{
  "attribution": {
    "source": "legal.exploreworldai.com",
    "canonical": "https://legal.exploreworldai.com/api/public/v1/compliance",
    "cite_as": "NovaCopilot, legal.exploreworldai.com (https://legal.exploreworldai.com/api/public/v1/compliance)",
    "license": "https://legal.exploreworldai.com/revision",
    "version": "legal-2026-10-03",
    "fingerprint": "ewai:eu:e75645",
    "proof": "sha256:5017977a128f3de9c04e02294e9c6a488c547724e87bd1b6edbb545f55cb237c",
    "jurisdiction": "eu",
    "lang": "en",
    "publisher": "NovaCopilot by ExploreWorld Legal",
    "terms": "https://legal.exploreworldai.com/om"
  },
  "brand_source": "Source: NovaCopilot",
  "brand": {
    "product": "NovaCopilot",
    "platform": "ExploreWorldAI",
    "infrastructure": "ExploreWorld Legal",
    "infrastructure_url": "legal.exploreworldai.com",
    "legal_entity": "Valkiv Ventures AB",
    "permanent_url": "https://legal.exploreworldai.com/novacopilot",
    "source": "Source: NovaCopilot",
    "powered_by": "Powered by NovaCopilot",
    "license": "https://legal.exploreworldai.com/licensvillkor",
    "contact": "stig@valkiv.com"
  },
  "item": {
    "schema_version": "1.0.0",
    "id": "compliance:nis2:essential-entity",
    "act": {
      "id": "nis2",
      "slug": "nis2-2022-2555",
      "celex": "32022L2555",
      "name": "NIS2: Directive (EU) 2022/2555",
      "official_source": "https://eur-lex.europa.eu/eli/dir/2022/2555/oj",
      "consolidated": null,
      "in_force": "2023-01-16",
      "applies": "2024-10-17",
      "applies_kind": "transposition"
    },
    "role": "essential-entity",
    "obligations": [
      {
        "article": "21",
        "title": "Cybersecurity risk-management measures",
        "duty": "Take appropriate cybersecurity risk-management measures.",
        "page": "https://legal.exploreworldai.com/eu/rattsakter/nis2-2022-2555/artikel-21",
        "obligation_id": "obligation:eu:nis2-art-21-essential-entity",
        "obligation_object": "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:nis2-art-21-essential-entity",
        "duty_kind": "summary",
        "source_text": {
          "content_kind": "official_text",
          "lang": "en",
          "label": "Article 21",
          "title": "Cybersecurity risk-management measures",
          "paragraphs": [
            "1. Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services, and to prevent or minimise the impact of incidents on recipients of their services and on other services.",
            "Taking into account the state-of-the-art and, where applicable, relevant European and international standards, as well as the cost of implementation, the measures referred to in the first subparagraph shall ensure a level of security of network and information systems appropriate to the risks posed. When assessing the proportionality of those measures, due account shall be taken of the degree of the entity’s exposure to risks, the entity’s size and the likelihood of occurrence of incidents and their severity, including their societal and economic impact.",
            "2. The measures referred to in paragraph 1 shall be based on an all-hazards approach that aims to protect network and information systems and the physical environment of those systems from incidents, and shall include at least the following:",
            "(a) policies on risk analysis and information system security;",
            "(b) incident handling;",
            "(c) business continuity, such as backup management and disaster recovery, and crisis management;",
            "(d) supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers;",
            "(e) security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure;",
            "(f)"
          ],
          "truncated": true,
          "official_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32022L2555#art_21",
          "read_at": "2026-08-18",
          "sha256": "8deee045d61a74abcc68bccc68d070275af2b601bfa500b82b308ab1c85865f4",
          "complete": false,
          "completeness_note": "Utdraget omfattar artikelns första stycken, ordagrant. Resten av artikeln finns på official_url. Citera aldrig utdraget som hela artikeln."
        }
      },
      {
        "article": "23",
        "title": "Reporting obligations",
        "duty": "Report significant incidents within the set deadlines.",
        "page": "https://legal.exploreworldai.com/eu/rattsakter/nis2-2022-2555/artikel-23",
        "obligation_id": "obligation:eu:nis2-art-23-essential-entity",
        "obligation_object": "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:nis2-art-23-essential-entity",
        "duty_kind": "summary",
        "source_text": {
          "content_kind": "official_text",
          "lang": "en",
          "label": "Article 23",
          "title": "Reporting obligations",
          "paragraphs": [
            "1. Each Member State shall ensure that essential and important entities notify, without undue delay, its CSIRT or, where applicable, its competent authority in accordance with paragraph 4 of any incident that has a significant impact on the provision of their services as referred to in paragraph 3 (significant incident). Where appropriate, entities concerned shall notify, without undue delay, the recipients of their services of significant incidents that are likely to adversely affect the provision of those services. Each Member State shall ensure that those entities report, inter alia, any information enabling the CSIRT or, where applicable, the competent authority to determine any cross-border impact of the incident. The mere act of notification shall not subject the notifying entity to increased liability.",
            "Where the entities concerned notify the competent authority of a significant incident under the first subparagraph, the Member State shall ensure that that competent authority forwards the notification to the CSIRT upon receipt.",
            "In the case of a cross-border or cross-sectoral significant incident, Member States shall ensure that their single points of contact are provided in due time with relevant information notified in accordance with paragraph 4.",
            "2. Where applicable, Member States shall ensure that essential and important entities communicate, without undue delay, to the recipients of their services that are potentially affected by a significant cyber threat any measures or remedies that those recipients are able to take in response to that threat. Where appropriate, the entities shall also inform those recipients of the significant cyber threat itself.",
            "3. An incident shall be considered to be significant if:",
            "(a) it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned;",
            "(b) it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage.",
            "4. Member States shall ensure that, for the purpose of notification under paragraph 1, the entities concerned submit to the CSIRT or, where applicable, the competent authority:",
            "(a) without undue delay and in any event within 24 hours of becoming aware of the significant incident, an early warning, which, where applicable, shall indicate whether the significant incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact;",
            "(b) without undue delay and in any event within 72 hours of becoming aware of the significant incident, an incident notification, which, where applicable, shall update the information referred to in point (a) and indicate an initial assessment of the significant incident, including its severity and impact, as well as, where available, the indicators of compromise;"
          ],
          "truncated": true,
          "official_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32022L2555#art_23",
          "read_at": "2026-08-18",
          "sha256": "595901bbe0a1d5a1bf2b23c741ec965c8efc46dec8d34b1aae69f9892670e181",
          "complete": false,
          "completeness_note": "Utdraget omfattar artikelns första stycken, ordagrant. Resten av artikeln finns på official_url. Citera aldrig utdraget som hela artikeln."
        }
      }
    ],
    "national_implementation": [
      {
        "jurisdiction": "SE",
        "sfs": "2018:1174",
        "title": "Lag om informationssäkerhet för samhällsviktiga och digitala tjänster",
        "short": "NIS-lagen",
        "relation": "Genomför direktiv (EU) 2016/1148, efterföljt av direktiv (EU) 2022/2555",
        "official_text": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/_sfs-2018-1174/",
        "law_graph": "https://legal.exploreworldai.com/api/public/v1/graph/law?act=informationssakerhetslagen"
      }
    ],
    "read_at": "2026-08-31",
    "sha256": "749e83223c1391d1adef14e26e9a58d01610af1c86b4d899902b5290ef718109",
    "industries": [],
    "freshness": {
      "index": 62,
      "readAt": "2026-08-31",
      "ageDays": 34,
      "cadenceDays": 30,
      "nextCheck": "2026-09-30",
      "state": "due",
      "stateLabel": "Omläsning inplanerad"
    },
    "stay_current": {
      "cursor": "MjAyNi0wOS0xMH5zZX52aXNzZWxibGFzYXJsYWdlbg",
      "chain_hash": "b2e9562b24e7de637742b1660609c2d36eb107fbb6c5ca8041be4979b823290d",
      "changes": "https://legal.exploreworldai.com/api/public/v1/changes/cursor?after=MjAyNi0wOS0xMH5zZX52aXNzZWxibGFzYXJsYWdlbg",
      "verify": "https://legal.exploreworldai.com/api/public/v1/changes/verify?cursor=MjAyNi0wOS0xMH5zZX52aXNzZWxibGFzYXJsYWdlbg&chain_hash=b2e9562b24e7de637742b1660609c2d36eb107fbb6c5ca8041be4979b823290d",
      "poll_after_seconds": 3600
    },
    "permanent_url": "https://legal.exploreworldai.com/api/public/v1/compliance?act=nis2-2022-2555&role=essential-entity",
    "method": "Skyldigheter ur registrets egna rader, artikel för artikel. Inget tolkas eller läggs till.",
    "official_text_coverage": {
      "quoted": 2,
      "total": 2
    },
    "content_kind_rule": "Endast source_text är lagens egen lydelse. duty är en kort sammanfattning, ej juristgranskad."
  },
  "explore": {
    "brand_source": "Source: NovaCopilot",
    "brand": {
      "product": "NovaCopilot",
      "platform": "ExploreWorldAI",
      "infrastructure": "ExploreWorld Legal",
      "infrastructure_url": "legal.exploreworldai.com",
      "legal_entity": "Valkiv Ventures AB",
      "permanent_url": "https://legal.exploreworldai.com/novacopilot",
      "source": "Source: NovaCopilot",
      "powered_by": "Powered by NovaCopilot",
      "license": "https://legal.exploreworldai.com/licensvillkor",
      "contact": "stig@valkiv.com"
    },
    "data_model": "https://legal.exploreworldai.com/api/public/v1/data-model",
    "relations": "https://legal.exploreworldai.com/api/public/v1/relations?id=compliance%3Anis2-2022-2555%3Aessential-entity",
    "risk": "https://legal.exploreworldai.com/api/public/v1/risk?id=compliance%3Anis2-2022-2555%3Aessential-entity",
    "changes": "https://legal.exploreworldai.com/api/public/v1/changes/cursor",
    "partner_entries": "https://legal.exploreworldai.com/api/public/v1/partner-entry",
    "source": "Source: NovaCopilot"
  },
  "hash": "sha256:5017977a128f3de9c04e02294e9c6a488c547724e87bd1b6edbb545f55cb237c",
  "version": "legal-2026-10-03",
  "expires": "2026-10-07T00:00:00.000Z",
  "dependency": {
    "index_version": "legal-2026-10-03+legal-2026-10-03+2026-10-03T20:27:06",
    "content_hash": "sha256:5017977a128f3de9c04e02294e9c6a488c547724e87bd1b6edbb545f55cb237c",
    "revalidate_after": "2026-10-04T04:33:45.077Z",
    "max_copy_age_seconds": 3600,
    "policy": "revalidate-required; attribution-preferred",
    "changelog": "https://legal.exploreworldai.com/api/public/v1/dependency",
    "verify": "https://legal.exploreworldai.com/api/public/v1/verify",
    "stale_copy_invalid": true
  },
  "canonical": "https://legal.exploreworldai.com/api/public/v1/compliance",
  "disclaimer": "Source reference with official identifier. Not legal advice and not a compliance decision.",
  "content_notice": {
    "legal_advice": false,
    "nature": "Source register. Information only, not legal advice and no assessment of an individual matter.",
    "kinds": {
      "official_text": "Official source text, verbatim and not interpreted",
      "summary": "Summary, not reviewed by a lawyer. Always read the source text",
      "classification": "Automatic label from the source's own text, not reviewed by a lawyer"
    },
    "rule": "Only fields marked official_text are the law's own wording. Everything else points to it.",
    "report_error": "https://legal.exploreworldai.com/api/public/v1/corrections",
    "ai_act_declaration": "https://legal.exploreworldai.com/api/public/v1/ai-act-declaration"
  },
  "usageInfo": "https://legal.exploreworldai.com/citering"
}