NIS2 (Directive (EU) 2022/2555) sets cybersecurity risk-management and incident-reporting obligations for medium-sized and large organisations in 18 sectors. It is a directive, so the obligations come from each Member State's national law. For you as a buyer the supply chain is the key part. In-scope organisations must take the cybersecurity practices of their direct suppliers and service providers into account (Art. 21(2)(d) and 21(3)), and you will see that in the questions and contract clauses used when buying cloud and software.
Facts and dates last checked: 11 October 2026 · This page gives general information and is not legal advice; check the text of the Directive and your national law for your situation.
The Directive entered into force, twenty days after its publication in the Official Journal on 27 December 2022 (Art. 45).
Deadline for Member States to adopt and publish the transposition measures (Art. 41(1)).
Member States must apply the transposition measures from this date (Art. 41(1)). Implementing Regulation (EU) 2024/2690 is published in the Official Journal on the same day.
Germany: the act transposing NIS2 entered into force, after promulgation on 5 December 2025 (according to the BSI).
The European Commission decides to refer Ireland, Spain, France and the Netherlands to the Court of Justice of the EU for failing to notify measures transposing NIS2.
Netherlands: the Cyberbeveiligingswet (Cybersecurity Act) entered into force.
Who is in scope
NIS2 applies to public or private entities of a type listed in Annex I (sectors of high criticality) or Annex II (other critical sectors) that are medium-sized or larger and that provide services or carry out activities in the Union (Art. 2(1)). Size follows Recommendation 2003/361/EC. Article 3(4) of the Annex to that Recommendation does not apply for NIS2.
Annex I includes energy, transport, banking, health, digital infrastructure, ICT service management (business-to-business) and public administration, among others. Annex II includes postal services, waste management, chemicals, food, manufacturing, digital providers (online marketplaces, search engines, social networking platforms) and research, among others. Digital infrastructure covers, among others, cloud computing, data centre and content delivery network providers; managed service providers and managed security service providers are listed under ICT service management. Software vendors are not listed as such in the annexes.
Essential entities include entities of an Annex I type that exceed the ceilings for medium-sized enterprises, and, regardless of size, qualified trust service providers, top-level domain name registries and DNS service providers (Art. 3(1)). All other entities of an annex type are important entities (Art. 3(2)). Some entities are in scope regardless of size, for example providers of public electronic communications networks or services, trust service providers, the sole provider of an essential service in a Member State, and domain name registration services (Art. 2(2) to (4)). For essential entities, supervision includes regular and targeted security audits (Art. 32(2)). For important entities, supervision is ex post (Art. 33).
What the Directive requires of organisations
The management body of an essential or important entity approves the cybersecurity risk-management measures, oversees their implementation and can be held liable for infringements of Art. 21 (Art. 20(1)). Members of management bodies must follow training so that they can identify risks and assess cybersecurity practices (Art. 20(2)).
Art. 21 requires appropriate and proportionate technical, operational and organisational measures based on an all-hazards approach, covering at least ten areas (Art. 21(1) and (2)(a) to (j)). For buyers of software and cloud services these are the most relevant, together with reporting and fines:
Supply chain security, including security-related aspects of the relationships with direct suppliers and service providers (Art. 21(2)(d)).
When choosing those measures, the entity takes into account the vulnerabilities specific to each direct supplier, the overall quality of their products and their cybersecurity practices, including secure development procedures, and the results of coordinated security risk assessments of critical supply chains at Union level (Art. 21(3), Art. 22(1)).
Security in the acquisition, development and maintenance of systems, including vulnerability handling and disclosure (Art. 21(2)(e)).
Business continuity, such as backup management and disaster recovery (Art. 21(2)(c)), and policies on cryptography and, where appropriate, encryption (Art. 21(2)(h)).
Reporting: a significant incident is notified to the CSIRT or competent authority with an early warning within 24 hours of becoming aware, an incident notification within 72 hours, an intermediate report on request, and a final report no later than one month after the incident notification (Art. 23(4)). Where appropriate, entities also inform the recipients of their services (Art. 23(1)).
Fines: for infringements of Art. 21 or 23, Member States must provide for maxima of at least EUR 10 million or 2 % of total worldwide annual turnover of the undertaking the essential entity belongs to, whichever is higher, and for important entities at least EUR 7 million or 1.4 % (Art. 34(4) and (5)). National law sets the final amounts.
Transposition status in the Member States
Member States had to adopt and publish transposition measures by 17 October 2024 and apply them from 18 October 2024 (Art. 41(1)). On 8 July 2026 the European Commission decided to refer Ireland, Spain, France and the Netherlands to the Court of Justice of the EU for failing to notify measures transposing NIS2. Because NIS2 is a directive and Member States may maintain a higher level of cybersecurity (Art. 5), national rules can differ. Status on 11 October 2026 for four countries:
Netherlands: the Cyberbeveiligingswet (Cbw) entered into force on 15 August 2026 and replaces the Wbni, according to the Dutch government.
Germany: the Bundestag passed the transposition act (NIS2UmsuCG) on 13 November 2025 and the Bundesrat on 21 November 2025. It was promulgated on 5 December 2025 and entered into force on 6 December 2025. Entities register with the BSI no later than three months after they fall within the act (§ 33 BSIG).
France: the bill on the resilience of critical infrastructure and the strengthening of cybersecurity was adopted by the Senate on 12 March 2025 and is at first reading in the Assemblée nationale. According to the file it has not been finally adopted or promulgated. The Conférence des présidents of 6 October 2026 removed the bill from the agenda of 7 and 9 October.
For other Member States, check the national law and the national supervisory authority.
What this means when you choose cloud and software vendors
NIS2 does not bind your vendor directly unless the vendor is itself in scope, for example as a cloud computing, data centre or managed service provider. The obligation sits with the entity that buys: it secures its supply chain and takes the practices of its direct suppliers into account (Art. 21(2)(d) and 21(3)).
Implementing Regulation (EU) 2024/2690, published on 18 October 2024, sets out the technical requirements of Art. 21(2) for, among others, DNS service providers, cloud computing, data centre and content delivery network providers, managed service providers, managed security service providers, online marketplaces, search engines and social networking platforms, and specifies when an incident is significant for them (Art. 1 and 3). Their supply chain security policy includes supplier selection criteria: cybersecurity practices, quality and resilience of products and services, and the ability to diversify sources of supply and limit vendor lock-in (point 5.1.2). They set requirements in contracts (point 5.1.4), keep a register of direct suppliers (point 5.2) and review suppliers at planned intervals (point 5.1.6). The Annex is not directly binding on other organisations, but you can use its points as a checklist:
Is the vendor itself in scope of NIS2 (cloud, data centre, managed service), in which Member State, and can it show that?
Incidents: does the contract oblige the vendor to notify you without undue delay of incidents that present a risk to your network and information systems (point 5.1.4(d))? You need that to meet the deadlines of Art. 23(4) yourself.
Audit: do you have the right to audit or to receive audit reports (point 5.1.4(e))?
Secure development and vulnerabilities: how is software developed, and how are vulnerabilities handled and disclosed (Art. 21(2)(e), Art. 21(3), point 5.1.4(f))?
Subcontractors: which sub-processors and subcontractors are used, and which security requirements apply to them (point 5.1.4(g))?
Exit: what happens to your data at the end of the contract, such as retrieval and disposal (point 5.1.4(h)), and how do you limit dependence on a single vendor (point 5.1.2(d))?
Updates and components: how long are security updates provided, or when must you replace the product, and can you get a description of the hardware and software components used (point 6.1.2(b) and (c))?
Continuity and encryption: which backup and recovery measures apply, and who manages the keys (Art. 21(2)(c) and (h))?
NIS2 alongside the CRA, DORA and the GDPR
The CRA (Regulation (EU) 2024/2847) sets requirements for products with digital elements and their manufacturers. NIS2 concerns the risk management of entities. According to recital 12 of the CRA, NIS2 applies to cloud computing services, including SaaS, PaaS and IaaS, and according to recital 13 Member States can, under NIS2, impose additional cybersecurity requirements on ICT products used by essential and important entities.
According to recital 28 of NIS2, DORA (Regulation (EU) 2022/2554) is a sector-specific Union legal act for financial entities. The DORA provisions on ICT risk management, ICT-related incident reporting, testing and ICT third-party risk then apply instead of the NIS2 provisions on risk management, reporting and supervision. Art. 4 describes when sector-specific requirements are equivalent.
Where an infringement of Art. 21 or 23 can entail a personal data breach, the competent authority informs the GDPR supervisory authority. If that authority has imposed a fine for the same conduct, the NIS2 authority does not impose a fine under Art. 34 for it (Art. 35).
How this relates to digital sovereignty and the five score dimensions
The text of Art. 21(3) does not refer to the country in which a supplier is established. The Directive asks you to look at vulnerabilities, products and cybersecurity practices. The coordinated risk assessments at Union level may take into account technical and, where relevant, non-technical risk factors (Art. 22(1)).
The score touches on a few topics that NIS2 names. Cryptography and encryption (Art. 21(2)(h)) relate to cryptographic key sovereignty (CKS). Limiting lock-in and retrieving data at the end of a contract (points 5.1.2(d) and 5.1.4(h) of the implementing regulation) relate to portability (PLS). Where data is hosted and where a vendor and its parent are established (DRS and JES), and whether software is open source or self-hostable (SRS), are not named as such in Art. 21. You can include them in your own risk assessment. The score is not a NIS2 compliance assessment and does not show that you or a vendor comply with the Directive.
Want to know how your own software stack scores on digital sovereignty? Take the free assessment.
It depends on the type of organisation, the sector and the size. The type must be listed in Annex I or II and the organisation must be at least medium-sized, unless an exception for smaller entities applies (Art. 2). Check the national law and the supervisory authority in your country.
Is my cloud vendor responsible for my compliance?
No, the obligations of Art. 21 sit with the essential or important entity itself. A cloud provider can also be in scope itself, because cloud computing service providers are listed in Annex I.
How quickly must an incident be reported?
An early warning within 24 hours of becoming aware of the significant incident, an incident notification within 72 hours and a final report no later than one month after that notification (Art. 23(4)).
What are the fines?
For infringements of Art. 21 or 23, Member States must provide for maxima of at least EUR 10 million or 2 % of worldwide annual turnover for essential entities, and at least EUR 7 million or 1.4 % for important entities (Art. 34(4) and (5)).
Can managers be held liable?
The management body approves the security measures, oversees them and can be held liable for infringements of Art. 21 (Art. 20(1)). National rules on public institutions and public servants remain unaffected.
Have all Member States transposed NIS2?
Not all. On 8 July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice. The Netherlands and Germany have since had their laws enter into force; in France the bill is still before parliament.