home / frameworks / nis2

// Foreign laws with Canadian reach

NIS2 Directive (EU) 2022/2555

The EU directive that sets cybersecurity risk-management and incident reporting duties for entities in 18 sectors. Canadian firms meet it through EU customers' supply-chain demands, and some digital providers fall directly under it.

European Union

Overview

Directive (EU) 2022/2555, known as NIS2, sets a common baseline for cybersecurity across 18 sectors in the EU. It replaced the first NIS Directive on October 18, 2024. Member states had to write it into national law by October 17, 2024. Most did, though many were late. The Commission sent reasoned opinions to 19 member states on May 7, 2025, and on July 8, 2026 it referred Ireland, Spain, France, and the Netherlands to the Court of Justice and asked for financial penalties. Because NIS2 is a directive, the obligations that bind a company sit in each national law, so registration portals, reporting forms, and penalties differ by country.

Entities are classed as essential or important. Essential entities are mostly large organizations in Annex I sectors such as energy, transport, banking, health, digital infrastructure, and business-to-business ICT service management, and they face proactive supervision. Important entities include other medium and large organizations in Annex I and Annex II sectors and are supervised mainly after an incident or complaint. Both must apply the 10 risk-management measures in Article 21 and report significant incidents under Article 23, with an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month. Management bodies must approve the measures and take training. Member states must set maximum fines of at least €10 million or 2% of worldwide turnover for essential entities and €7 million or 1.4% for important ones.

Canadian companies are reached in 2 ways. The common one is the supply chain, since Article 21 requires in-scope entities to manage the security of their suppliers and service providers, which shows up as contract clauses, questionnaires, and audit rights. Direct coverage applies to some digital providers. Under Article 26, a DNS provider, TLD registry, domain registration service, cloud, data centre, content delivery, managed service, or managed security service provider, online marketplace, search engine, or social network that isn't established in the EU but offers services there must designate a representative in a member state and falls under that state's jurisdiction. On January 20, 2026 the Commission proposed targeted amendments to clarify scope and simplify compliance, and that proposal isn't law yet.

Who it applies to in Canada

Medium and large public and private entities in 18 sectors that provide services or carry out activities in the EU, plus some entities regardless of size, such as DNS providers, TLD registries, and qualified trust service providers.

Canadian suppliers to in-scope EU entities receive NIS2 security requirements through contracts, since Article 21 covers supply chain security. Canadian cloud, data centre, managed service, and other digital providers offering services in the EU without an EU establishment must designate an EU representative.

Controls at a glance

NIS2 defines who is in scope, then sets governance, risk-management, reporting, and supervision duties that member states write into national law.

Scope and classification (Articles 2 and 3)

  • 18 sectors across Annex I and Annex II
  • Medium and large entities in those sectors are covered
  • Some providers covered regardless of size
  • Essential entities face ex ante supervision
  • Important entities face ex post supervision
  • Member states list entities and review lists every 2 years

Governance (Article 20)

  • Management bodies approve risk-management measures
  • Management oversees implementation
  • Management can be held liable for infringements
  • Management members must follow cybersecurity training
  • Regular training encouraged for employees

Article 21 measures (a) to (e)

  • Risk analysis and information system security policies
  • Incident handling
  • Business continuity, backups, disaster recovery, and crisis management
  • Supply chain security, including supplier relationships
  • Secure acquisition, development, and maintenance, with vulnerability handling

Measures must be proportionate to risk, size, and likely impact.

Article 21 measures (f) to (j)

  • Policies to assess effectiveness of risk-management measures
  • Basic cyber hygiene practices and cybersecurity training
  • Policies on cryptography and, where appropriate, encryption
  • Human resources security, access control, and asset management
  • Multi-factor or continuous authentication and secured emergency communications

Incident reporting (Article 23)

  • Early warning to the CSIRT or authority within 24 hours
  • Incident notification with initial assessment within 72 hours
  • Intermediate status reports on request
  • Final report within one month of notification
  • Tell service recipients about significant incidents affecting them
  • Tell recipients about remedies for significant cyber threats

Jurisdiction and registration (Articles 26 and 27)

  • Most entities fall under the member state of establishment
  • Digital providers fall under their main EU establishment
  • Non-EU digital providers designate an EU representative
  • Without a representative, any affected member state may act
  • Digital providers submit registration details for the ENISA registry
  • Report changes to registration details promptly

Supervision and enforcement (Articles 31 to 37)

  • On-site inspections and regular or targeted audits
  • Security scans and requests for evidence
  • Binding instructions and orders to remedy
  • Administrative fines set in national law
  • Temporary bans on managers of essential entities, as last resort

Implementing Regulation (EU) 2024/2690

  • Technical requirements for Article 21 measures
  • Thresholds for significant incidents
  • Applies to DNS, TLD, cloud, and data centre providers
  • Applies to CDN, managed service, and managed security providers
  • Applies to marketplaces, search engines, social networks, trust services

ENISA publishes technical implementation guidance for this regulation.

Certification and assessment

Entities show compliance through documented policies, risk assessments, incident records, and evidence requested in audits or inspections. Supervision of essential entities is proactive, while important entities are mainly checked after evidence of non-compliance. National laws may require the use of certified products or schemes, but no single NIS2 certificate exists.

Dates to know

2023-01-16
NIS2 enters into force
2024-10-17
Transposition deadline for member states
2024-10-18
National NIS2 measures apply and the first NIS Directive is repealed
2025-04-17
Deadline for member states to establish lists of essential and important entities
2025-05-07
Commission sends reasoned opinions to 19 member states over incomplete transposition
2026-01-20
Commission proposes targeted NIS2 amendments as part of a cybersecurity package (proposal, not adopted)
2026-07-08
Commission refers Ireland, Spain, France, and the Netherlands to the Court of Justice

Resources

Official texts and free tools for NIS2. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. Directive (EU) 2022/2555 (NIS2), EUR-Lex, Publications Office of the European Union
  2. Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose the rules on cybersecurity, European Commission
  3. NIS2 transposition status by member state, European Commission
  4. NIS2 Directive: securing network and information systems, European Commission