Skip to content
Compliance1 min read

NIS2: deadlines, obligations and penalties for European organizations

28 March 2026|AEGIDA Research Team

The European NIS2 (Network and Information Security Directive 2) represents the most significant regulatory update in cybersecurity in recent years. It significantly extends the scope of obligated entities and introduces severe penalties for non-compliance.

Who is affected?

NIS2 applies to two categories: Essential entities (energy, transport, healthcare, water, digital infrastructure, public administration) and Important entities (postal services, waste management, food production, manufacturing, research). If your organization operates in one of these sectors with at least 50 employees or revenue exceeding 10 million euros, you are almost certainly covered.

Key obligations

  • Implementation of proportionate technical and organizational measures (Art. 21)
  • Encryption of communications and protection of data in transit
  • Incident management with notification within 24 hours
  • Supply chain security and supplier access control
  • Business continuity and disaster recovery
  • Governance: management is directly responsible

Penalties

For Essential entities, penalties can reach 10 million euros or 2% of annual global turnover. For Important entities, up to 7 million euros or 1.4% of turnover.

Unlike GDPR, NIS2 also provides for personal liability of management: executives can be held directly responsible in case of negligence in overseeing security measures.

What to do now

The first step is to conduct an assessment of your current security posture, identifying gaps against NIS2 requirements. AEGIDA offers a free self-assessment tool that provides an indicative evaluation in minutes, with personalized recommendations and guidance on the most suitable technological solutions.

Do not wait for deadlines: NIS2 compliance is not a project that can be completed in a few days. It requires planning, technological investment, and a cultural shift in how operational communications security is managed.