EUEuropean UnionPhasing inNIS2

How to bring your AI systems into NIS2 compliance

NIS2 Directive (EU) 2022/2555

Status
Phasing in
Binding
Yes
Object analysed
Organisation
Requirements
4
Next milestone
—

In short

Cybersecurity measures for essential and important entities; AI systems fall within the risk management and supply-chain measures.

Steps to compliance

  1. Qualify each AI systemAxes to decide: Entity category.
  2. Determine your roleDuties vary by role: Entity.
  3. Apply the 4 requirementsThey focus on: Governance & accountability, Literacy & competence, Cybersecurity and Third parties & value chain.
  4. Prove it with checks6 checks to document, 5 of which also serve ISO 42001, NIST AI RMF and DORA.
  5. Keep compliance up to dateEvery known milestone has passed: the obligations apply.

Scope and penalties

Kind
Directive
Scope
Essential and important entities in 18 sectors.
Territorial reach
European Union, via national transposition.
Penalties
Essential: €10M or 2% of turnover; important: €7M or 1.4%.
Jurisdiction
European Union

Timeline

Jan 16, 2023Entry into force
Oct 17, 2024Transposition deadline
2026French transposition (resilience law): final adoption to verifyTo verify
Release
PastSet in the textPotentialTo verify

Qualifying a system

Classification axes and possible verdicts

Entity category

Essential entityImportant entityOut of scope

Requirements

4 requirements

CodeArticleRequirementApplies toChecks
NIS2-20Art. 20Management body approval and training
EntityEssential entityImportant entity
NIS2-21Art. 21Cyber risk-management measures, incl. supply chain
EntityEssential entityImportant entity
NIS2-23Art. 23Incident reporting (24h / 72h / 1 month)
EntityEssential entityImportant entity
NIS2-27Art. 3, 27Registration with the authority (ANSSI)
EntityEssential entityImportant entity

Checks to document

Evidence collected for a check counts for every regulation that uses it.

CodeCheckScopeThemesAlso used by
CHK-EXEC-ACCOUNTExecutive leadership is accountable for AI risk decisions (board committee, risk appetite)Organisation
CHK-TRAININGPersonnel and partners receive AI risk-management trainingOrganisation
VER-009-01Cybersecurity of the hosting environmentOrganisation
CHK-THIRDPARTY-POLPolicies address third-party AI/data risks, incl. IP, transparency and testingOrganisation
VER-022-F-01Risk and incident response procedureOrganisation
NEW-NIS2-01Entity registered with ANSSI proposedSystem
—

Themes covered

Frequently asked questions

Who is in scope of NIS2?

Essential and important entities in 18 sectors. European Union, via national transposition.

What penalties does NIS2 carry?

Essential: €10M or 2% of turnover; important: €7M or 1.4%.

When do the NIS2 obligations apply?

Oct 17, 2024: Transposition deadline; 2026: French transposition (resilience law): final adoption to verify.

Is NIS2 binding?

Yes. Kind: directive. Status: phasing in.

How does NIS2 relate to other regulations?

The same checks serve several texts. Shared checks: ISO 42001 (4), NIST AI RMF (4) and DORA (3).

Related regulations

Official sources

Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo