Guide

NIS2 and universities: are you in scope?

The NIS2 Directive does not list universities as a sector, yet many European universities are now covered by it, and others are not. This guide explains the three routes into scope, what nine national laws say on 7 October 2026, what NIS2 means for supplier and vendor assessment, and how its incident reporting differs from the GDPR's 72 hours.

Published 7 October 2026 · Sources checked 7 October 2026

The short version

Contents

  1. NIS2 in brief
  2. Three routes into scope for universities
  3. Size rules, essential and important entities
  4. Transposition status in nine countries
  5. What in-scope universities must do
  6. Supply chain security and vendor assessment
  7. Incident reporting: NIS2 and the GDPR side by side
  8. Pending EU changes
  9. Checklist
  10. Sources
  11. About this page

1. NIS2 in brief

The NIS2 Directive sets cybersecurity risk-management and incident reporting duties for "essential" and "important" entities in the sectors listed in its Annex I (sectors of high criticality, such as energy, health, digital infrastructure and public administration) and Annex II (other critical sectors, such as digital providers and research). Member States had to adopt and publish their transposition measures by 17 October 2024 and apply them from 18 October 2024 (Art. 41).

Because NIS2 is a directive, the duties reach a university only through national law, and national law is where the scope decisions for higher education are made. The Commission sent reasoned opinions to 19 Member States in May 2025 for failing to notify full transposition. On 8 July 2026 it referred four of them (Ireland, Spain, France and the Netherlands) to the Court of Justice; the Commission said that most Member States had complied by then.

2. Three routes into scope for universities

Route 1: The research sector (usually not)

Annex II lists "research organisations". NIS2 defines a research organisation as an entity whose primary goal is to conduct applied research or experimental development with a view to exploiting the results for commercial purposes, "but which does not include educational institutions" (Art. 6(41)). Recital 36 adds that the category covers entities focused on applied research or experimental development for commercial exploitation. A university is therefore not in scope merely because it does research. Separate research institutes, spin-outs or contract research organisations may be.

Route 2: Public administration

Annex I covers public administration entities of central government, and at regional level following a risk-based assessment, "as defined by a Member State in accordance with national law" (Art. 2(2)(f)). Central government public administration entities are essential entities regardless of size (Art. 3(1)(d)). To count as a public administration entity, a body must meet the criteria in Art. 6(35), including the power to address administrative or regulatory decisions to people affecting their rights in the cross-border movement of persons, goods, services or capital. Where universities are state agencies, as in Sweden, this route matters, and national lawmakers have had to decide whether a university's decisions meet that test.

Route 3: The education option in Article 2(5)(b)

Member States "may provide for this Directive to apply to" education institutions, "in particular where they carry out critical research activities" (Art. 2(5)(b)). This is the option most relevant to universities, and it is where the countries below differ most.

Validemic's analysis There is also a fourth, less obvious route. A university that itself carries out an activity listed in the annexes, for example running a hospital, a district heating plant or a data centre service for third parties, may be in scope for that activity. The Swedish higher education association's January 2026 webinar on scope, for instance, examined whether institutions are covered for activities in research, health care or cloud services. Check your own activities against the national annex, not just your status as a university.

3. Size rules, essential and important entities

For the sectors in the annexes, NIS2 generally applies to entities that are medium-sized or larger under Commission Recommendation 2003/361/EC (Art. 2(1)). The Commission's SME definition sets these ceilings:

CategoryStaffTurnoveror Balance sheet
Small< 50≤ EUR 10 million≤ EUR 10 million
Medium-sized< 250≤ EUR 50 million≤ EUR 43 million

Some entities are covered regardless of size, including central government public administration entities and entities a Member State identifies as critical (Art. 2(2)). Entities of an Annex I type above the medium-sized ceilings are essential; most others in scope are important (Art. 3). The difference matters mainly for supervision and fines: Member States must provide maximum fines of at least EUR 10 million or 2% of worldwide turnover for essential entities and EUR 7 million or 1.4% for important entities (Art. 34(4) and (5)), but each Member State decides whether and to what extent fines can be imposed on public administration entities (Art. 34(7)).

Validemic's analysis Most comprehensive universities exceed the medium-sized staff ceiling, so where national law brings them in, size rarely keeps them out. The classification as essential or important then depends on the national route used.

4. Transposition status in nine countries

The table summarises what we could verify from national legislation, government documents and the Commission on 7 October 2026. The Commission's per-country NIS2 pages were last updated in July 2025 and do not reflect later laws, so we relied on national sources where available. "Not found" means we could not confirm the point from a primary source, not that the answer is no.

CountryNational law and statusUniversities
SwedenIn force Cybersecurity Act (2025:1506) and Cybersecurity Ordinance (2025:1507), in force 15 January 2026.Private degree-awarding institutions are covered if medium-sized or larger or of special importance, with exemptions possible by decision. State universities are covered only as state agencies meeting the cross-border decision criterion (1 ch. 3 §), or if designated. The government bill rejected the inquiry's proposal to cover all state universities.
FinlandIn force Cybersecurity Act (124/2025), in force 8 April 2025.The Annex II research entry expressly excludes higher education institutions and other education institutions. Public administration is regulated through the Act on Information Management in Public Administration (906/2019). Whether a given university falls under that route: not determined here.
Norway (EEA)Not incorporated NIS2 is under scrutiny for incorporation into the EEA Agreement (draft Joint Committee Decision under consideration). The Digital Security Act, in force 1 October 2025, implements the first NIS Directive.No NIS2 duties in Norwegian law yet. Education is not among the Digital Security Act's sectors.
DenmarkIn force NIS 2 Act (Act no. 434 of 6 May 2025), in force 1 July 2025.Research organisations exclude education institutions. The competent minister may lay down rules applying the Act to education institutions (§ 1(7)). Such rules: not found.
NetherlandsIn force Cybersecurity Act (Cyberbeveiligingswet), in force 15 August 2026.The government is designating funded universities and universities of applied sciences as important entities via a ministerial regulation, consulted from 12 June 2026. Registration and incident reporting apply on designation; the duty of care applies 36 months later. Regulation in force on 7 October 2026: not found.
BelgiumIn force NIS2 Act of 26 April 2024, in force 18 October 2024. The Commission lists Belgium as transposed.Not found: we could not confirm from a primary source whether Belgium uses the education option. Check with the Centre for Cybersecurity Belgium.
IrelandNot transposed General Scheme of the National Cyber Security Bill published 30 August 2024. We did not find the Bill in the Oireachtas bills database. Referred to the Court of Justice on 8 July 2026.Not found.
GermanyIn force NIS2 Implementation Act of 2 December 2025 (BGBl. 2025 I No. 301), which replaced the BSI Act (BSIG). The BSI states that the registration deadline has passed.The BSIG says educational institutions are not research institutions. Universities are mostly run by the Länder, whose own rules we did not review: not found.
FranceBill pending Bill on the resilience of critical infrastructure and strengthening cybersecurity, adopted by the Senate on 12 March 2025; Assemblée nationale committee report 10 September 2025. Referred to the Court of Justice on 8 July 2026.The Senate text covers "education establishments carrying out research activities": essential if designated by order of the Prime Minister, otherwise important, with exemptions for low-impact establishments. Not yet law.

Notes on Sweden and the Netherlands

Sweden shows how much turns on the public administration test. In the government bill (prop. 2025/26:28, section 5.3.4) the government counts 16 state universities, 15 state university colleges and 18 private degree-awarding providers. It decided that only state universities with the power to take decisions affecting cross-border movement should be covered, and it describes as too extensive an interpretation under which ordinary decisions, such as on employment, would meet the test. The Association of Swedish Higher Education Institutions (SUHF) told members in a January 2026 webinar that each institution must take its own position, and that in its view it is a more than reasonable reading that state institutions are not covered on that ground alone. Supervision of private providers sits with six county administrative boards (Cybersecurity Ordinance, § 9).

The Netherlands chose the education option deliberately. In April 2025 the education minister told parliament that funded higher education institutions would be brought under the Act, while secondary vocational education (mbo) and non-funded providers would not. A June 2026 letter set out the detail: designation as important (not essential) entities, the Inspectorate of Education as supervisor, SURFcert as the intended CSIRT, incident thresholds set in the regulation, and a 36-month delay before the duty of care and its supervision apply.

5. What in-scope universities must do

National laws transpose four core duties, sometimes with local detail:

Validemic's analysis For many universities the measures themselves are not new: the Dutch minister noted in 2025 that the Act's substantive norms largely match what Dutch institutions already do under sector agreements. What changes is external supervision, management accountability and the need to show evidence, including evidence about suppliers.

6. Supply chain security and vendor assessment

Article 21(2)(d) requires "supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers". Article 21(3) adds that entities must take into account the vulnerabilities specific to each direct supplier, the overall quality of their products and cybersecurity practices, including secure development procedures, and the results of EU coordinated risk assessments of critical supply chains.

NIS2 does not prescribe a supplier questionnaire for universities. The most detailed EU text is Commission Implementing Regulation (EU) 2024/2690, which applies directly only to certain digital providers (such as cloud, data centre and managed service providers) but is a useful benchmark. ENISA published technical implementation guidance for it in June 2025. Its supply chain section requires a supplier security policy and, among other things:

This maps closely onto a good GDPR vendor assessment. The difference is the angle: the GDPR asks whether a processor provides "sufficient guarantees" for personal data (Art. 28(1)), while NIS2 asks whether the supplier relationship creates risks to the security of the university's network and information systems, whether or not personal data is involved.

Validemic's analysis In practice universities can run one supplier process with two lenses. Practical steps:

Our vendor assessment guide for universities sets out the full process, and HECVAT for European universities offers a free questionnaire you can extend with these questions. Fact sheets on widely used platforms such as Microsoft Teams, Zoom and Canvas summarise what vendors document publicly.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

7. Incident reporting: NIS2 and the GDPR side by side

The two regimes answer different questions. NIS2 looks at incidents that significantly affect the services an entity provides; the GDPR looks at breaches affecting personal data. One ransomware attack can trigger both.

NIS2 (Art. 23)GDPR (Arts. 33 and 34)
What is reportedSignificant incidents: severe operational disruption or financial loss, or considerable damage to othersPersonal data breaches, unless unlikely to result in a risk to individuals
To whomCSIRT or competent authority; recipients of services where appropriateData protection authority; data subjects if high risk
First deadlineEarly warning within 24 hours of awarenessWithout undue delay, where feasible within 72 hours of awareness
Second stepIncident notification within 72 hours, with initial assessmentFurther information in phases without undue further delay
Final stepFinal report within one month of the incident notificationNo fixed final report; documentation under Art. 33(5)
Below thresholdVoluntary reporting possible (Art. 30)Must still be documented internally

National laws keep these timelines; Sweden's Cybersecurity Act, for example, uses 24 and 72 hours, and Finland's uses 24 and 72 hours from detection. Where a NIS2 authority finds an infringement that can entail a personal data breach notifiable under the GDPR, it must inform the data protection authority (Art. 35). Our guide to personal data breach response for universities covers the GDPR side in detail, with a free response kit.

8. Pending EU changes

Pending: on 20 January 2026 the Commission proposed targeted amendments to NIS2 as part of a cybersecurity package, aimed at legal clarity and simpler compliance. Separately, the Digital Omnibus proposal of 19 November 2025 (COM(2025) 837) would create a single entry point for incident reporting under NIS2, the GDPR and other laws, and would extend the GDPR authority notification deadline to 96 hours. On 7 October 2026 the European Parliament lists the Digital Omnibus as awaiting committee decision. Neither proposal changes the rules in force today.

9. Checklist

Scope

Governance and measures

Suppliers

Sources

  1. Directive (EU) 2022/2555 (NIS2), Articles 2, 3, 6, 20, 21, 23, 30, 34, 35, 41, Annexes I and II and Recital 36 (retrieved 7 October 2026).
  2. European Commission: SME definition (Recommendation 2003/361/EC thresholds) (retrieved 7 October 2026).
  3. European Commission: NIS2 Directive transposition in EU countries and the per-country pages for Sweden, Finland, Denmark, the Netherlands, Belgium, Ireland, Germany and France (retrieved 7 October 2026).
  4. European Commission: Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice, 8 July 2026 (retrieved 7 October 2026).
  5. European Commission: NIS2 Directive, including the 20 January 2026 targeted amendments (retrieved 7 October 2026).
  6. Commission Implementing Regulation (EU) 2024/2690, Annex, section 5 (supply chain security) (retrieved 7 October 2026).
  7. ENISA: NIS2 Technical Implementation Guidance, published 26 June 2025 (retrieved 7 October 2026).
  8. Sweden: Cybersäkerhetslag (2025:1506) and Cybersäkerhetsförordning (2025:1507) (retrieved 7 October 2026).
  9. Sweden: Government bill prop. 2025/26:28, section 5.3.4 (retrieved 7 October 2026).
  10. SUHF: webinar slides on the scope of the Cybersecurity Act, 29 January 2026 (retrieved 7 October 2026).
  11. Finland: Kyberturvallisuuslaki (124/2025), consolidated text via Finlex open data (retrieved 7 October 2026).
  12. EFTA: EEA-Lex entry for Directive (EU) 2022/2555 and Norway: Digitalsikkerhetsloven (LOV-2023-12-20-108) (retrieved 7 October 2026).
  13. Denmark: NIS 2-loven (lov nr. 434 af 6. maj 2025) (retrieved 7 October 2026).
  14. Netherlands: Rijksoverheid, Cyberbeveiligingswet in force from 15 August 2026, 7 July 2026; Kamerstukken II 2024/25, 31 288, nr. 1189 (24 April 2025); Kamerstukken II 2025/26, 26 643, nr. 1535 (retrieved 7 October 2026).
  15. Ireland: General Scheme of the National Cyber Security Bill 2024 and the Oireachtas bills database (retrieved 7 October 2026).
  16. Germany: BSI-Gesetz as enacted by the Act of 2 December 2025 (BGBl. 2025 I Nr. 301), § 2, and BSI: NIS-2-regulierte Unternehmen (retrieved 7 October 2026).
  17. France: Sénat legislative file, résilience des infrastructures critiques et renforcement de la cybersécurité, and text adopted by the Senate on 12 March 2025 (retrieved 7 October 2026).
  18. European Parliament Legislative Observatory, procedure 2025/0360(COD), Digital Omnibus (retrieved 7 October 2026).

About this page

Sources checked on 7 October 2026. We read the NIS2 text and Implementing Regulation (EU) 2024/2690 in the versions published by the EU Publications Office, the national laws and parliamentary documents listed above in their original languages, and the Commission, ENISA, EFTA and European Parliament pages. Belgium's scope for education and the German Länder rules could not be verified and are marked "not found". Where we give our own interpretation, it is labelled as Validemic's analysis. This page is general information, not legal advice. National transposition is still moving, and we will update the table when laws, designations or the EU amendments change. If you spot an error or have a primary source for a "not found" entry, please contact us and we will correct it.

Frequently asked questions

Are universities covered by NIS2?

Not automatically. Higher education is not one of the sectors in Annexes I and II, and the definition of research organisation excludes educational institutions. Universities come into scope where a Member State uses the option in Art. 2(5)(b) for education institutions, where they are public administration entities under national law, or where they carry out another listed activity. The answer is therefore national.

Which countries have brought universities under NIS2?

On 7 October 2026: the Netherlands is designating funded universities and universities of applied sciences as important entities through a ministerial regulation (draft consulted from June 2026); Sweden covers private degree-awarding institutions and state universities only where they meet the public administration criteria; France's pending bill would cover education establishments carrying out research. Finland's and Denmark's laws exclude education institutions from the research category.

What are the NIS2 incident reporting deadlines?

For a significant incident: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, and a final report within one month of the incident notification (Art. 23(4)). These run in parallel with any GDPR breach notification to the data protection authority.

Does NIS2 require universities to assess their suppliers?

In-scope entities must take measures that include supply chain security, covering security aspects of relationships with direct suppliers and service providers (Art. 21(2)(d)), taking into account each supplier's vulnerabilities and the quality of its products and cybersecurity practices (Art. 21(3)).

Is NIS2 in force in Norway?

No. NIS2 is marked as EEA relevant and is under scrutiny for incorporation into the EEA Agreement, with a draft Joint Committee Decision under consideration. Norway's Digital Security Act, in force since 1 October 2025, implements the first NIS Directive.

Our university is not in scope. Should we ignore NIS2?

Not entirely. Many of your suppliers (cloud, data centre and managed service providers) are in scope, and the security measures in Art. 21 are a reasonable benchmark for any institution. Scope can also change through national designation or the pending EU amendments.