and can be held personally liable; staff must receive training, and entities must register with their authority.
How episki helps
episki carries NIS2 obligations as structured records: risk management measures wired to evaluated controls, incident findings with owners and reporting clocks that sync into your engineers' tracker, and supply chain risk run through the TPRM module with review cadences that advance on accepted evidence. Management accountability is backed by approvals that record the approver and the rationale. Start a free trial or book a demo.
NIS2 outcomes with episki
Why teams choose episki for NIS2
- Incident handling, BCDR, and crisis management
- Supply-chain and third-party security
- Cryptography, access control, and MFA
- 24-hour early warning
- 72-hour incident notification
- One-month final report
- Management-body approval and liability
- Security awareness and training
- Entity registration with the authority
NIS2 readiness inside episki
Plug episki into your stack and work directly from this checklist during the free trial.
- ✓ Scope determination (essential vs. important entity)
- ✓ Article 21 risk-management measures as controls
- ✓ Incident classification and 24h / 72h / 1-month reporting
- ✓ Supply-chain and third-party security program
- ✓ Business continuity, backup, and crisis management
- ✓ Management-body oversight, training, and registration