Directive (EU) 2022/2555 introduced dozens of new legal definitions for cybersecurity across 18 sectors. If your IT, legal, and compliance teams use them inconsistently — that’s a gap your national authority will find.
The NIS2 Directive (Directive (EU) 2022/2555) is the EU’s updated framework for a high common level of cybersecurity across all member states. It replaced the original NIS Directive (2016/1148), expanding scope from a handful of sectors to 18 sectors covering both essential and important entities.
The transposition deadline was October 17, 2024 — member states were required to adopt national legislation by that date (transposition remains uneven across member states; several EU countries still finalizing national implementation laws as of Q1 2026). NIS2 covers:
Any organization in these sectors above the size threshold (50+ employees or €10M+ turnover) is in scope. The directive mandates cybersecurity risk management measures, three-stage incident reporting (24-hour early warning, 72-hour notification, one-month final report under Article 23), supply chain security, and management body accountability. Smaller entities are also in scope regardless of size if they are sole providers of essential services, DNS/TLD registries, trust service providers, or public administration entities (Article 2(2)).
NIS2 introduces a dense set of new legal definitions that didn’t exist under the original NIS Directive. Cross-functional teams — IT security, legal, compliance, and executive management — must all use these terms consistently and correctly. Terminology inconsistency is exactly the kind of control weakness that supervisory authorities flag.
Terms that consistently cause alignment problems under NIS2:
The NIS2 Directive terminology landscape, categorized by domain:
| Category | Terms | Examples |
|---|---|---|
| Entities | 6 | Essential Entity, Important Entity, DNS Service Provider, TLD Name Registry |
| Incidents & Threats | 7 | Significant Incident, Cyber Threat, Vulnerability, Near Miss, Active Cyber Threat |
| Measures & Controls | 8 | Cybersecurity Risk Management Measures, Supply Chain Security, MFA, Encryption |
| Governance | 5 | Management Body, CSIRT, Single Point of Contact, Cooperation Group |
| Compliance | 4 | Supervisory Authority, Administrative Fine, Compliance Audit, Penalty |
32 entity, incident, control, governance, and compliance terms. Submit your email and the packet is delivered to your inbox.
Penalties: Essential entities face fines up to €10 million or 2% of global annual turnover (whichever is higher). Important entities face up to €7 million or 1.4% of global turnover. Article 20(1) places cybersecurity risk-management oversight on management bodies, and for essential entities Article 32(5)(b) lets competent authorities request that courts temporarily prohibit a natural person in a managerial function from exercising that role. Both are subject to Member State transposition.
Organizations operating in any of 18 listed sectors (energy, transport, banking, health, digital infrastructure, drinking and waste water, public administration, ICT service management, and others) that meet the size threshold of 50+ employees or €10M+ annual turnover. Smaller entities are also in scope regardless of size if they are sole providers of essential services, DNS/TLD registries, trust service providers, or public administration entities (Article 2(2)).
Essential entities are larger organizations in highly critical sectors (energy, transport, banking, health, drinking water, digital infrastructure, public administration) subject to ex-ante supervision and administrative fines up to €10M or 2% of global turnover. Important entities are medium-sized organizations in other NIS2 sectors subject to ex-post supervision and fines up to €7M or 1.4% of global turnover. Misclassification is itself a compliance failure.
Article 23 sets three stages for reporting a significant incident: (1) an early warning to the CSIRT or competent authority within 24 hours of becoming aware of the incident, (2) an incident notification within 72 hours, and (3) a final report within one month of the notification. Intermediate and progress reports may be required on request.
Essential entities face administrative fines up to €10 million or 2% of total worldwide annual turnover, whichever is higher. Important entities face up to €7 million or 1.4% of global turnover. Article 20(1) places cybersecurity risk-management oversight on management bodies, and for essential entities Article 32(5)(b) lets competent authorities request that courts temporarily prohibit a natural person in a managerial function from exercising that role. Both are subject to Member State transposition.
Build your NIS2 glossary in Confluence using the terminology packet as a starting structure. Align your IT, legal, and compliance teams on every definition. Scan your Confluence documentation for inconsistencies. Share the version history with your supervisory authority. Review our transparent app limitations for full details on what we do and don’t cover.
Evaluate in Confluence Get Free PacketCompliance for Confluence — approved terms, page scanning, and audit evidence for regulated teams in Confluence
DORA Terminology — Digital Operational Resilience Act terms for financial sector ICT risk management
SOC 2 Terminology Management — 40 Trust Services Criteria terms for InfoSec & GRC teams
Compliance Guide — what auditors check and how we help, mapped to real regulatory standards
Four-Eyes Principle — approval workflows for compliance, QA, GRC, legal, security, and regulatory teams, mapped to SOX, MiFID II, and ISO 27001
Glossary App Comparison — how Confluence glossary apps compare for compliance, QA, GRC, legal, security, and regulatory teams