NIS2 Directive
Sets cybersecurity risk management and incident reporting obligations for medium and large entities in critical sectors and requires member states to supervise and enforce them.
Where it stands
In forceIntroducedCommitteeFloorLawIn forceCommission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose NIS2Jul 82 months ago
- Body
- European Parliament and Council
- Session
- 9th parliamentary term
- Introduced
- Dec 16, 2020
- In effect since
- Jan 16, 20233 years ago
Timeline
Jul 8 2 months ago
Jan 20 8 months ago
Nov 19, 2025 10 months ago
Digital Omnibus proposal COM(2025) 837 proposes a single entry point for incident reporting
May 7, 2025 1 year ago
Commission sends reasoned opinions to member states that had not notified transposition
Nov 28, 2024 1 year ago
Commission sends letters of formal notice to member states that had not notified transposition
Oct 17, 2024 1 year ago
Jan 16, 2023 3 years ago
Dec 27, 2022 3 years ago
Dec 14, 2022 3 years ago
Nov 28, 2022 3 years ago
Nov 10, 2022 3 years ago
Jul 13, 2022 4 years ago
Oct 28, 2021 4 years ago
Dec 16, 2020 5 years ago
Commission proposal COM(2020) 823 published, procedure 2020/0359(COD)