EU Cybersecurity

NIS2 Directive Terminology for Confluence

Directive (EU) 2022/2555 introduced dozens of new legal definitions for cybersecurity across 18 sectors. If your IT, legal, and compliance teams use them inconsistently — that’s a gap your national authority will find.

Compliance Glossary terms table in Confluence with Regulation Packs import, approval statuses, lifecycle state, and version history
Compliance Glossary for Confluence: version-controlled terms with approval statuses, lifecycle tracking, and one-click Regulation Packs import.
Quick answer: NIS2 (Directive (EU) 2022/2555) applies to 18 sectors and classifies organizations as essential or important entities. Essential entities face administrative fines up to €10M or 2% of global turnover; important entities up to €7M or 1.4% (Article 34). Member states’ transposition deadline was 17 October 2024. Incident reporting follows 24h early warning / 72h notification / one-month final report under Article 23. Last verified: 2026-04-17.

What Is NIS2?

The NIS2 Directive (Directive (EU) 2022/2555) is the EU’s updated framework for a high common level of cybersecurity across all member states. It replaced the original NIS Directive (2016/1148), expanding scope from a handful of sectors to 18 sectors covering both essential and important entities.

The transposition deadline was October 17, 2024 — member states were required to adopt national legislation by that date (transposition remains uneven across member states; several EU countries still finalizing national implementation laws as of Q1 2026). NIS2 covers:

Any organization in these sectors above the size threshold (50+ employees or €10M+ turnover) is in scope. The directive mandates cybersecurity risk management measures, three-stage incident reporting (24-hour early warning, 72-hour notification, one-month final report under Article 23), supply chain security, and management body accountability. Smaller entities are also in scope regardless of size if they are sole providers of essential services, DNS/TLD registries, trust service providers, or public administration entities (Article 2(2)).

The NIS2 Terminology Challenge

NIS2 introduces a dense set of new legal definitions that didn’t exist under the original NIS Directive. Cross-functional teams — IT security, legal, compliance, and executive management — must all use these terms consistently and correctly. Terminology inconsistency is exactly the kind of control weakness that supervisory authorities flag.

Common compliance gap: Your incident response plan defines “significant incident” as any service disruption. Your risk register uses it only for data breaches. Your CSIRT report uses a third definition. When the national authority reviews your documentation — they see three different thresholds for the same legal obligation.

Terms that consistently cause alignment problems under NIS2:

NIS2 Terminology — Categorized by Domain

The NIS2 Directive terminology landscape, categorized by domain:

Entities (6 terms)

Essential Entity
Important Entity
Operator of Essential Services
Digital Service Provider
DNS Service Provider
TLD Name Registry

Incidents & Threats (7 terms)

Significant Incident
Cyber Threat
Vulnerability
Near Miss
Large-Scale Cybersecurity Incident
Active Cyber Threat
Risk

Measures & Controls (8 terms)

Cybersecurity Risk Management Measures
Incident Handling
Business Continuity
Supply Chain Security
Encryption
Multi-Factor Authentication
Network Security
Security Policies

Governance (5 terms)

Management Body
Due Diligence
CSIRT
Single Point of Contact
Cooperation Group

Compliance (4 terms)

Supervisory Authority
Penalty
Administrative Fine
Compliance Audit
CategoryTermsExamples
Entities6Essential Entity, Important Entity, DNS Service Provider, TLD Name Registry
Incidents & Threats7Significant Incident, Cyber Threat, Vulnerability, Near Miss, Active Cyber Threat
Measures & Controls8Cybersecurity Risk Management Measures, Supply Chain Security, MFA, Encryption
Governance5Management Body, CSIRT, Single Point of Contact, Cooperation Group
Compliance4Supervisory Authority, Administrative Fine, Compliance Audit, Penalty

Free NIS2 Terminology Packet

32 entity, incident, control, governance, and compliance terms. Submit your email and the packet is delivered to your inbox.

NIS2 Enforcement Timeline

Penalties: Essential entities face fines up to €10 million or 2% of global annual turnover (whichever is higher). Important entities face up to €7 million or 1.4% of global turnover. Article 20(1) places cybersecurity risk-management oversight on management bodies, and for essential entities Article 32(5)(b) lets competent authorities request that courts temporarily prohibit a natural person in a managerial function from exercising that role. Both are subject to Member State transposition.

NIS2 FAQ

Who must comply with NIS2?

Organizations operating in any of 18 listed sectors (energy, transport, banking, health, digital infrastructure, drinking and waste water, public administration, ICT service management, and others) that meet the size threshold of 50+ employees or €10M+ annual turnover. Smaller entities are also in scope regardless of size if they are sole providers of essential services, DNS/TLD registries, trust service providers, or public administration entities (Article 2(2)).

What is the difference between essential and important entities?

Essential entities are larger organizations in highly critical sectors (energy, transport, banking, health, drinking water, digital infrastructure, public administration) subject to ex-ante supervision and administrative fines up to €10M or 2% of global turnover. Important entities are medium-sized organizations in other NIS2 sectors subject to ex-post supervision and fines up to €7M or 1.4% of global turnover. Misclassification is itself a compliance failure.

What are the NIS2 incident reporting deadlines?

Article 23 sets three stages for reporting a significant incident: (1) an early warning to the CSIRT or competent authority within 24 hours of becoming aware of the incident, (2) an incident notification within 72 hours, and (3) a final report within one month of the notification. Intermediate and progress reports may be required on request.

What are the penalties for NIS2 non-compliance?

Essential entities face administrative fines up to €10 million or 2% of total worldwide annual turnover, whichever is higher. Important entities face up to €7 million or 1.4% of global turnover. Article 20(1) places cybersecurity risk-management oversight on management bodies, and for essential entities Article 32(5)(b) lets competent authorities request that courts temporarily prohibit a natural person in a managerial function from exercising that role. Both are subject to Member State transposition.

Cybersecurity Terminology Under Control

Build your NIS2 glossary in Confluence using the terminology packet as a starting structure. Align your IT, legal, and compliance teams on every definition. Scan your Confluence documentation for inconsistencies. Share the version history with your supervisory authority. Review our transparent app limitations for full details on what we do and don’t cover.

Evaluate in Confluence Get Free Packet

Related Compliance Resources

Compliance for Confluence — approved terms, page scanning, and audit evidence for regulated teams in Confluence

DORA Terminology — Digital Operational Resilience Act terms for financial sector ICT risk management

SOC 2 Terminology Management — 40 Trust Services Criteria terms for InfoSec & GRC teams

Compliance Guide — what auditors check and how we help, mapped to real regulatory standards

Four-Eyes Principle — approval workflows for compliance, QA, GRC, legal, security, and regulatory teams, mapped to SOX, MiFID II, and ISO 27001

Glossary App Comparison — how Confluence glossary apps compare for compliance, QA, GRC, legal, security, and regulatory teams