How to bring your AI systems into NIS2 compliance
NIS2 Directive (EU) 2022/2555
- Status
- Phasing in
- Binding
- Yes
- Object analysed
- Organisation
- Requirements
- 4
- Next milestone
- —
In short
Cybersecurity measures for essential and important entities; AI systems fall within the risk management and supply-chain measures.
Steps to compliance
- Qualify each AI systemAxes to decide: Entity category.
- Determine your roleDuties vary by role: Entity.
- Apply the 4 requirementsThey focus on: Governance & accountability, Literacy & competence, Cybersecurity and Third parties & value chain.
- Prove it with checks6 checks to document, 5 of which also serve ISO 42001, NIST AI RMF and DORA.
- Keep compliance up to dateEvery known milestone has passed: the obligations apply.
Scope and penalties
- Kind
- Directive
- Scope
- Essential and important entities in 18 sectors.
- Territorial reach
- European Union, via national transposition.
- Penalties
- Essential: €10M or 2% of turnover; important: €7M or 1.4%.
- Jurisdiction
- European Union
Timeline
Qualifying a system
Classification axes and possible verdicts
Entity category
Requirements
4 requirements
| Code | Article | Requirement | Applies to | Checks |
|---|---|---|---|---|
| NIS2-20 | Art. 20 | Management body approval and training | ||
| NIS2-21 | Art. 21 | Cyber risk-management measures, incl. supply chain | ||
| NIS2-23 | Art. 23 | Incident reporting (24h / 72h / 1 month) | ||
| NIS2-27 | Art. 3, 27 | Registration with the authority (ANSSI) |
Checks to document
Evidence collected for a check counts for every regulation that uses it.
| Code | Check | Scope | Themes | Also used by |
|---|---|---|---|---|
| CHK-EXEC-ACCOUNT | Executive leadership is accountable for AI risk decisions (board committee, risk appetite) | Organisation | ||
| CHK-TRAINING | Personnel and partners receive AI risk-management training | Organisation | ||
| VER-009-01 | Cybersecurity of the hosting environment | Organisation | ||
| CHK-THIRDPARTY-POL | Policies address third-party AI/data risks, incl. IP, transparency and testing | Organisation | ||
| VER-022-F-01 | Risk and incident response procedure | Organisation | ||
| NEW-NIS2-01 | Entity registered with ANSSI proposed | System |
Themes covered
Frequently asked questions
Who is in scope of NIS2?
Essential and important entities in 18 sectors. European Union, via national transposition.
What penalties does NIS2 carry?
Essential: €10M or 2% of turnover; important: €7M or 1.4%.
When do the NIS2 obligations apply?
Oct 17, 2024: Transposition deadline; 2026: French transposition (resilience law): final adoption to verify.
Is NIS2 binding?
Yes. Kind: directive. Status: phasing in.
How does NIS2 relate to other regulations?
The same checks serve several texts. Shared checks: ISO 42001 (4), NIST AI RMF (4) and DORA (3).
Related regulations
Official sources
Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.