Essential entity — EU obligations
What the obligations mean for the role of essential entity: the obligations, the articles carrying them, the workflows that get you there and what most often fails. Every row carries article, reading date and hash.
Obligations
- NIS2 — 21: Cybersecurity risk-management measures — Take appropriate cybersecurity risk-management measures.
- NIS2 — 23: Reporting obligations — Report significant incidents within the set deadlines.
Risk points
- Incident reporting is never tested before it is needed.
What forces a redo
- The node hash changes — the text behind the row is no longer the same.
- The reading date moves forward — the row has been re-read against the source.
- A timeline passes — the requirement starts to apply or tightens.
As data
- The same node as data: add ?format=json to the address, or ?format=agent for receipt and dependencies.
Workflows
Articles
Relations
Metadata
- Acts
- NIS2
- Articles
- 2
- Reading date
- 2026-08-31
- Freshness
- 74/100
- Hash
- 4c1b1ececcd2ecfa
- Corpus version
- legal-2026-08-25
- Next check
- —
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.