NIS2 for the security officer
Directive (EU) 2022/2555 in one pass: the scope test, the obligations by article, the reporting clock, the fine ceilings and a mapping to ISO 27001 Annex A.
Compliance3 Sept 20269 min read
On this page
What it is
NIS2 is Directive (EU) 2022/2555, on measures for a high common level of cybersecurity across the Union. It was published in Official Journal L 333 of 27 December 2022, page 80 1. It repealed Directive (EU) 2016/1148 from 18 October 2024 2.
A directive binds Member States, not entities. What an organisation obeys is the national act that transposes it. The Directive fixes the floor; the national law carries the authority, the detail and the penalty regime. In Sweden that act is Cybersäkerhetslag (2025:1506) 3.
For a security officer the Directive has four moving parts. Articles 2 and 3 decide scope and class. Article 21 lists the measures. Article 23 sets the reporting clock. Chapter VII carries supervision, enforcement and the fine ceilings.
Who is in scope (decision test)
Steps 1 to 3 decide whether the Directive reaches the organisation; steps 4 and 5, what follows.
- Sector. Is the entity of a type listed in
Annex IorAnnex II?Annex I, sectors of high criticality, names eleven: energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management (business-to-business), public administration, space.Annex II, other critical sectors, names seven: postal and courier services, waste management, chemicals, food, manufacturing, digital providers, research 4. If neither, go to step 3. - Size. Article 2(1) reaches entities of those types that qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC, or exceed those ceilings 5. That Annex sets the SME category at fewer than 250 persons, turnover at or below EUR 50 million and/or a balance sheet at or below EUR 43 million. Small is fewer than 50 persons at EUR 10 million 6. Medium-sized is the band that remains. Article 2(1) also disapplies Article 3(4) of that Annex, so public control of 25 % or more does not remove SME status here.
- Size-independent hooks. Article 2(2) to 2(4) also catches, whatever the size
7:
- public electronic communications networks or services, trust service providers, TLD name registries and DNS service providers;
- the sole provider in a Member State of an essential service;
- entities whose disruption could significantly affect public safety, security or health, or induce systemic risk;
- entities critical at national or regional level;
- central-government bodies;
- critical entities under Directive (EU) 2022/2557, and domain name registration services.
- Class. Article 3(1) makes an entity essential where it is an
Annex Itype above the medium-sized ceilings. The same holds for qualified trust service providers, TLD name registries, DNS service providers, central-government bodies, and critical entities under Directive (EU) 2022/2557. Everything else in either annex is important 8. - Jurisdiction. Article 26 places an entity under the Member State where it is established. Electronic communications providers answer where they serve; the listed digital categories, where cybersecurity decisions are predominantly taken 9.
| Outcome | What it means | Next step |
|---|---|---|
| In scope | Articles 20, 21 and 23 apply. Essential entities are supervised ex ante under Article 32, important entities ex post under Article 33 | Register with the authority, then close Article 21 gaps in risk order |
| Out of scope | No duty of its own, but customers inside scope push Article 21(2)(d) expectations down by contract | Answer supplier questions from the same control set; re-run after a service change |
| Needs legal input | The sector fit, the size calculation across linked enterprises, or the jurisdiction rule is arguable | Write the analysis down, an article per step, and have counsel confirm |
Obligations by article
| Article / clause | Obligation | What it means in practice | Evidence |
|---|---|---|---|
| Art. 20 | Management bodies approve the Article 21 measures, oversee implementation, are liable for infringements, and must follow training 10 | A decision of the body itself; board training is separate from staff awareness | Minuted approval; training record per member |
| Art. 21(1) | Measures proportionate to state of the art, cost, exposure and size 11 | Proportionality is argued from the risk assessment | Risk assessment carrying the argument |
| Art. 21(2) | Ten measures, all-hazards, covering the physical environment of the systems 12 | A minimum, not a ceiling | Statement of applicability mapped to (a) to (j) |
| Art. 21(3), 21(4) | Weigh each supplier's vulnerabilities and secure development; correct self-found gaps promptly 13 | A returned questionnaire is not the measure | Supplier assessments; corrective-action log |
| Art. 23(1), 23(3) | Notify significant incidents promptly. Significant means severe disruption, financial loss or considerable damage to others 14 | Someone judges significance under pressure | Written criteria; a decision record |
| Art. 23(4) | Early warning within 24 hours of awareness, notification within 72 hours, final report one month later 15 | The clock starts at awareness. Trust service providers report at 24 hours | Timestamped submissions; the awareness record |
| Art. 24 | Member States may require certification under a scheme adopted under Regulation (EU) 2019/881 16 | A national option, not a Union duty | Watch item on the regulatory register |
| Art. 32, Art. 33 | Inspections, audits, security scans; authorities may suspend an authorisation or bar a chief executive 17 | Class sets how ready evidence must be | An evidence index an inspector walks alone |
| Art. 34(4), 34(5) | Essential entities: at least EUR 10 000 000 or 2 % of worldwide annual turnover, whichever is higher. Important entities: EUR 7 000 000 or 1,4 % 18 | Floors on the national maximum | The transposing act's penalties |
Dates (verified)
| Date | What happens | Source |
|---|---|---|
| 2023-01-16 | Entry into force, twenty days after publication | 19 |
| 2024-10-17 | Transposition deadline; implementing acts for the listed digital categories due | 20 |
| 2024-10-18 | Member States apply the measures; Directive (EU) 2016/1148 repealed | 21 |
| 2025-01-17 | Listed digital entities submit registry information | 22 |
| 2025-04-17 | Member States establish the list of essential and important entities | 23 |
| 2026-01-15 | Cybersäkerhetslag (2025:1506), issued 11 December 2025, takes effect and repeals lagen (2018:1174) | 3 |
The Swedish act took effect fifteen months after the transposition deadline. Under it an operator registers with the designated authority as soon as that can be done, and reports changed particulars within fourteen days 24.
Mapping to ISO 27001 Annex A / NIST CSF
A certified management system answers most of Article 21(2) already. The last column is the one worth reading.
| Art. 21(2) | Measure | ISO/IEC 27001:2022 Annex A | NIST CSF 2.0 | Gap |
|---|---|---|---|---|
| (a) | Risk analysis and security policies | A.5.1 Policies for information security; A.5.2 Information security roles and responsibilities | GOVERN | All-hazards scope pulls physical risk into the register |
| (b) | Incident handling | A.5.24 Information security incident management planning and preparation, through A.5.28 Collection of evidence | RESPOND | The Article 23 clock and significance test |
| (c) | Continuity, backup, recovery, crisis management | A.5.29 Information security during disruption; A.5.30 ICT readiness for business continuity | RECOVER | Crisis management above the ICT layer |
| (d) | Supply chain security | A.5.19 Information security in supplier relationships, through A.5.22 Monitoring, review and change management of supplier services | GOVERN | Article 21(3) per-supplier judgement |
| (e) | Acquisition, development, maintenance; vulnerability handling | ISO/IEC 27002:2022 Clause 8, Technological controls | PROTECT | A disclosure route reaching the CSIRT |
| (f) | Assessing effectiveness of the measures | A.5.35 Independent review of information security; A.5.36 Compliance with policies, rules and standards | GOVERN | Evidence that a measurement changed something |
| (g) | Cyber hygiene and training | A.6.3 Information security awareness, education and training | PROTECT | Article 20(2) training for the management body |
| (h) | Cryptography and encryption | ISO/IEC 27002:2022 Clause 8, Technological controls | PROTECT | Key management evidence |
| (i) | HR security, access control, asset management | A.5.15 Access control, through A.5.18 Access rights; A.6.1 Screening | PROTECT, IDENTIFY | An ISMS boundary narrower than the service |
| (j) | Multi-factor authentication; secured and emergency communications | A.5.14 Information transfer; Clause 8, Technological controls | PROTECT | Emergency communication surviving loss of the estate |
Control titles come from the contents of ISO/IEC 27002:2022 on the ISO Online Browsing Platform 25. That public listing stops at 8.1, so points (e), (h) and (j) are cited at clause level. The framework functions are GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND and RECOVER 26.
Next 90 days
| Week | Action | Owner | Output |
|---|---|---|---|
| 1-2 | Run the scope test above and write the answer down, step by step | Security officer | Scope memo, one citation per step |
| 3-4 | Map the control set onto Article 21(2): met, partial or absent | Security officer | Gap list ranked by risk |
| 3-4 | Rewrite the incident runbook around 24 hours, 72 hours and one month | Incident manager | Runbook with the significance criteria |
| 5-6 | Put the measures and the gap list to the management body under Article 20 | Management body | Minuted approval of the measure set |
| 5-6 | Book Article 20 training for management-body members | Security officer | Attendance record per member |
| 7-8 | Tier direct suppliers and assess the top tier against Article 21(3) | Procurement | Assessments with re-assessment triggers |
| 9-10 | Exercise the reporting chain end to end, timing the awareness decision | Incident manager | Exercise report, clock measured |
| 11-12 | Assemble the evidence index an inspector would walk under Article 32 | Security officer | One index, an owner per artefact |
References
- European Parliament and Council. Directive (EU) 2022/2555. CELEX 32022L2555. https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng
- European Commission. Recommendation 2003/361/EC concerning the definition of micro, small and medium-sized enterprises. CELEX 32003H0361. https://publications.europa.eu/resource/celex/32003H0361
- Sveriges riksdag. Cybersäkerhetslag (2025:1506). https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/cybersakerhetslag-20251506_sfs-2025-1506/
- ISO/IEC. ISO/IEC 27002:2022, contents. ISO Online Browsing Platform. https://www.iso.org/obp/ui/en/#iso:std:iso-iec:27002:ed-3:v2:en
- NIST. The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29. https://doi.org/10.6028/NIST.CSWP.29
Sources
- 1EUR-Lex CELEX 32022L2555 OJ L 333/80 · verified 2026-09-03
- 2EUR-Lex CELEX 32022L2555 Art. 44 · verified 2026-09-03
- 3riksdagen.se SFS 2025:1506 · verified 2026-09-03
- 4EUR-Lex CELEX 32022L2555 sector annexes · verified 2026-09-03
- 5EUR-Lex CELEX 32022L2555 Art. 2(1) · verified 2026-09-03
- 6EU Publications Office CELEX 32003H0361 Annex Art. 2 · verified 2026-09-03
- 7EUR-Lex CELEX 32022L2555 Art. 2(2)-(4) · verified 2026-09-03
- 8EUR-Lex CELEX 32022L2555 Art. 3(1)-(2) · verified 2026-09-03
- 9EUR-Lex CELEX 32022L2555 Art. 26 · verified 2026-09-03
- 10EUR-Lex CELEX 32022L2555 Art. 20 · verified 2026-09-03
- 11EUR-Lex CELEX 32022L2555 Art. 21(1) · verified 2026-09-03
- 12EUR-Lex CELEX 32022L2555 Art. 21(2) · verified 2026-09-03
- 13EUR-Lex CELEX 32022L2555 Art. 21(3)-(4) · verified 2026-09-03
- 14EUR-Lex CELEX 32022L2555 Art. 23(1) and 23(3) · verified 2026-09-03
- 15EUR-Lex CELEX 32022L2555 Art. 23(4) · verified 2026-09-03
- 16EUR-Lex CELEX 32022L2555 Art. 24 · verified 2026-09-03
- 17EUR-Lex CELEX 32022L2555 Art. 32 and 33 · verified 2026-09-03
- 18EUR-Lex CELEX 32022L2555 Art. 34(4)-(5) · verified 2026-09-03
- 19EUR-Lex CELEX 32022L2555 Art. 45 and 38(2) · verified 2026-09-03
- 20EUR-Lex CELEX 32022L2555 Art. 41(1) and 21(5) · verified 2026-09-03
- 21EUR-Lex CELEX 32022L2555 Art. 41(1) and 44 · verified 2026-09-03
- 22EUR-Lex CELEX 32022L2555 Art. 27(2) · verified 2026-09-03
- 23EUR-Lex CELEX 32022L2555 Art. 3(3) · verified 2026-09-03
- 24riksdagen.se SFS 2025:1506 2 kap. 2 § · verified 2026-09-03
- 25ISO OBP ISO/IEC 27002:2022 contents · verified 2026-09-03
- 26nvlpubs.nist.gov NIST CSWP 29 CSF 2.0 Core Functions · verified 2026-09-03
Related
- ISO 27001 first certification
Engagement pattern
- NIS2 readiness for an important entity
Engagement pattern
- Product cybersecurity under R155, ISO 21434 and the CRA
Engagement pattern