The final text of the NIS 2 Directive (14 December 2022)


Preamble 1 to 144.


Preamble 1 to 10, NIS 2 Directive


Preamble 11 to 20, NIS 2 Directive


Preamble 21 to 30, NIS 2 Directive


Preamble 31 to 40, NIS 2 Directive


Preamble 41 to 50, NIS 2 Directive


Preamble 51 to 60, NIS 2 Directive


Preamble 61 to 70, NIS 2 Directive


Preamble 71 to 80, NIS 2 Directive


Preamble 81 to 90, NIS 2 Directive


Preamble 91 to 100, NIS 2 Directive


Preamble 101 to 110, NIS 2 Directive


Preamble 111 to 120, NIS 2 Directive


Preamble 121 to 130, NIS 2 Directive


Preamble 131 to 144, NIS 2 Directive



CHAPTER I, GENERAL PROVISIONS


Article 1, Subject matter, NIS 2 Directive.


Article 2, Scope, NIS 2 Directive.


Article 3, Essential and important entities, NIS 2 Directive.


Article 4, Sector-specific Union legal acts, NIS 2 Directive.


Article 5, Minimum harmonisation, NIS 2 Directive.


Article 6, Definitions, NIS 2 Directive.



CHAPTER II, COORDINATED CYBERSECURITY FRAMEWORKS


Article 7, National cybersecurity strategy, NIS 2 Directive.


Article 8, Competent authorities and single points of contact, NIS 2 Directive.


Article 9, National cyber crisis management frameworks, NIS 2 Directive.


Article 10, Computer security incident response teams (CSIRTs), NIS 2 Directive.


Article 11, Requirements, technical capabilities and tasks of CSIRTs, NIS 2 Directive.


Article 12, Coordinated vulnerability disclosure and a European vulnerability database, NIS 2 Directive.


Article 13, Cooperation at national level, NIS 2 Directive.



CHAPTER III, COOPERATION AT UNION AND INTERNATIONAL LEVEL


Article 14, Cooperation Group, NIS 2 Directive.


Article 15, CSIRTs network, NIS 2 Directive.


Article 16, European cyber crisis liaison organisation network (EU-CyCLONe), NIS 2 Directive.


Article 17, International cooperation, NIS 2 Directive.


Article 18, Report on the state of cybersecurity in the Union, NIS 2 Directive.


Article 19, Peer reviews, NIS 2 Directive.



CHAPTER IV, CYBERSECURITY RISK-MANAGEMENT MEASURES AND REPORTING OBLIGATIONS


Article 20, Governance, NIS 2 Directive.


Article 21, Cybersecurity risk-management measures, NIS 2 Directive.


Article 22, Union level coordinated security risk assessments of critical supply chains, NIS 2 Directive.


Article 23, Reporting obligations, NIS 2 Directive.


Article 24, Use of European cybersecurity certification schemes, NIS 2 Directive.


Article 25, Standardisation, NIS 2 Directive.



CHAPTER V, JURISDICTION AND REGISTRATION


Article 26, Jurisdiction and territoriality, NIS 2 Directive.


Article 27, Registry of entities, NIS 2 Directive.


Article 28, Database of domain name registration data, NIS 2 Directive.



CHAPTER VI, INFORMATION SHARING


Article 29, Cybersecurity information-sharing arrangements, NIS 2 Directive.


Article 30, Voluntary notification of relevant information, NIS 2 Directive.



CHAPTER VII, SUPERVISION AND ENFORCEMENT


Article 31, General aspects concerning supervision and enforcement, NIS 2 Directive.


Article 32, Supervisory and enforcement measures in relation to essential entities, NIS 2 Directive.


Article 33, Supervisory and enforcement measures in relation to important entities, NIS 2 Directive.


Article 34, General conditions for imposing administrative fines on essential and important entities, NIS 2 Directive.


Article 35, Infringements entailing a personal data breach, NIS 2 Directive.


Article 36, Penalties, NIS 2 Directive.


Article 37, Mutual assistance, NIS 2 Directive.



CHAPTER VIII, DELEGATED AND IMPLEMENTING ACTS


Article 38, Exercise of the delegation, NIS 2 Directive.


Article 39, Committee procedure, NIS 2 Directive.



CHAPTER IX, FINAL PROVISIONS


Article 40, Review, NIS 2 Directive.


Article 41, Transposition, NIS 2 Directive.


Article 42, Amendment of Regulation (EU) No 910/2014, NIS 2 Directive.


Article 43, Amendment of Directive (EU) 2018/1972, NIS 2 Directive.


Article 44, Repeal, NIS 2 Directive.


Article 45, Entry into force, NIS 2 Directive.


Article 46, Addressees, NIS 2 Directive.



Note: This is the final text of the NIS 2 Directive. The full name is "Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive)".


Understanding Cybersecurity in the European Union.

1. The NIS 2 Directive

2. The Digital Operational Resilience Act (DORA)

3. The Critical Entities Resilience Directive (CER)

4. The European Data Act

5. The European Data Governance Act (DGA)

6. The European Cyber Resilience Act (CRA)

7. The Digital Services Act (DSA)

8. The Digital Markets Act (DMA)

9. The European Chips Act

10. The Artificial Intelligence Act

11. The Artificial Intelligence Liability Directive

12. The Framework for Artificial Intelligence Cybersecurity Practices (FAICP)

13. The EU Cyber Solidarity Act

14. The Digital Networks Act (DNA)

15. The European ePrivacy Regulation

16. The European Digital Identity Regulation

17. The European Media Freedom Act (EMFA)

18. The Corporate Sustainability Due Diligence Directive (CSDDD)

19. The European Health Data Space (EHDS)

20. The European Financial Data Space (EFDS)

21. The Financial Data Access (FiDA) Regulation

22. The Payment Services Directive 3 (PSD3), Payment Services Regulation (PSR)

23. The European Cyber Defence Policy

24. The Strategic Compass of the European Union

25. The EU Cyber Diplomacy Toolbox