Back to briefings
    Briefing

    NIS2 for the security officer

    Directive (EU) 2022/2555 in one pass: the scope test, the obligations by article, the reporting clock, the fine ceilings and a mapping to ISO 27001 Annex A.

    Compliance3 Sept 20269 min read

    Directive (EU) 2022/2555ISO/IEC 27001:2022
    On this page

    What it is

    NIS2 is Directive (EU) 2022/2555, on measures for a high common level of cybersecurity across the Union. It was published in Official Journal L 333 of 27 December 2022, page 80 1. It repealed Directive (EU) 2016/1148 from 18 October 2024 2.

    A directive binds Member States, not entities. What an organisation obeys is the national act that transposes it. The Directive fixes the floor; the national law carries the authority, the detail and the penalty regime. In Sweden that act is Cybersäkerhetslag (2025:1506) 3.

    For a security officer the Directive has four moving parts. Articles 2 and 3 decide scope and class. Article 21 lists the measures. Article 23 sets the reporting clock. Chapter VII carries supervision, enforcement and the fine ceilings.

    Who is in scope (decision test)

    Steps 1 to 3 decide whether the Directive reaches the organisation; steps 4 and 5, what follows.

    1. Sector. Is the entity of a type listed in Annex I or Annex II? Annex I, sectors of high criticality, names eleven: energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management (business-to-business), public administration, space. Annex II, other critical sectors, names seven: postal and courier services, waste management, chemicals, food, manufacturing, digital providers, research 4. If neither, go to step 3.
    2. Size. Article 2(1) reaches entities of those types that qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC, or exceed those ceilings 5. That Annex sets the SME category at fewer than 250 persons, turnover at or below EUR 50 million and/or a balance sheet at or below EUR 43 million. Small is fewer than 50 persons at EUR 10 million 6. Medium-sized is the band that remains. Article 2(1) also disapplies Article 3(4) of that Annex, so public control of 25 % or more does not remove SME status here.
    3. Size-independent hooks. Article 2(2) to 2(4) also catches, whatever the size 7:
      • public electronic communications networks or services, trust service providers, TLD name registries and DNS service providers;
      • the sole provider in a Member State of an essential service;
      • entities whose disruption could significantly affect public safety, security or health, or induce systemic risk;
      • entities critical at national or regional level;
      • central-government bodies;
      • critical entities under Directive (EU) 2022/2557, and domain name registration services.
    4. Class. Article 3(1) makes an entity essential where it is an Annex I type above the medium-sized ceilings. The same holds for qualified trust service providers, TLD name registries, DNS service providers, central-government bodies, and critical entities under Directive (EU) 2022/2557. Everything else in either annex is important 8.
    5. Jurisdiction. Article 26 places an entity under the Member State where it is established. Electronic communications providers answer where they serve; the listed digital categories, where cybersecurity decisions are predominantly taken 9.
    OutcomeWhat it meansNext step
    In scopeArticles 20, 21 and 23 apply. Essential entities are supervised ex ante under Article 32, important entities ex post under Article 33Register with the authority, then close Article 21 gaps in risk order
    Out of scopeNo duty of its own, but customers inside scope push Article 21(2)(d) expectations down by contractAnswer supplier questions from the same control set; re-run after a service change
    Needs legal inputThe sector fit, the size calculation across linked enterprises, or the jurisdiction rule is arguableWrite the analysis down, an article per step, and have counsel confirm

    Obligations by article

    Article / clauseObligationWhat it means in practiceEvidence
    Art. 20Management bodies approve the Article 21 measures, oversee implementation, are liable for infringements, and must follow training 10A decision of the body itself; board training is separate from staff awarenessMinuted approval; training record per member
    Art. 21(1)Measures proportionate to state of the art, cost, exposure and size 11Proportionality is argued from the risk assessmentRisk assessment carrying the argument
    Art. 21(2)Ten measures, all-hazards, covering the physical environment of the systems 12A minimum, not a ceilingStatement of applicability mapped to (a) to (j)
    Art. 21(3), 21(4)Weigh each supplier's vulnerabilities and secure development; correct self-found gaps promptly 13A returned questionnaire is not the measureSupplier assessments; corrective-action log
    Art. 23(1), 23(3)Notify significant incidents promptly. Significant means severe disruption, financial loss or considerable damage to others 14Someone judges significance under pressureWritten criteria; a decision record
    Art. 23(4)Early warning within 24 hours of awareness, notification within 72 hours, final report one month later 15The clock starts at awareness. Trust service providers report at 24 hoursTimestamped submissions; the awareness record
    Art. 24Member States may require certification under a scheme adopted under Regulation (EU) 2019/881 16A national option, not a Union dutyWatch item on the regulatory register
    Art. 32, Art. 33Inspections, audits, security scans; authorities may suspend an authorisation or bar a chief executive 17Class sets how ready evidence must beAn evidence index an inspector walks alone
    Art. 34(4), 34(5)Essential entities: at least EUR 10 000 000 or 2 % of worldwide annual turnover, whichever is higher. Important entities: EUR 7 000 000 or 1,4 % 18Floors on the national maximumThe transposing act's penalties

    Dates (verified)

    DateWhat happensSource
    2023-01-16Entry into force, twenty days after publication19
    2024-10-17Transposition deadline; implementing acts for the listed digital categories due20
    2024-10-18Member States apply the measures; Directive (EU) 2016/1148 repealed21
    2025-01-17Listed digital entities submit registry information22
    2025-04-17Member States establish the list of essential and important entities23
    2026-01-15Cybersäkerhetslag (2025:1506), issued 11 December 2025, takes effect and repeals lagen (2018:1174)3

    The Swedish act took effect fifteen months after the transposition deadline. Under it an operator registers with the designated authority as soon as that can be done, and reports changed particulars within fourteen days 24.

    Mapping to ISO 27001 Annex A / NIST CSF

    A certified management system answers most of Article 21(2) already. The last column is the one worth reading.

    Art. 21(2)MeasureISO/IEC 27001:2022 Annex ANIST CSF 2.0Gap
    (a)Risk analysis and security policiesA.5.1 Policies for information security; A.5.2 Information security roles and responsibilitiesGOVERNAll-hazards scope pulls physical risk into the register
    (b)Incident handlingA.5.24 Information security incident management planning and preparation, through A.5.28 Collection of evidenceRESPONDThe Article 23 clock and significance test
    (c)Continuity, backup, recovery, crisis managementA.5.29 Information security during disruption; A.5.30 ICT readiness for business continuityRECOVERCrisis management above the ICT layer
    (d)Supply chain securityA.5.19 Information security in supplier relationships, through A.5.22 Monitoring, review and change management of supplier servicesGOVERNArticle 21(3) per-supplier judgement
    (e)Acquisition, development, maintenance; vulnerability handlingISO/IEC 27002:2022 Clause 8, Technological controlsPROTECTA disclosure route reaching the CSIRT
    (f)Assessing effectiveness of the measuresA.5.35 Independent review of information security; A.5.36 Compliance with policies, rules and standardsGOVERNEvidence that a measurement changed something
    (g)Cyber hygiene and trainingA.6.3 Information security awareness, education and trainingPROTECTArticle 20(2) training for the management body
    (h)Cryptography and encryptionISO/IEC 27002:2022 Clause 8, Technological controlsPROTECTKey management evidence
    (i)HR security, access control, asset managementA.5.15 Access control, through A.5.18 Access rights; A.6.1 ScreeningPROTECT, IDENTIFYAn ISMS boundary narrower than the service
    (j)Multi-factor authentication; secured and emergency communicationsA.5.14 Information transfer; Clause 8, Technological controlsPROTECTEmergency communication surviving loss of the estate
    Article 21(2) points (a) to (j) against ISO/IEC 27001:2022 Annex A and NIST CSF 2.0

    Control titles come from the contents of ISO/IEC 27002:2022 on the ISO Online Browsing Platform 25. That public listing stops at 8.1, so points (e), (h) and (j) are cited at clause level. The framework functions are GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND and RECOVER 26.

    Next 90 days

    WeekActionOwnerOutput
    1-2Run the scope test above and write the answer down, step by stepSecurity officerScope memo, one citation per step
    3-4Map the control set onto Article 21(2): met, partial or absentSecurity officerGap list ranked by risk
    3-4Rewrite the incident runbook around 24 hours, 72 hours and one monthIncident managerRunbook with the significance criteria
    5-6Put the measures and the gap list to the management body under Article 20Management bodyMinuted approval of the measure set
    5-6Book Article 20 training for management-body membersSecurity officerAttendance record per member
    7-8Tier direct suppliers and assess the top tier against Article 21(3)ProcurementAssessments with re-assessment triggers
    9-10Exercise the reporting chain end to end, timing the awareness decisionIncident managerExercise report, clock measured
    11-12Assemble the evidence index an inspector would walk under Article 32Security officerOne index, an owner per artefact

    References

    1. European Parliament and Council. Directive (EU) 2022/2555. CELEX 32022L2555. https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng
    2. European Commission. Recommendation 2003/361/EC concerning the definition of micro, small and medium-sized enterprises. CELEX 32003H0361. https://publications.europa.eu/resource/celex/32003H0361
    3. Sveriges riksdag. Cybersäkerhetslag (2025:1506). https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/cybersakerhetslag-20251506_sfs-2025-1506/
    4. ISO/IEC. ISO/IEC 27002:2022, contents. ISO Online Browsing Platform. https://www.iso.org/obp/ui/en/#iso:std:iso-iec:27002:ed-3:v2:en
    5. NIST. The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29. https://doi.org/10.6028/NIST.CSWP.29

    Sources

    1. 1EUR-Lex CELEX 32022L2555 OJ L 333/80 · verified 2026-09-03
    2. 2EUR-Lex CELEX 32022L2555 Art. 44 · verified 2026-09-03
    3. 3riksdagen.se SFS 2025:1506 · verified 2026-09-03
    4. 4EUR-Lex CELEX 32022L2555 sector annexes · verified 2026-09-03
    5. 5EUR-Lex CELEX 32022L2555 Art. 2(1) · verified 2026-09-03
    6. 6EU Publications Office CELEX 32003H0361 Annex Art. 2 · verified 2026-09-03
    7. 7EUR-Lex CELEX 32022L2555 Art. 2(2)-(4) · verified 2026-09-03
    8. 8EUR-Lex CELEX 32022L2555 Art. 3(1)-(2) · verified 2026-09-03
    9. 9EUR-Lex CELEX 32022L2555 Art. 26 · verified 2026-09-03
    10. 10EUR-Lex CELEX 32022L2555 Art. 20 · verified 2026-09-03
    11. 11EUR-Lex CELEX 32022L2555 Art. 21(1) · verified 2026-09-03
    12. 12EUR-Lex CELEX 32022L2555 Art. 21(2) · verified 2026-09-03
    13. 13EUR-Lex CELEX 32022L2555 Art. 21(3)-(4) · verified 2026-09-03
    14. 14EUR-Lex CELEX 32022L2555 Art. 23(1) and 23(3) · verified 2026-09-03
    15. 15EUR-Lex CELEX 32022L2555 Art. 23(4) · verified 2026-09-03
    16. 16EUR-Lex CELEX 32022L2555 Art. 24 · verified 2026-09-03
    17. 17EUR-Lex CELEX 32022L2555 Art. 32 and 33 · verified 2026-09-03
    18. 18EUR-Lex CELEX 32022L2555 Art. 34(4)-(5) · verified 2026-09-03
    19. 19EUR-Lex CELEX 32022L2555 Art. 45 and 38(2) · verified 2026-09-03
    20. 20EUR-Lex CELEX 32022L2555 Art. 41(1) and 21(5) · verified 2026-09-03
    21. 21EUR-Lex CELEX 32022L2555 Art. 41(1) and 44 · verified 2026-09-03
    22. 22EUR-Lex CELEX 32022L2555 Art. 27(2) · verified 2026-09-03
    23. 23EUR-Lex CELEX 32022L2555 Art. 3(3) · verified 2026-09-03
    24. 24riksdagen.se SFS 2025:1506 2 kap. 2 § · verified 2026-09-03
    25. 25ISO OBP ISO/IEC 27002:2022 contents · verified 2026-09-03
    26. 26nvlpubs.nist.gov NIST CSWP 29 CSF 2.0 Core Functions · verified 2026-09-03