Regulatory change

NIS2 implementing rules set technical requirements for digital-infrastructure entities

Regulatory change17 Oct 2024✓ verified 4 Jul 2026

Implementing Regulation (EU) 2024/2690 turns NIS2's open norms into concrete, testable technical requirements — and numeric 'significant incident' thresholds — for DNS, cloud, data-centre, CDN, managed-service and online-platform providers.

What changed

Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 lays down the technical and methodological requirements of the NIS2 risk-management measures for digital-sector entities — DNS service providers, TLD registries, cloud computing, data centres, content-delivery networks, managed and managed-security service providers, online marketplaces, search engines, social networks and trust service providers. Its annex spans the full control set: security policies, risk management, incident handling, business continuity and crisis management, supply-chain security, secure acquisition, technical security measures, cryptography, physical security, and HR and access management. It also specifies when an incident is 'significant' and therefore reportable, using concrete criteria such as direct financial loss above EUR 500 000 or 5% of annual turnover, service-unavailability durations that vary per service type, compromised data integrity or confidentiality through malicious action, user-impact thresholds, harm to health or life, and successful suspected-malicious unauthorised access.

Why it matters

For the digital sector, 'appropriate measures' arguments no longer suffice: the annex is a checkable control baseline, and the incident thresholds are numbers, not judgement calls. Incident-classification logic written before this regulation will not match the thresholds supervisors now apply.

Who is affected

The listed digital-infrastructure and digital-provider categories wherever they serve EU customers — in practice the security team owns the annex mapping and the incident-response team owns the new significance thresholds.
Rolessecurity teamsincident response teamscompliance teams
Organisationsdigital service providerscloud providersdigital infrastructure providersmanaged service providers

What to check next

  • Confirm whether your services fall in the covered digital-entity categories
  • Map your security controls to the annex's requirement areas and document the gaps
  • Compare your incident-classification thresholds to the regulation's significance criteria (financial loss, unavailability durations, user impact, data compromise)
  • Review supply-chain and acquisition security practices against the annex sections
  • Document the mapping — the annex is the reference a supervisor will use

Key dates

  • 2024-10-17Implementing regulation adopted (published 18 October 2024)
Source. EUR-Lex — Commission Implementing Regulation (EU) 2024/2690 ↗
Document: Commission Implementing Regulation (EU) 2024/2690 — CELEX 32024R2690
Verified by Trusq against this source on 4 Jul 2026. Trusq publishes only what it can trace to an official source; the source text prevails. Not legal advice.
Relates to NIS2
← All updates