NIS2 Directive (Directive (EU) 2022/2555)
The EU's horizontal cybersecurity law for critical and important sectors, published in the Official Journal on 27 December 2022 (OJ L 333, 27.12.2022, p. 80), in force since 16 January 2023, with Member State transposition due by 17 October 2024 (Art. 41, not extracted; see Sources). It replaced the original NIS Directive (EU) 2016/1148. This folder reproduces the consolidated text 02022L2555-20221227.
Scope is sector-plus-size: entities in the Annex I/II sectors that meet or exceed the medium-sized-enterprise ceiling (Art. 2(1)), plus categorical inclusions regardless of size (Art. 2(2)–(4)), split into essential and important entities (Art. 3).
Applicability to EdTech
- Education is not a listed sector — schools and EdTech vendors are typically not NIS2 entities as such. The realistic routes in are Annex I point 8 (digital infrastructure), point 9 (ICT service management, B2B) and Annex II point 6 (digital providers) — read the actual entry definitions before assuming cloud-hosted EdTech qualifies (e.g. "cloud computing service" is defined at Art. 6(30)).
- NIS2 reaches suppliers through customers: in-scope entities must address "supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers" (Art. 21(2)(d)) — which is why NIS2-derived security schedules now appear in school-ministry and public-sector procurement even where the school itself is out of scope. The ten-point minimum measure list of Art. 21(2) is the checklist those schedules copy.
- Incident-reporting ladder (Art. 23(4)): early warning within 24 hours, incident notification within 72 hours, final report within one month — timings that flow down contractually to subprocessors.
- Public administration entities are in scope (Art. 2(2)(f), Annex I point 10 public administration), so ministries and regional education authorities running national platforms may themselves be NIS2 entities imposing flow-down terms.
Contents
| Document | Covers |
|---|---|
| SCOPE-AND-ENTITIES.md | Arts. 1–3 — subject matter, scope and size-cap, essential vs important entities |
| DEFINITIONS.md | Art. 6 — definitions |
| RISK-MANAGEMENT-AND-REPORTING.md | Arts. 21, 23 — the minimum measures and the reporting ladder |
| SECTORS.md | Annexes I–II — sectors of high criticality and other critical sectors |
Scope note: governance (Art. 20), registration (Art. 27), jurisdiction (Art. 26), supervision and the fine regimes for essential/important entities (Arts. 31–37) and the cooperation machinery can be added with the same tooling when needed.
Key obligations at a glance
- In-scope entities take "appropriate and proportionate technical, operational and organisational measures" on an all-hazards basis (Art. 21(1)), covering at minimum the ten Art. 21(2) areas.
- Significant incidents: 24h early warning → 72h notification → one-month final report (Art. 23(4)); recipients also notified where appropriate (Art. 23(1)–(2)).
Enforcement
National competent authorities; supervision is ex ante + ex post for essential entities and ex post for important entities, with administrative fines whose national maxima must be at least EUR 10m or 2% of total worldwide annual turnover, whichever is higher (essential entities, Art. 34(4)) and at least EUR 7m or 1,4% (important entities, Art. 34(5)) for Art. 21/23 infringements — Art. 34 is not extracted; wording verified against the consolidated text 2026-09-06.
Related
- EU GDPR — parallel breach-notification duties; NIS2 incident reporting does not displace personal-data-breach notification
- EU AI Act — Art. 21-style security schedules increasingly reference both in procurement
Sources
- EUR-Lex — Directive (EU) 2022/2555 (NIS2), consolidated text 02022L2555-20221227
- ENISA — NIS2 technical implementation guidance
Meta
Article and annex text in the content documents is reproduced verbatim from the EUR-Lex consolidated text (CELEX 02022L2555-20221227) and built/re-verified mechanically by tools/eur-lex/build_eu_nis2.py (verify mode; do not hand-edit). Of the nine corrigenda postdating the consolidation only OJ L 2023/90206 covers English — one word in Article 19(1), not extracted here (checked via Cellar RDF, 2026-09-06). Anchors: official ELI ids plus derived paragraph/point anchors from printed labels. The fine floors in "Enforcement" summarise Arts. 34(4)–(5), which are not extracted — wording checked against the consolidated text on 2026-09-06.