Directive (EU) 2022/2555. Where Directors Can Be Banned.
The one-paragraph answer
NIS2 (Directive (EU) 2022/2555) is the EU’s horizontal cybersecurity law, covering 18 sectors through two tiers: essential and important entities. It requires risk management measures including supply-chain security, and incident reporting on a 24 hours / 72 hours / one month clock. Fines reach €10 million or 2 percent of worldwide turnover. But the provision that changes behaviour is Article 20: the management body is personally accountable, must be trained, and for essential entities, executives can be temporarily banned from management functions. Not the company. The person.
Most cybersecurity regulation threatens the balance sheet. A fine is a number, it gets modelled, and it gets absorbed. NIS2 threatens the individual. Under Article 20, management bodies must approve the cybersecurity risk-management measures, oversee their implementation, and can be held directly accountable for breaches. For essential entities, competent authorities can temporarily prohibit an individual from exercising management functions.
That is a different conversation in a boardroom. The board that received an annual security slide and signed off is exactly the board NIS2 was drafted against.
The second pain is scope. Companies assume that because they are not a utility or a bank, they are outside it. NIS2 covers 18 sectors including manufacturing of critical products, food, chemicals, waste management, postal and courier services, and ICT service management. And it reaches non-EU companies offering covered services into the EU, who must designate an EU representative.
An all-hazards set: risk analysis and information system security policies, incident handling, business continuity and crisis management, supply chain security, security in acquisition and development, effectiveness testing, cyber hygiene and training, cryptography and encryption, access control and asset management, and multi-factor or continuous authentication. Measures must be appropriate and proportionate, taking account of the state of the art.
Supply chain security is where AI lands. An AI vendor with deep access to an essential entity is a supply-chain risk that Article 21 obliges the entity to assess. The SBOM and the vendor security review are the mechanism.
Early warning within 24 hours of becoming aware of a significant incident. Incident notification within 72 hours. Final report within one month. Significance is judged on operational disruption, financial loss, and material or non-material damage to others.
Approve the measures. Oversee implementation. Be trained, and offer similar training to staff. Be personally accountable. For essential entities, face a temporary management ban.
Essential entities are broadly large organisations (250+ staff or over €50m turnover) in the Annex I high-criticality sectors. They face proactive supervision: audits and inspections, whether or not anything has gone wrong. Fines to €10 million or 2 percent of worldwide turnover.
Important entities are medium-sized entities in Annex I, and medium and large entities in Annex II. They face ex post supervision, triggered only by suspicion of a violation. Fines to €7 million or 1.4 percent.
Some entities are in scope regardless of size, including DNS providers, TLD registries, and qualified trust service providers.
The transposition deadline was 17 October 2024, and most Member States missed it. The Commission opened infringement proceedings against 23 Member States in November 2024, sent reasoned opinions to 19 in May 2025, and by May 2026 had referred seven to the Court of Justice.
That history has made compliance teams complacent. It should not. The great majority of Member States have now transposed, several have layered their own national milestones on top, and the practical convergence point is autumn 2026. Supervisory patience is running out precisely as the last national laws land.
Article 4 gives way to sector-specific regimes of equivalent effect. For financial entities, that regime is DORA. If DORA applies to you, its ICT risk provisions displace the corresponding NIS2 obligations rather than stacking on top of them.
Article 21’s supply-chain provision is not boilerplate. It is the response to where attacks actually come from.
“recent years have shown almost exponential growth in attackers leveraging these software artifacts”
SolarWinds, Log4j, xz utils. NIS2 Article 21(2)(d) is the EU’s legislative answer, and it puts the duty on the entity, not the supplier.
“99% of vulnerabilities in client programs are caused by their dependencies”
Which is why an entity that cannot enumerate its components cannot discharge Article 21, and cannot report on a 24-hour clock about a system it cannot describe.
Only if you are a specific covered entity type (cloud computing, DNS, online marketplace, social network, and similar) and you offer those services within the EU. Merely having EU users is not enough. If both apply, you must designate a representative in a Member State.
No. ISO 27001 is voluntary certification; NIS2 is law with penalties. But the controls map closely to Article 21, and regulators in several Member States accept ISO 27001 evidence toward compliance. It is a large head start, not a substitute.
For essential entities, yes. Competent authorities can temporarily prohibit an individual from exercising management functions. This is not theoretical drafting; it is the enforcement lever that distinguishes NIS2 from a fine schedule.
They are complementary and frequently confused. The CRA regulates the product you place on the market. NIS2 regulates the organisation operating in a critical sector. A manufacturer can easily be subject to both, for different reasons, with different evidence.
Volume V produces the artefacts Article 21 expects: the AI Vendor Tier Map for supply chain, the Red Button procedure and incident response addendum for Article 23, and the Four-Page Board Pack for the Article 20 management-body record.
Note that NIS2 is a directive: your binding obligations come from your Member State’s transposing law, not from the directive text. Read both.
The AI Business Enablement Audit™ measures your organization against every framework in this library, including NIS2 Directive, and delivers a defensible governance dossier. Start or finish your audit below.
Start or finish your AI Audit →