EuroComply
Konto erstellen
Official source map

NIS2 official sources

Primary NIS2 sources for SMEs and suppliers: directive text, Commission guidance, incident reporting references, and EuroComply checklists.

What official sources should SMEs cite for NIS2?

The primary source for NIS2 is Directive (EU) 2022/2555, supported by European Commission guidance and national transposition rules. SMEs should verify whether they are essential or important entities, then keep evidence for cybersecurity risk management, management oversight, supplier controls and incident reporting.

  • Articles 2-3: Scope and entity types
  • Article 20: Governance
  • Article 21: Risk measures
  • Article 23: Incident reporting
  • Article 34: Penalties
Primary sourceDirective (EU) 2022/2555
EuroComply source page/sources/nis2
Last reviewed2026-05-11
Source: Directive (EU) 2022/2555Reviewed:

Key references

ReferenceTopicWhy it matters
Articles 2-3Scope and entity typesDetermines essential or important status.
Article 20GovernanceManagement body oversight.
Article 21Risk measuresCore cybersecurity controls.
Article 23Incident reporting24-hour and 72-hour reporting path.
Article 34PenaltiesMaximum fine framework.

Use the source map with an action plan

Official sources answer what the law says. EuroComply guides turn those references into owners, deadlines, evidence and dashboard-ready actions.

EU AI Act official sourcesGDPR official sourcesDORA official sourcesData Act official sourcesPay Transparency Directive official sources