This is an old revision of the document!
Table of Contents
EU NIS2 and CER Directives (2022)
As of 30 September 2026.
| Full title | Directive (EU) 2022/2555 (NIS2 Directive) and Directive (EU) 2022/2557 (Critical Entities Resilience Directive) |
|---|---|
| Type | EU directives |
| Adopted by | European Parliament and Council of the European Union |
| Adopted | 14 December 2022 |
| Legal status | In force since 16 January 2023; transposition deadline 17 October 2024; binding on Member States as to the result (require national transposition) |
| Official text | EUR-Lex (NIS2) · EUR-Lex (CER) |
| Subject area | Cybersecurity, cybercrime and critical infrastructure |
Overview
The NIS2 Directive sets measures for a high common level of cybersecurity across the Union. It replaces Directive (EU) 2016/1148 (NIS) and extends cybersecurity risk-management and incident-reporting obligations to “essential” and “important” entities in a wide range of sectors, including energy, transport, health, digital infrastructure and public administration. The CER Directive, adopted the same day, addresses the physical and non-cyber resilience of critical entities providing essential services. The two instruments are referred to in debates on the protection of critical infrastructure against cyber and hybrid threats.
Provisions relevant to the cyber and information sphere
- NIS2 Art. 7 – National cybersecurity strategies.
- NIS2 Arts. 9–10 – National cyber crisis management authorities and computer security incident response teams (CSIRTs).
- NIS2 Art. 16 – European cyber crisis liaison organisation network (EU-CyCLONe) for coordinated management of large-scale cybersecurity incidents.
- NIS2 Art. 21 – Cybersecurity risk-management measures, including supply-chain security.
- NIS2 Art. 23 – Staged reporting of significant incidents (early warning within 24 hours, incident notification within 72 hours, final report).
- NIS2 Art. 20 – Management bodies must approve and oversee cybersecurity measures and can be held liable.
- CER Arts. 4–6 – National strategies, risk assessments and identification of critical entities; Arts. 13–15 – resilience measures and incident notification by critical entities.
Application to cyber and information operations
The directives do not address attribution or State responsibility; they regulate preparedness, resilience and incident handling. They form part of the EU's internal framework alongside the external measures of the EU cyber sanctions regime and Cyber Diplomacy Toolbox.
Germany. The NIS2 Directive was transposed by the “Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung” (NIS2UmsuCG) of 2 December 2025, promulgated in BGBl. 2025 I Nr. 301 on 5 December 2025; it entered into force on 6 December 2025 and substantially amends the BSI Act (BSIG). The CER Directive was transposed by the “Gesetz zur Umsetzung der Richtlinie (EU) 2022/2557 und zur Stärkung der Resilienz kritischer Anlagen” (KRITIS-Dachgesetz), of 11 March 2026, promulgated in BGBl. 2026 I Nr. 66 on 16 March 2026; according to the Federal Government it entered into force on 17 March 2026, with certain provisions applying from later dates.
Recent developments
- 2024-10-17: Transposition deadline for both directives.
- 2025-05-07: Commission reasoned opinions to 19 Member States (including Germany) for failure to notify complete transposition of NIS2 (European Commission).
- 2025-12-06: German NIS2UmsuCG enters into force (BGBl. 2025 I Nr. 301).
- 2026-03-16: German KRITIS-Dachgesetz promulgated (BGBl. 2026 I Nr. 66); in force since 17 March 2026.
- 2026-07-08: Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify complete transposition of NIS2 (Commission press release IP/26/1499).
Related entries
Sources
- Directive (EU) 2022/2555 (EUR-Lex), accessed 2026-09-27
- Directive (EU) 2022/2557 (EUR-Lex), accessed 2026-09-27
- BGBl. 2025 I Nr. 301 (NIS2UmsuCG), accessed 2026-09-27
- Federal Ministry of the Interior: NIS2UmsuCG legislative procedure, accessed 2026-09-27
- BGBl. 2026 I Nr. 66 (KRITIS-Dachgesetz), accessed 2026-09-27
- Federal Government: Stärkerer Schutz kritischer Infrastrukturen (KRITIS-Dachgesetz), accessed 2026-09-30
- European Commission: Commission calls on 19 Member States to fully transpose NIS2, accessed 2026-09-27
Change log
- 2026-09-27: Entry created (draft).
- 2026-09-30: Entry reviewed and finalised.
