WorldPrivacyAtlas
Laws by country

Sector-Specific Law

Directive on measures for a high common level of cybersecurity across the Union (NIS2)

NIS2 Directive

European Union · October 18, 2024 (repeal of the original NIS Directive); binding through national transposing laws, several of which landed late

NIS2 requires 'essential' and 'important' entities across roughly eighteen sectors (Annexes I and II) to adopt baseline cybersecurity risk-management measures, report significant incidents on a three-step clock — a 24-hour early warning, a 72-hour notification, and a final report within one month — and hold management bodies personally accountable for cybersecurity oversight. Scope is generally size-capped at medium and large entities, with size-independent categories for certain providers. Two caveats matter for anyone reading this page. First, it is a Directive: the binding text is each member state's transposing law, and most states missed the October 17, 2024 deadline, prompting Commission infringement proceedings — so the operative rules and their commencement dates differ by country and should be checked per member state rather than assumed uniform. Second, this atlas's questionnaire can only detect two of NIS2's sectors (health, and banking/financial market infrastructure), so a non-match here is not a determination that NIS2 does not apply to you — check Annexes I and II directly, particularly if you are a cloud, managed service, data centre, online marketplace, or search provider.

Directive (EU) 2022/2555; national transposing laws (transposition deadline October 17, 2024)Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.