Skip to content
// Cybersecurity

The NIS2 Directive

Directive (EU) 2022/2555 (CELEX 32022L2555) · Adopted 14 Dec 2022 · transposed in Sweden through the Cybersecurity Act (2025:1506)

NIS2 is the EU's updated directive for a high common level of cybersecurity. It dramatically broadens which sectors and companies are covered compared with the old NIS Directive, and tightens the requirements on risk management, incident reporting and management accountability.

// In brief

  • Directive (EU) 2022/2555, adopted 14 December 2022 — replaces the old NIS Directive (2016/1148).
  • As a directive, it applies through national law. In Sweden: the Cybersecurity Act (2025:1506), in force since 15 January 2026.
  • Divides organisations into essential and important entities — as a rule, medium-sized companies and larger in the designated sectors.
  • Requires cybersecurity risk-management measures (Article 21), incident reporting (Article 23) and management accountability (Article 20).
  • Early warning within 24 hours, incident notification within 72 hours and a final report within one month.

What is NIS2 and why was it introduced?

NIS2 (Network and Information Security Directive 2) is the EU's response to growing cyber threats and to the fact that the old NIS Directive covered too few sectors and was applied inconsistently across member states. The goal is a high common level of cybersecurity throughout the Union.

Because NIS2 is a directive, it does not apply directly — each country transposes it into national law. In Sweden this is done through the Cybersecurity Act (2025:1506).

Who does NIS2 apply to?

NIS2 designates sectors in two annexes: Annex I (sectors of high criticality) — energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space — and Annex II (other critical sectors) — postal services, waste management, chemicals, food, manufacturing, digital providers and research.

As a rule, organisations that are medium-sized or larger are in scope. They are classified as either essential or important entities, which determines how strict the supervision is.

The requirements in brief

  • Risk-management measures (Article 21): risk analysis, incident handling, business continuity, supply chain security, encryption, access control, multi-factor authentication and more — taking an all-hazards approach.
  • Incident reporting (Article 23): an early warning within 24 hours, an incident notification within 72 hours and a final report within one month.
  • Management accountability (Article 20): boards and management must approve the measures, undergo training and can be held personally accountable.

Penalties

The directive sets caps for administrative fines: for essential entities at least up to €10 million or 2% of global annual turnover, for important entities up to €7 million or 1.4%. The exact amounts in Sweden are set out in the Cybersecurity Act.

How ZORC helps

We build systems that stand up to the NIS2 requirements: secure architecture, logging and incident handling, supply chain security and documentation that holds up under supervision. Talk to us about NIS2-ready systems →

This page is informational and fact-checked against the primary source, but it does not constitute legal advice. For a binding assessment of your specific organisation — talk to us or your legal counsel.

Frequently asked questions

What is NIS2 in simple terms?

NIS2 is the EU's cybersecurity directive. It requires companies and organisations in critical sectors of society to work systematically with security and to report serious incidents. It replaces the older NIS Directive and covers far more organisations.

Does NIS2 apply in Sweden?

Yes. NIS2 has been transposed into Swedish law through the Cybersecurity Act (2025:1506), which entered into force on 15 January 2026.

Which companies are covered by NIS2?

Organisations in the designated sectors (Annex I and II) that, as a rule, are medium-sized or larger. They are classified as essential or important entities depending on their sector and significance.

How quickly must an incident be reported under NIS2?

An early warning must be submitted within 24 hours, a formal incident notification within 72 hours and a final report within one month of the notification.

What happens if you don't comply with NIS2?

The supervisory authority can issue orders, carry out security audits and impose administrative fines. For essential entities, up to €10 million or 2% of turnover; in serious cases, individual managers can be banned from exercising managerial functions.

Need help complying with NIS2?

We build secure, compliant solutions and help you map exactly what applies to your organisation.