Energy 4 min read
NIS2
NIS2 Directive Also known as: NIS 2 directive, KSC
Definition
NIS2 is the EU cybersecurity directive (EU) 2022/2555. It requires essential and important entities, including electricity suppliers, grid operators, producers, aggregators, storage and charge point operators, to manage cyber risk and send an early warning of significant incidents within 24 hours.
Cite this entry
Text
"NIS2". Order Group, Software glossary, 10 October 2026. https://ordergroup.co/glossary/nis2/
HTML
<a href="https://ordergroup.co/glossary/nis2/">NIS2</a> - Order Group
How NIS2 works
Directive (EU) 2022/2555, known as NIS2, was adopted on December 14, 2022 and replaced the first NIS directive (2016/1148). Member States had to transpose it by October 17, 2024 and apply it from October 18, 2024. As a directive it does not bind companies directly. Each country writes its own law, and in Poland that law is the act on the national cybersecurity system (ustawa o krajowym systemie cyberbezpieczeństwa, KSC).
NIS2 covers medium-sized and larger organizations in the sectors listed in its annexes and sorts them into essential and important entities, which differ mainly in how closely they are supervised and how high the fines can go. Energy is in Annex I. For electricity the list covers electricity undertakings that supply power, distribution and transmission system operators, producers, nominated electricity market operators, market participants providing aggregation, demand response or energy storage services, and operators of recharging points.
The obligations sit in three articles. Article 20 makes the management body approve the cybersecurity risk-management measures, oversee them and take part in training. Article 21 lists the minimum measures, from risk analysis and incident handling to supply chain security, cryptography and multi-factor authentication. Article 23 sets the reporting clock for significant incidents.
| Obligation | Article | Requirement |
|---|---|---|
| Early warning | 23(4)(a) | Within 24 hours of becoming aware of a significant incident |
| Incident notification | 23(4)(b) | Within 72 hours |
| Final report | 23(4)(d) | Within one month of the notification |
| Fines, essential entities | 34(4) | Maximum of at least EUR 10 million or 2% of worldwide annual turnover, whichever is higher |
| Fines, important entities | 34(5) | Maximum of at least EUR 7 million or 1.4% of worldwide annual turnover, whichever is higher |
What NIS2 means for your software
NIS2 regulates the organization, but most of Article 21 lands on its systems, and much of it on whoever builds them. Point (d) requires supply chain security and point (e) security in "network and information systems acquisition, development and maintenance," including vulnerability handling. Article 21(3) tells entities to consider the vulnerabilities of each direct supplier and the quality of its products and cybersecurity practices. A grid operator, aggregator or charge point operator buying software will therefore write these requirements into the contract and ask its supplier to prove them.
In practice the requirements that reach the software are fairly predictable. Encryption of data in transit and, where appropriate, at rest follows from point (h), and multi-factor authentication for users and administrators from point (j). Access control and an asset inventory come from point (i), backups and a tested recovery procedure from point (c). The 24-hour early warning sets a design target: the system has to produce security logs and alerts that let someone notice an incident within hours of it starting. Device fleets add their own work, because every meter, gateway or inverter connection is a supplier link and an entry point.
NIS2 does not certify products. Connected devices are covered by separate EU rules, the Cyber Resilience Act (CRA) and the delegated act under the Radio Equipment Directive (RED DA), so for energy devices the hardware maker answers to CRA and RED DA, and the operator to NIS2.
| Measure (Art. 21(2)) | What to expect in the software |
|---|---|
| (b) Incident handling | Central logs, alerting, a runbook that supports the 24-hour warning |
| (c) Business continuity | Backups, restore tests, documented recovery time |
| (d) Supply chain security | Supplier inventory, dependency and component tracking |
| (e) Secure development and maintenance | Code review, vulnerability handling and patch process |
| (h) Cryptography | TLS for device and user traffic, encryption of stored data |
| (i) Access control and asset management | Roles, the least-privilege principle and a list of devices and services |
| (j) Multi-factor authentication | MFA for administrators and remote access |
Rules and standards
Poland transposed NIS2 through the act of January 23, 2026 amending the KSC act (Dz.U. 2026 poz. 252), published on March 2, 2026 and in force since April 3, 2026. According to the Ministry of Digital Affairs, key entities (the Polish act's name for essential entities) and important entities had to apply for entry in the register by October 3, 2026 and must implement the new obligations by April 3, 2027. Key entities have to complete their first security audit by April 3, 2028 and repeat it at least every three years. For most obligations, administrative fines can be imposed only after April 3, 2028. The amendment also makes the heads of entities responsible for carrying out cybersecurity tasks.
For other EU countries check the national transposition act, since scope details, registration and supervisors differ.
From our projects
We have not run NIS2 compliance programs for clients. We meet NIS2 as a requirement on the systems we build. The clearest case is Zeronest, an energy management platform for solar and battery installations that we have built since January 2024. The platform has to meet cybersecurity requirements under NIS2, CRA, RED DA and Poland's KSC act. Devices talk to the cloud over MQTT encrypted with TLS 1.2 behind AWS IoT Core, and client data stays in the EU. Each installation reads the inverter through Zeronest's own device with its own SIM card and LTE link, so the data path does not depend on the inverter maker's cloud or the homeowner's Wi-Fi. The platform also has a demand-side response module for aggregators, the kind of customer listed in Annex I, which is one reason these requirements flow down to the software.
Sources
- Directive (EU) 2022/2555 (NIS 2 Directive) - EUR-Lex
- Ustawa z dnia 23 stycznia 2026 r. o zmianie ustawy o krajowym systemie cyberbezpieczeństwa oraz niektórych innych ustaw (Dz.U. 2026 poz. 252) - Dziennik Ustaw RP
- Nowelizacja ustawy o krajowym systemie cyberbezpieczeństwa zaczyna obowiązywać - Ministerstwo Cyfryzacji
FAQ
-
It applies if you operate in a sector listed in the directive, for example electricity supply, distribution, generation, aggregation, demand response, energy storage or charging, and you are at least a medium-sized enterprise. Some smaller entities can be included by national authorities. Check the national act, in Poland the amended KSC act, for the exact criteria.
-
An early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours and a final report within one month of the notification (Article 23(4)).
-
A supplier may not be an essential or important entity itself, but Article 21 requires covered entities to manage supply chain security and secure development. Expect contract clauses on vulnerability handling, encryption, MFA, logging and incident cooperation.
-
The amended KSC act has been in force since April 3, 2026. Entities had until October 3, 2026 to apply for registration and have until April 3, 2027 to implement the obligations. Key entities must complete their first audit by April 3, 2028.
Building a system that depends on NIS2?
See how we build software for this domain, with case studies and the stack we use.