====== EU NIS2 and CER Directives (2022) ====== //As of 30 September 2026. Information only, not legal advice – see the [[about:disclaimer|disclaimer]].// ^ Full title | Directive (EU) 2022/2555 (NIS2 Directive) and Directive (EU) 2022/2557 (Critical Entities Resilience Directive) | ^ Type | EU directives | ^ Adopted by | European Parliament and Council of the European Union | ^ Adopted | 14 December 2022 | ^ Legal status | In force since 16 January 2023; transposition deadline 17 October 2024; binding on Member States as to the result (require national transposition) | ^ Official text | [[https://eur-lex.europa.eu/eli/dir/2022/2555/oj|EUR-Lex (NIS2)]] · [[https://eur-lex.europa.eu/eli/dir/2022/2557/oj|EUR-Lex (CER)]] | ^ Subject area | Cybersecurity, cybercrime and critical infrastructure | ===== Overview ===== The NIS2 Directive sets measures for a high common level of cybersecurity across the Union. It replaces Directive (EU) 2016/1148 (NIS) and extends cybersecurity risk-management and incident-reporting obligations to "essential" and "important" entities in a wide range of sectors, including energy, transport, health, digital infrastructure and public administration. The CER Directive, adopted the same day, addresses the physical and non-cyber resilience of critical entities providing essential services. The two instruments are referred to in debates on the protection of critical infrastructure against cyber and hybrid threats. ===== Provisions relevant to the cyber and information sphere ===== * **NIS2 Art. 7** – National cybersecurity strategies. * **NIS2 Arts. 9–10** – National cyber crisis management authorities and computer security incident response teams (CSIRTs). * **NIS2 Art. 16** – European cyber crisis liaison organisation network (EU-CyCLONe) for coordinated management of large-scale cybersecurity incidents. * **NIS2 Art. 21** – Cybersecurity risk-management measures, including supply-chain security. * **NIS2 Art. 23** – Staged reporting of significant incidents (early warning within 24 hours, incident notification within 72 hours, final report). * **NIS2 Art. 20** – Management bodies must approve and oversee cybersecurity measures and can be held liable. * **CER Arts. 4–6** – National strategies, risk assessments and identification of critical entities; **Arts. 13–15** – resilience measures and incident notification by critical entities. ===== Application to cyber and information operations ===== The directives do not address attribution or State responsibility; they regulate preparedness, resilience and incident handling. They form part of the EU's internal framework alongside the external measures of the [[law:eu:cyber_sanctions|EU cyber sanctions regime and Cyber Diplomacy Toolbox]]. **Germany.** The NIS2 Directive was transposed by the "Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung" (NIS2UmsuCG) of 2 December 2025, promulgated in BGBl. 2025 I Nr. 301 on 5 December 2025; it entered into force on 6 December 2025 and substantially amends the BSI Act (BSIG). The CER Directive was transposed by the "Gesetz zur Umsetzung der Richtlinie (EU) 2022/2557 und zur Stärkung der Resilienz kritischer Anlagen" (KRITIS-Dachgesetz), of 11 March 2026, promulgated in BGBl. 2026 I Nr. 66 on 16 March 2026; according to the Federal Government it entered into force on 17 March 2026, with certain provisions applying from later dates. ===== Recent developments ===== * 2024-10-17: Transposition deadline for both directives. * 2025-05-07: Commission reasoned opinions to 19 Member States (including Germany) for failure to notify complete transposition of NIS2 (European Commission). * 2025-12-06: German NIS2UmsuCG enters into force (BGBl. 2025 I Nr. 301). * 2026-03-16: German KRITIS-Dachgesetz promulgated (BGBl. 2026 I Nr. 66); in force since 17 March 2026. * 2026-07-08: Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify complete transposition of NIS2 (Commission press release IP/26/1499). ===== Related entries ===== * [[law:eu:cyber_sanctions]] * [[law:un:ict_norms]] * [[law:national:germany]] * [[gaps:nc3]] * [[law:eu:cyber_resilience_act]] ===== Sources ===== * [[https://eur-lex.europa.eu/eli/dir/2022/2555/oj|Directive (EU) 2022/2555 (EUR-Lex)]], accessed 2026-09-27 * [[https://eur-lex.europa.eu/eli/dir/2022/2557/oj|Directive (EU) 2022/2557 (EUR-Lex)]], accessed 2026-09-27 * [[https://www.recht.bund.de/bgbl/1/2025/301/VO.html|BGBl. 2025 I Nr. 301 (NIS2UmsuCG)]], accessed 2026-09-27 * [[https://www.bmi.bund.de/SharedDocs/gesetzgebungsverfahren/DE/CI1/nis2umsucg.html|Federal Ministry of the Interior: NIS2UmsuCG legislative procedure]], accessed 2026-09-27 * [[https://www.recht.bund.de/bgbl/1/2026/66/VO.html|BGBl. 2026 I Nr. 66 (KRITIS-Dachgesetz)]], accessed 2026-09-27 * [[https://www.bundesregierung.de/breg-de/aktuelles/kritis-dachgesetz-2383682|Federal Government: Stärkerer Schutz kritischer Infrastrukturen (KRITIS-Dachgesetz)]], accessed 2026-09-30 * [[https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1499|European Commission: Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose the rules on cybersecurity (IP/26/1499)]], accessed 2026-09-30 * [[https://digital-strategy.ec.europa.eu/en/news/commission-calls-19-member-states-fully-transpose-nis2-directive|European Commission: Commission calls on 19 Member States to fully transpose NIS2]], accessed 2026-09-27 ===== Change log ===== * 2026-09-27: Entry created (draft). * 2026-09-30: Entry reviewed and finalised. * 2026-10-01: Cross-reference to the Cyber Resilience Act added.