LawyersForPeace.Online

a curated map of the law of peace in the cyber & information sphere

User Tools

Site Tools


law:eu:nis2_cer

This is an old revision of the document!


Directive (EU) 2022/2555 (NIS2 Directive) and Directive (EU) 2022/2557 (Critical Entities Resilience Directive)

Draft – editorial review pending. As of 27 September 2026.

Type EU directives
Adopted by European Parliament and Council of the European Union
Adopted 14 December 2022
Legal status In force since 16 January 2023; transposition deadline 17 October 2024; binding on Member States as to the result (require national transposition)
Official text EUR-Lex (NIS2) · EUR-Lex (CER)
Subject area Cybersecurity, cybercrime and critical infrastructure

Overview

The NIS2 Directive sets measures for a high common level of cybersecurity across the Union. It replaces Directive (EU) 2016/1148 (NIS) and extends cybersecurity risk-management and incident-reporting obligations to “essential” and “important” entities in a wide range of sectors, including energy, transport, health, digital infrastructure and public administration. The CER Directive, adopted the same day, addresses the physical and non-cyber resilience of critical entities providing essential services. The two instruments are referred to in debates on the protection of critical infrastructure against cyber and hybrid threats.

Provisions relevant to the cyber and information sphere

  • NIS2 Art. 7 – National cybersecurity strategies.
  • NIS2 Arts. 9–10 – National cyber crisis management authorities and computer security incident response teams (CSIRTs).
  • NIS2 Art. 16 – European cyber crisis liaison organisation network (EU-CyCLONe) for coordinated management of large-scale cybersecurity incidents.
  • NIS2 Art. 21 – Cybersecurity risk-management measures, including supply-chain security.
  • NIS2 Art. 23 – Staged reporting of significant incidents (early warning within 24 hours, incident notification within 72 hours, final report).
  • NIS2 Art. 20 – Management bodies must approve and oversee cybersecurity measures and can be held liable.
  • CER Arts. 4–6 – National strategies, risk assessments and identification of critical entities; Arts. 13–15 – resilience measures and incident notification by critical entities.

Application to cyber and information operations

The directives do not address attribution or State responsibility; they regulate preparedness, resilience and incident handling. They form part of the EU's internal framework alongside the external measures of the EU cyber sanctions regime and Cyber Diplomacy Toolbox.

Germany. The NIS2 Directive was transposed by the “Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung” (NIS2UmsuCG) of 2 December 2025, promulgated in BGBl. 2025 I Nr. 301 on 5 December 2025; it entered into force on 6 December 2025 and substantially amends the BSI Act (BSIG). The CER Directive was transposed by the “Gesetz zur Umsetzung der Richtlinie (EU) 2022/2557 und zur Stärkung der Resilienz kritischer Anlagen” (KRITIS-Dachgesetz), promulgated in BGBl. 2026 I Nr. 66 on 16 March 2026 [to be verified: entry-into-force date(s)].

Recent developments

  • 2024-10-17: Transposition deadline for both directives.
  • 2025-05-07: Commission reasoned opinions to 19 Member States (including Germany) for failure to notify complete transposition of NIS2 (European Commission).
  • 2025-12-06: German NIS2UmsuCG enters into force (BGBl. 2025 I Nr. 301).
  • 2026-03-16: German KRITIS-Dachgesetz promulgated (BGBl. 2026 I Nr. 66).
  • 2026-07: Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failure to notify complete transposition of NIS2 [to be verified against official Commission release].

Sources

Change log

  • 2026-09-27: Entry created (draft).
law/eu/nis2_cer.1790536042.txt.gz · Last modified: by lfpo