NIS2 NIS 2 Directive
Directive (EU) 2022/2555 of the European Parliament and of the Council
of 14 December 2022
on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive)
(Text with EEA relevance)
46 articles, 144 recitals and three annexes. Select an entry from the table of contents.
Chapter I · General provisions
Art. 1Subject matterArt. 2ScopeArt. 3Essential and important entitiesArt. 4Sector-specific Union legal actsArt. 5Minimum harmonisationArt. 6Definitions
Chapter II · Coordinated cybersecurity frameworks
Art. 7National cybersecurity strategyArt. 8Competent authorities and single points of contactArt. 9National cyber crisis management frameworksArt. 10Computer security incident response teams (CSIRTs)Art. 11Requirements, technical capabilities and tasks of CSIRTsArt. 12Coordinated vulnerability disclosure and a European vulnerability databaseArt. 13Cooperation at national level
Chapter III · Cooperation at Union and international level
Art. 14Cooperation GroupArt. 15CSIRTs networkArt. 16European cyber crisis liaison organisation network (EU-CyCLONe)Art. 17International cooperationArt. 18Report on the state of cybersecurity in the UnionArt. 19Peer reviews
Chapter IV · Cybersecurity risk-management measures and reporting obligations
Art. 20GovernanceArt. 21Cybersecurity risk-management measuresArt. 22Union level coordinated security risk assessments of critical supply chainsArt. 23Reporting obligationsArt. 24Use of European cybersecurity certification schemesArt. 25Standardisation
Chapter V · Jurisdiction and registration
Art. 26Jurisdiction and territorialityArt. 27Registry of entitiesArt. 28Database of domain name registration data
Chapter VI · Information sharing
Art. 29Cybersecurity information-sharing arrangementsArt. 30Voluntary notification of relevant information
Chapter VII · Supervision and enforcement
Art. 31General aspects concerning supervision and enforcementArt. 32Supervisory and enforcement measures in relation to essential entitiesArt. 33Supervisory and enforcement measures in relation to important entitiesArt. 34General conditions for imposing administrative fines on essential and important entitiesArt. 35Infringements entailing a personal data breachArt. 36PenaltiesArt. 37Mutual assistance
Chapter VIII · Delegated and implementing acts
Chapter IX · Final provisions
Art. 40ReviewArt. 41TranspositionArt. 42Amendment of Regulation (EU) No 910/2014Art. 43Amendment of Directive (EU) 2018/1972Art. 44RepealArt. 45Entry into forceArt. 46Addressees
Preamble
THE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,
Having regard to the Treaty on the Functioning of the European Union, and in particular Article 114 thereof,
Having regard to the proposal from the European Commission,
After transmission of the draft legislative act to the national parliaments,
Having regard to the opinion of the European Central Bank1,
Having regard to the opinion of the European Economic and Social Committee2,
After consulting the Committee of the Regions,
Acting in accordance with the ordinary legislative procedure3,
HAVE ADOPTED THIS DIRECTIVE:
Signatures
Done at Strasbourg, 14 December 2022.
For the European Parliament
The President
R. Metsola
For the Council
The President
M. Bek
Document version
Official Journal version of 27 December 2022