NIS2 is the EU directive on measures for a high common level of cybersecurity across the Union. It entered into force on 16 January 2023, with member states required to transpose it into national law by 17 October 2024, and it replaces the original 2016 NIS Directive — widening both who is regulated and what they must do.
It divides entities into essential and important, across sectors including energy, transport, banking, financial market infrastructure, health, water, digital infrastructure, ICT service management, public administration, space, postal services, waste, chemicals, food, manufacturing and digital providers. The split affects supervision — essential entities face proactive supervision, important entities largely reactive — and the maximum penalty, not the substance of what is required.
Because it is a directive rather than a regulation, the detail varies by member state, and transposition has run at very different speeds. A group operating across several countries faces one set of obligations and several national implementations of them.
The provision that matters most here is Article 21(2)(d): entities are responsible for the security of their direct suppliers and service providers. That makes supply chain security a legal obligation rather than good practice. Our full NIS2 explainer covers scope, the essential-versus-important test and the reporting deadlines in detail.