Legislation · European Union · EU Directive & Regulation (Directive (EU) 2022/2555)

EU Cybersecurity Directive (NIS2)

NIS2 moves cybersecurity out of the IT department's remit and ties it to the board of directors' legal responsibility. It covers a broad cluster of companies in energy, transport, healthcare, digital infrastructure and critical branches of manufacturing.

In forceIn force · 17.10.2024 (transposition into national law)Source · ABl. L 333, 27.12.2022Threshold · Sector + size (medium-sized and above)
In summary

The Directive imposes on “essential” and “important” entities obligations covering risk management measures, supply chain security and strict incident reporting (early warning within 24 hours, notification within 72 hours). The management body is responsible for approving and overseeing the measures; personal liability may arise in the event of a breach.

Overview

NIS2 is the directive that broadens and hardens the EU’s cybersecurity baseline. What sets it apart from its predecessor (NIS1) is a much wider scope, penalties that converge towards those of the GDPR, and responsibility that is expressly tied to the management body.

Scope

In the sectors listed in Annexes I and II (energy, transport, banking, healthcare, drinking water, digital infrastructure, public administration; postal services, waste, chemicals, food, critical branches of manufacturing, digital providers), medium-sized and larger entities are, as a rule, within scope. Entities are classified as “essential” or “important”, and the intensity of oversight varies accordingly.

Core obligations

Companies must implement risk-management measures covering incident handling, business continuity, supply-chain security, access control and encryption; report significant incidents on a staged timeline (24 hours / 72 hours / detailed report); and establish oversight at management level.

Key point for the Turkish side

Turkish companies most often fall within scope through the supply chain: customers in the EU add security requirements, audit rights and incident-notification deadlines to their contracts. IT and legal need to negotiate these terms together.

Roadmap

Scope analysis based on the EU subsidiary and customer portfolio; mapping the existing security framework (ISO 27001, etc.) to NIS2 headings; incident-response and notification arrangements; documenting oversight through board resolutions and training records.

Penalties

For essential entities, administrative fines are provided for with a ceiling of at least EUR 10 million or 2% of global turnover; for important entities, at least EUR 7 million or 1.4%. For members of the management body, personal measures in the event of an oversight breach — up to a temporary ban from holding office — are on the table.

Related content

We address the management-responsibility dimension in our NIS2 analysis and the incident-response framework in our Cybersecurity focus. For data-breach notifications, read it alongside the GDPR and KVKK records.

This record is provided for general information and monitoring only; it does not constitute legal advice or create an attorney–client relationship. The official text in force is authoritative. Contact our team for a scope and compliance assessment specific to your company.
01

Related Practice Areas

We address this regulation together with our expertise in the following practice areas.

02

Focus & Sector Links

This regulation creates a cross-disciplinary focus with a greater impact on certain sectors.

DC
Related Desk · Regional

Data & Cybersecurity Desk

Integrated advice spanning multiple jurisdictions in KVKK and GDPR compliance, cross-border data transfer, and cyber incident response.

Explore the regional desk
Legislation · European Union

EU Cybersecurity Directive (NIS2) — obtain the right legal support.

Let us assess the impact of this regulation on your business and establish a practical compliance framework.