Agent · nis2-2022-2555-4
NIS2 artikel 4: Sector-specific Union legal acts
Structural tree: the article's own paragraphs, verbatim.
CELEX 32022L2555 · 2026-08-18 · Weight 75 · minimal-risk
OpenOpen reading. No metering is planned for this class.
- What this page is
- Agent, NIS2 artikel 4
- Checked against the official source
- 2026-08-18Current
- Responsible publisher
- ExploreWorld Legal, editorial deskLiability position
Short answer
What does NIS2 Article 4 require, and what outcome does the rule tree give?
NIS2 Article 4 is tested here by a deterministic rule tree of 7 rules, built from the article's own conditions. The tree reads your facts and names the outcome that applies, starting with Paragraph 1 applies, carrying paragraph citation, content hash and read date 2026-08-18 against CELEX 32022L2555. The outcome is a machine classification, not a compliance decision.
NIS2 Article 4Checked against the publisher 2026-08-18Official text
- Paragraph 1 applies. 1. Where sector-specific Union legal acts require essential or important entities to adopt cybersecurity risk-management measures or to notify significant incidents and where those requirements are at least equivalent in effect to the obligations laid down in this Directive, the relevant provisions of this Directive, including the provisions on supervision and enforcement laid down in Chapter VII, shall not apply to…
- Paragraph 2 applies. 2. The requirements referred to in paragraph 1 of this Article shall be considered to be equivalent in effect to the obligations laid down in this Directive where:
- Paragraph 3 applies. (a)
A source reference, not legal advice.
Jurisdiction
The same agent, read through one country's lens.
Inputs
- in_scopeThe article applies to the situationboolean
- punktParagraph of the articleenum (1 | 2 | 3 | 4 | 5 | 6 | 7)
Rule tree
If: alla(in_scope = true, punkt = 1)
Paragraph 1 applies
1. Where sector-specific Union legal acts require essential or important entities to adopt cybersecurity risk-management measures or to notify significant incidents and where those requirements are at least equivalent in effect to the obligations laid down in this Directive, the relevant provisions of this Directive, including the provisions on supervision and enforcement laid down in Chapter VII, shall not apply to…
Paragraph 1
If: alla(in_scope = true, punkt = 2)
Paragraph 2 applies
2. The requirements referred to in paragraph 1 of this Article shall be considered to be equivalent in effect to the obligations laid down in this Directive where:
Paragraph 2
If: alla(in_scope = true, punkt = 3)
Paragraph 3 applies
(a)
Paragraph 3
If: alla(in_scope = true, punkt = 4)
Paragraph 4 applies
cybersecurity risk-management measures are at least equivalent in effect to those laid down in Article 21(1) and (2); or
Paragraph 4
If: alla(in_scope = true, punkt = 5)
Paragraph 5 applies
(b)
Paragraph 5
If: alla(in_scope = true, punkt = 6)
Paragraph 6 applies
the sector-specific Union legal act provides for immediate access, where appropriate automatic and direct, to the incident notifications by the CSIRTs, the competent authorities or the single points of contact under this Directive and where requirements to notify significant incidents are at least equivalent in effect to those laid down in Article 23(1) to (6) of this Directive.
Paragraph 6
If: alla(in_scope = true, punkt = 7)
Paragraph 7 applies
3. The Commission shall, by 17 July 2023, provide guidelines clarifying the application of paragraphs 1 and 2. The Commission shall review those guidelines on a regular basis. When preparing those guidelines, the Commission shall take into account any observations of the Cooperation Group and ENISA.
Paragraph 7
If no rule matches: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.
The article text as read
- 11. Where sector-specific Union legal acts require essential or important entities to adopt cybersecurity risk-management measures or to notify significant incidents and where those requirements are at least equivalent in effect to the obligations laid down in this Directive, the relevant provisions of this Directive, including the provisions on supervision and enforcement laid down in Chapter VII, shall not apply to such entities. Where sector-specific Union legal acts do not cover all entities in a specific sector falling within the scope of this Directive, the relevant provisions of this Directive shall continue to apply to the entities not covered by those sector-specific Union legal acts.
- 22. The requirements referred to in paragraph 1 of this Article shall be considered to be equivalent in effect to the obligations laid down in this Directive where:
- 3(a)
- 4cybersecurity risk-management measures are at least equivalent in effect to those laid down in Article 21(1) and (2); or
- 5(b)
- 6the sector-specific Union legal act provides for immediate access, where appropriate automatic and direct, to the incident notifications by the CSIRTs, the competent authorities or the single points of contact under this Directive and where requirements to notify significant incidents are at least equivalent in effect to those laid down in Article 23(1) to (6) of this Directive.
- 73. The Commission shall, by 17 July 2023, provide guidelines clarifying the application of paragraphs 1 and 2. The Commission shall review those guidelines on a regular basis. When preparing those guidelines, the Commission shall take into account any observations of the Cooperation Group and ENISA.
Lineage
Interface
Hashes
Artefacts
No legal advice. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.
Citation: 32022L2555 art. 4, Sector-specific Union legal acts. ExploreWorld Legal, https://legal.exploreworldai.com/agent/nis2-2022-2555/artikel-4 (hämtad 2026-08-18, bevis sha256:1771b85012d3ad1b, bygge legal-2026-08-25).