EU Directive 2022/2555 · NIS2

NIS2 compliance you can prove.

From scoping analysis to the ten minimum measures to reporting to your supervisory authority: the SwissGRC® Platform makes your NIS2 implementation structured, traceable and audit ready.

Scope check

Does NIS2 apply to your organisation?

Three inputs are enough for a structured first assessment: location, sector and company size. Right here, no form required.

1 · Location
2 · Sector
3 · Size
Result
Where does your organisation primarily operate?
What matters is where you provide your services or are established.

This first assessment is based on the core criteria of Directive (EU) 2022/2555 and its national implementations. Special cases such as entities covered regardless of size (e.g. trust services, DNS, TLD, public communication networks) and sector-specific law (e.g. DORA in the financial sector) require separate review. It does not replace legal advice.

Deadlines & roadmap

NIS2 across the DACH region: the clock is ticking.

Three countries, three speeds. Pick your country and see which deadlines are already running and what comes next.

Countdown: NISG 2026 in Austria
0Days
0Hrs
0Min
0Sec
06.12.2025
NIS2 implementation act in force
The NIS2UmsuCG applies without any transition period. The requirements are anchored in the revised BSI Act. Around 29,500 companies are affected.
In force
06.03.2026
Mandatory registration with the BSI
The statutory registration deadline with the BSI (portal live since 6 Jan 2026) has passed. The BSI grants latecomers a grace period until 31 July 2026, but late registration remains subject to fines.
Grace period until 31 Jul 2026
Ongoing
Risk management, reporting duties, evidence
The measures under Art. 21 and the three-stage reporting duty (24h, 72h, 1 month) apply. The supervisory authority can demand evidence, and management is liable for implementation.
Active
December 2028
Evidence deadline for particularly important entities
Particularly important entities must demonstrate implementation of the risk management measures to the BSI within three years of the act entering into force.
Prepare
23.12.2025
NISG 2026 promulgated
Austria adopts its NIS2 implementation. A new central authority is created, the Federal Office for Cybersecurity. An estimated 4,000 companies are directly affected.
Adopted
01.10.2026
Entry into force: all obligations apply
Risk management measures, reporting duties and the training duty for management bodies become binding. The previous NISG 2018 is repealed.
Key date
31.12.2026
Registration deadline
Essential and important entities must be registered with the Federal Office for Cybersecurity. Classification is by self-assessment, and there is no group privilege.
30.09.2027
Self-declaration
Within twelve months of the registration obligation arising, a structured self-declaration must be submitted: implemented measures, risk analysis results, supply chain security.
01.10.2028
Regulatory audits possible
From two years after entry into force, the cybersecurity authority can demand evidence and order audits by independent bodies, for important entities on an event-driven basis.
Prepare
01.04.2025
Reporting duty under the ISA
Cyberattacks on critical infrastructure must be reported to the Federal Office for Cybersecurity (BACS) within 24 hours. Switzerland is taking its own path, similar in spirit to NIS2.
In force
Ongoing
NIS2 reaches through the supply chain
Swiss companies with EU customers or EU establishments receive NIS2 requirements indirectly: through security questionnaires, contract clauses and evidence obligations from their affected business partners.
Relevant for exporters & suppliers
16.01.2023
Directive (EU) 2022/2555 in force
NIS2 replaces the 2016 NIS Directive, extends the scope to 18 sectors and tightens supervision and sanctions.
18.10.2024
Start of application
Member states were required to transpose the directive into national law by 17 Oct 2024. Many followed late, and implementation has been progressing country by country since.
Ongoing
National implementations and implementing acts
For certain digital services, the Commission implementing regulation specifies the security requirements in detail. Nationally, deadlines, authorities and terminology differ, which is particularly demanding for groups with sites in several EU countries.

As of July 2026. Deadlines and regulatory practice evolve continuously; the respective legal texts and official communications are authoritative.

Art. 21(2) · The mandatory measures

Ten measures, one system.

NIS2 requires every in-scope entity to implement ten minimum measures, from risk analysis to multi-factor authentication. Click through: what the directive demands and how you implement it on the SwissGRC® Platform.

Art. 23 · Reporting duty for significant incidents
Three deadlines you must meet when it happens.
24h
Early warning

Without undue delay after becoming aware: initial notification to the competent authority or CSIRT, including any suspicion of unlawful action or cross-border impact.

72h
Notification

Structured assessment of the incident: severity, impact and, where available, indicators of compromise.

1 month
Final report

Detailed description of the incident, its causes and the remediation taken. Interim reports upon request.

FAQ

Frequently asked questions

The questions companies ask us most often when introducing their NIS2 solution. Answered directly, no detours.

In principle, medium and large companies (50+ employees or over EUR 10 million turnover) in the 18 sectors of Annexes I and II, from energy and health to manufacturing. Certain services such as DNS, TLD or trust services are covered regardless of size, and through the supply chain obligations the requirements also reach suppliers that are not directly regulated. The fastest way to orient yourself is the scope check at the top of this page.
Significant incidents must be reported in three stages (Art. 23): an early warning within 24 hours, a detailed notification within 72 hours and a final report no later than one month after the early warning. On the SwissGRC® Platform you define the reporting process as a workflow with deadlines, owners and templates, so that when it happens, nobody has to figure out who reports what by when.
Faster than most expect. The SwissGRC® Platform comes with pre-structured NIS2 content, so you are not starting from zero. First results such as the baseline assessment and a prioritised action plan are visible within days, and a typical rollout takes a few weeks depending on scope and modules. Our onboarding guides you step by step.
Evidence is attached directly to the requirement or measure: documents, minutes, screenshots, references. Every version is preserved, and every change is logged with user and timestamp. The result is a complete, audit-proof trail. When the supervisory authority or an auditor requests evidence, you export the current state at the click of a button instead of searching folders and inboxes.
Licensing is modular and transparent: you pay for the modules you use, scaled to the size of your organisation. There are no hidden costs and no obligation to buy the full suite. Because the right setup differs by starting point, we prepare a concrete quote after a short conversation. Contact sales

For the directive itself, including sectors, sanctions and deadlines, see the scope check and the roadmap above.

Do not just implement NIS2.
Prove it.

See how organisations across Europe structure, implement and evidence their NIS2 obligations with the SwissGRC® Platform, ready for authorities and auditors.