Emtract Ingest
API
EN
EN
DE
Dashboard
Regulations
Crawlers
Attributes
Topics
Home
/
Regulations
/
NIS2
/
Edit regulation
Edit regulation
Name
Short name (English)
Short name (German)
Full name (English)
Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive)
Full name (German)
Richtlinie (EU) 2022/2555 des Europäischen Parlaments und des Rates vom 14. Dezember 2022 über Maßnahmen für ein hohes gemeinsames Cybersicherheitsniveau in der Union, zur Änderung der Verordnung (EU) Nr. 910/2014 und der Richtlinie (EU) 2018/1972 sowie zur Aufhebung der Richtlinie (EU) 2016/1148 (NIS-2-Richtlinie)
Reference number
Source URL
Jurisdiction
Afghanistan
Albania
Algeria
Andorra
Angola
Antigua and Barbuda
Argentina
Armenia
Australia
Austria
Azerbaijan
Bahamas
Bahrain
Bangladesh
Barbados
Belarus
Belgium
Belize
Benin
Bhutan
Bolivia
Bosnia and Herzegovina
Botswana
Brazil
Brunei
Bulgaria
Burkina Faso
Burundi
Cabo Verde
Cambodia
Cameroon
Canada
Central African Republic
Chad
Chile
China
Colombia
Comoros
Congo (Democratic Republic of the)
Congo (Republic of the)
Costa Rica
Côte d'Ivoire
Croatia
Cuba
Cyprus
Czechia
Denmark
Djibouti
Dominica
Dominican Republic
Ecuador
Egypt
El Salvador
Equatorial Guinea
Eritrea
Estonia
Eswatini
Ethiopia
European Union
Fiji
Finland
France
Gabon
Gambia
Georgia
Germany
Ghana
Greece
Grenada
Guatemala
Guinea
Guinea-Bissau
Guyana
Haiti
Holy See
Honduras
Hungary
Iceland
India
Indonesia
Iran
Iraq
Ireland
Israel
Italy
Jamaica
Japan
Jordan
Kazakhstan
Kenya
Kiribati
Kuwait
Kyrgyzstan
Laos
Latvia
Lebanon
Lesotho
Liberia
Libya
Liechtenstein
Lithuania
Luxembourg
Madagascar
Malawi
Malaysia
Maldives
Mali
Malta
Marshall Islands
Mauritania
Mauritius
Mexico
Micronesia
Moldova
Monaco
Mongolia
Montenegro
Morocco
Mozambique
Myanmar
Namibia
Nauru
Nepal
Netherlands
New Zealand
Nicaragua
Niger
Nigeria
North Korea
North Macedonia
Norway
Oman
Pakistan
Palau
Palestine State
Panama
Papua New Guinea
Paraguay
Peru
Philippines
Poland
Portugal
Qatar
Romania
Russia
Rwanda
Saint Kitts and Nevis
Saint Lucia
Saint Vincent and the Grenadines
Samoa
San Marino
Sao Tome and Principe
Saudi Arabia
Senegal
Serbia
Seychelles
Sierra Leone
Singapore
Slovakia
Slovenia
Solomon Islands
Somalia
South Africa
South Korea
South Sudan
Spain
Sri Lanka
Sudan
Suriname
Sweden
Switzerland
Syria
Taiwan
Tajikistan
Tanzania
Thailand
Timor-Leste
Togo
Tonga
Trinidad and Tobago
Tunisia
Türkiye
Turkmenistan
Tuvalu
Uganda
Ukraine
United Arab Emirates
United Kingdom
United States of America
Uruguay
Uzbekistan
Vanuatu
Venezuela
Vietnam
Yemen
Zambia
Zimbabwe
Topic
AI
Anti-Corruption
Antitrust
Case Law
Compliance
Consumer Law
Corporate Law
Cybersecurity
Data Protection
Digital Platforms
Energy
Environment
Export Control
Financial Market
Health & Safety
Industry-Specific Regulation
IP & Licensing
Labor Law
Mobility & Transport
Money Laundering
Product Liability
Product Safety
Public Procurement
Real Estate & Construction
Regulatory Guidelines
Sanctions
Supply Chain
Sustainability
Tax
Telecommunications
Trade
Whistleblowing
Instrument type
Delegated Act
Directive
Implementing Act
Law
Proposal
Regulation
Standard / Guidance
Status
Idea
Consultation
Draft
Adopted
Published
In force
Repealed
Entered into force on
Repealed on
Repealed by
AFIR
Chemicals Climate Protection Ordinance
CSRD
CRA
EED
EnEfG
EntgTranspG
Energy Labelling Ordinance (Germany)
EPBD
GEG (Building Modernisation Act)
GEIG
LSV
NIS2
PPWR
UGB (sustainability reporting)
EU Energy Labelling Regulation
F-gas Regulation
Modified date
Listed at
Description (English)
The Directive requires entities in the eighteen sectors of Annexes I and II that are at least medium-sized enterprises to take cybersecurity risk-management measures, to report significant incidents in staggered steps and to register with the competent authority; the management body must approve the measures, oversee their implementation and can be held liable for them. It distinguishes essential from important entities: essential entities are subject to ex ante supervision and fines of up to EUR 10 million or 2 % of worldwide annual turnover, important entities to ex post supervision and fines of up to EUR 7 million or 1,4 %. Being a directive, it binds companies only through national transposing law. It entered into force on 16 January 2023; Member States had to transpose it by 17 October 2024 and have applied the provisions since 18 October 2024.
Description (German)
Die Richtlinie verpflichtet Einrichtungen in achtzehn Sektoren der Anhänge I und II, die mindestens mittlere Unternehmen sind, zu Risikomanagementmaßnahmen im Bereich der Cybersicherheit, zu gestaffelten Meldungen erheblicher Sicherheitsvorfälle und zur Registrierung bei der zuständigen Behörde; das Leitungsorgan muss die Maßnahmen billigen, ihre Umsetzung überwachen und kann dafür verantwortlich gemacht werden. Sie unterscheidet wesentliche und wichtige Einrichtungen: wesentliche unterliegen einer vorausschauenden Aufsicht und Geldbußen bis 10 Mio. EUR oder 2 % des weltweiten Jahresumsatzes, wichtige einer nachträglichen Aufsicht und Geldbußen bis 7 Mio. EUR oder 1,4 %. Als Richtlinie wirkt sie gegenüber Unternehmen erst über das nationale Umsetzungsrecht. Sie ist am 16. Januar 2023 in Kraft getreten; die Mitgliedstaaten hatten sie bis zum 17. Oktober 2024 umzusetzen und wenden die Vorschriften seit dem 18. Oktober 2024 an.
Cancel
Delete this regulation