Research the NIS2 Directive
with trusted AI.

Cite the Directive to the article. Classify essential and important entities in seconds. Ready as enforcement and the first audits ramp up.

European Union Austria Belgium Bulgaria Croatia Cyprus Czech Republic Denmark Estonia Finland France Germany Greece Hungary Ireland Italy Latvia Lithuania Luxembourg Malta Netherlands Poland Portugal Romania Slovakia Slovenia Spain Sweden United Kingdom Norway Switzerland Iceland Liechtenstein

Built for NIS2. Ready for the regulator.

A modern glass tower against the sky
17 Oct 2024 transposition deadline passed
A legal library overlooking a European cathedral
2 entity classes essential vs important
A modern glass tower at dusk
18 sectors Annex I & Annex II
A private boardroom overlooking a European city
24h / 72h early warning & notification
A boardroom overlooking a European cityscape
€10M or 2% max fine, Article 34
A modern legal office
Jun 2026 first audits ramping up
NIS2 coverage
Directive text · National transpositions · Implementing acts · ENISA guidance · CER Directive cross-refs · Competent-authority decisions
How it works

From your documents to a full cyber-risk file.

Upload

Drop your cyber-risk-management policy, incident playbook, supplier register, or management-accountability matrix straight into the chat. Documents persist across the whole conversation.

Ask

Classify your organisation as essential or important, map Article 21 risk-management duties, check incident-reporting timelines, or compare national transpositions across member states, cross-referenced to the Directive, ENISA guidance, and national law.

Export

A citation-backed report with paragraph-level gaps, obligation by obligation, ready to drop into your cyber-risk file or board-level liability briefing.

What incident-reporting timelines does NIS2 impose?

Article 23: a three-stage reporting cascade

Under Article 23 of Directive (EU) 2022/2555, essential and important entities must notify significant incidents through a staged cascade to the CSIRT or competent authority.

The timelines

  • Early warning within 24 hours of becoming aware (Art. 23(4)(a)) — flag if the incident is suspected unlawful/malicious or has cross-border impact
  • Incident notification within 72 hours (Art. 23(4)(b)) — update plus an initial assessment of severity, impact, and indicators of compromise
  • Final report within 1 month (Art. 23(4)(d)) — root cause, mitigation, and cross-border impact

What counts as significant

Art. 23(3): an incident is significant where it has caused or is capable of causing severe operational disruption or financial loss, or considerable material or non-material damage. Management bodies bear personal accountability under Article 20.

Trusted by legal and AI-governance teams across Europe.

"

The best AI for any research related to EU law and regulations. It always comes up with the best answer.

"

eulaw.ai is the only tool I trust for EU regulation. It has cut our compliance research time by at least 30%.

"

eulaw.ai enables us to take on clients from industries and jurisdictions we previously would have had to decline.

"

A single fabricated case citation can lead to professional sanctions. eulaw.ai is built so there is no fabricated legislation or case law: every reference traces back to a source in your results.

Your NIS2 work stays inside the EU.

EU Data Residency

Your documentation, queries, and chat history are stored and processed only within the EU.

Built for GDPR

Engineered for full GDPR compliance, so NIS2 research never works against your data-protection duties.

No Model Training

Your cyber-risk files never train AI models. Model providers never receive or store your content.

Encryption

All customer data is encrypted at rest and in transit using modern protocols including TLS 1.3.

ISO 27001:2022 & SOC 2

Run from ISO 27001:2022 and SOC 2 certified data centres.

Audits & Vulnerability

Regular external security reviews, with continuous vulnerability scanning.

Your first NIS2 citation in 30 seconds.

Free trial · no credit card · cancel anytime.