By: Johannes Fiegenbaum on 5/27/25, 7:58 AM · Last updated September 5, 2026
CSRD and NIS2 are two key EU regulations affecting businesses. But what’s the difference? Understanding these frameworks is essential for organizations navigating the evolving landscape of compliance, sustainability, and cybersecurity in the European Union. Both directives aim to enhance corporate responsibility but do so from distinct perspectives to one focusing on sustainability and transparency, the other on operational resilience and cyber risk management.
Quick Comparison:
| Aspect | CSRD | NIS2 |
|---|---|---|
| Focus | Sustainability reports incl. cyber risks | Cybersecurity and network protection |
| Affected companies | Large/publicly listed companies | Critical sectors (from 50 employees, €10 million revenue) |
| Security requirements | ESG reporting | Technical and organizational measures |
| Penalties | Variable, depending on country | Up to €10 million or 2% of annual revenue |
Both regulations overlap when it comes to considering cybersecurity risks. Companies should therefore develop integrated strategies to ensure efficient compliance. For example, a large energy provider may need to report on its cybersecurity posture under CSRD while also implementing technical controls and incident reporting mechanisms required by NIS2.

Live data: the Fiegenbaum Atlas provides green bond volumes, CSRD benchmarks, EU ETS prices, updated automatically. Open the dashboard.
The NIS2 Directive, which entered into force in January 2023, significantly raises the bar for cybersecurity across the EU. It broadens the scope to include more sectors and smaller organizations, introduces stricter incident reporting timelines, and holds top management personally accountable for compliance failures. According to the European Union Agency for Cybersecurity, NIS2 aims to create a high common level of cybersecurity across member states, reflecting the growing threat landscape and the increasing reliance on digital infrastructure (ENISA).
NIS2 is not the only instrument on this map: financial entities are governed by DORA, Regulation (EU) 2022/2554 (ICT risk, ICT third-party risk, operational resilience testing), and entities designated as critical under the CER Directive (EU) 2022/2557 answer for the physical resilience of their essential services. Article 4 of NIS2 stands back where such an act imposes at least equivalent requirements, so a bank reads DORA first and NIS2 only for what DORA leaves open.

CSRD and NIS2 complement each other when it comes to cybersecurity, but they have different focal points. While CSRD aims to integrate data protection and security aspects into sustainability reporting, NIS2 focuses on implementing clear technical and organizational security measures. This dual approach ensures that companies not only disclose their cyber risks but also actively manage and mitigate them.
My position on the overlap: CSRD compliance is not sustainability, and it is not security either. NIS2 incident records, control test results and the state of the risk register are worth more as an internal steering input than as a disclosure line in the sustainability statement. Where the reporting obligation drives the design, the data model gets built to fill a report and produces figures nobody steers by. Build the control system and its evidence first, then take the disclosure off it.
CSRD sets specific data protection requirements that must be considered in the context of ESG reporting:
| Area | Requirements |
|---|---|
| Governance | Supervision by company management, data protection policies |
| Risk management | Inclusion of data security risks in ESG assessments |
| Reporting | Disclosure of security incidents and preventive measures |
| Supply chain | Evaluation of data security among business partners |
Companies subject to CSRD must comprehensively document their data protection practices. This includes security strategies, risk management processes, and incident reports. The European Commission highlights that CSRD aims to bring sustainability reporting on par with financial reporting, making it more reliable and comparable (European Commission).
While CSRD integrates data protection into ESG reporting, NIS2 takes a more practical approach with clear security requirements.
The NIS2 Directive imposes stricter security requirements than its predecessor and mandates binding technical and organizational measures:
These two approaches show how companies are required by CSRD and NIS2 to implement comprehensive security measures. While CSRD is more principle-based for reporting, NIS2 defines clear technical requirements and timelines.
The CSRD (Corporate Sustainability Reporting Directive) applies to companies that meet at least two of the following criteria:
| Criterion | Threshold |
|---|---|
| Number of employees | More than 250 employees |
| Net revenue | Over €40 million |
| Balance sheet total | More than €20 million |
Implementation is phased: from 2025 for companies already covered by the NFRD (Non-Financial Reporting Directive), from 2026 for large companies not previously included, and from 2027 for listed SMEs. The latter can defer until 2028. This staged rollout allows organizations time to adapt their reporting processes and systems.
Unlike CSRD’s quantitative criteria, the NIS2 Directive is based on industry-specific requirements.
The NIS2 Directive defines its scope not by numbers, but by the relevance of specific industries. It expands the previous scope and applies to medium and large companies (from 50 employees and €10 million annual revenue) in so-called critical sectors. This includes not only traditional critical infrastructure like energy and transport, but also digital service providers, food production, and research institutions, reflecting the interconnected nature of modern supply chains (ENISA).
NIS2 distinguishes between:
Essential Entities:
Important Entities:
Large companies operating in regulated sectors must comply with both regulations. For example, an energy provider with more than 1,000 employees and more than 450 million euros in net turnover falls under both CSRD and NIS2, requiring a harmonized approach to reporting, risk management, and technical controls.
You can also revert to my CSRD Materiality Screening tool, the CSRD Climate Risk Guide or the Double Materiality Guide to find out where your company stands.
International companies face additional requirements: Non-EU companies generating over €150 million in revenue within the EU and with at least one EU branch must meet CSRD requirements from 2029 (for the 2028 financial year). The NIS2 Directive, on the other hand, applies to all companies providing essential services within the EU to regardless of where their headquarters are located. This extraterritorial reach is designed to ensure a level playing field and robust protection for the EU’s digital ecosystem (CSRwire).
CSRD focuses on disclosing cybersecurity measures in the sustainability report, while NIS2 mandates specific technical measures. This means that under CSRD, companies must be transparent about their cyber risk exposure and controls, whereas NIS2 requires them to implement and maintain concrete technical safeguards.
| Aspect | CSRD | NIS2 | DORA (financial entities) |
|---|---|---|---|
| Technical controls | No specific requirements | Multi-factor authentication, encryption | ICT risk management framework, resilience testing |
| Monitoring | Reporting on existing systems | Mandatory monitoring systems | Continuous ICT monitoring and incident classification |
| Risk assessment | Annual review | Continuous assessment | Continuous, including ICT third-party risk |
| Documentation | Public sustainability reports | Internal documentation | Register of information on ICT service provider contracts |
The table highlights the key differences. In addition, NIS2 requires further measures, such as:
For example, the European Union Agency for Cybersecurity recommends regular penetration testing and the use of advanced threat intelligence to proactively identify and mitigate vulnerabilities (ENISA IoT Security Guidelines).
Besides technical requirements, management plays a crucial role. The differences in responsibility are outlined in the next section.
DORA has applied since 17 January 2025 to the financial entities listed in its Article 2. On suppliers it goes a step further than NIS2. Besides an ICT risk management framework and incident reporting, it requires a register of information on every contractual arrangement with an ICT third-party service provider, minimum contractual content for those arrangements, and digital operational resilience testing, threat-led for the largest entities. ICT providers designated as critical fall under direct European oversight instead of being supervised only through their clients.
CSRD asks a different question: whether the topic is material and how governance handles it, not which control is installed. The DORA register, the NIS2 risk register and the governance narrative draw on the same underlying facts.
While CSRD views cybersecurity as part of sustainability reporting, NIS2 assigns direct and binding responsibility to top management. Both approaches complement each other to strengthen cybersecurity in companies.
CSRD Requirements:
NIS2 Requirements:
It’s especially important to note that violations of the NIS2 Directive can result in heavy fines, up to €10 million or 2 % of global annual turnover for essential entities. This is a significant increase from previous frameworks and is intended to drive real accountability at the executive level (Osborne Clarke).
NIS2 and CSRD differ significantly in their reporting approaches and timelines. NIS2 uses a three-stage reporting system as follows:
| Reporting stage | Time frame | Required information |
|---|---|---|
| Initial report | 24 hours | Basic incident details, possible cross-border impacts |
| Interim report | 72 hours | Technical details, damage assessment, initial countermeasures |
| Final report | 1 month | Comprehensive analysis, causes, remedial actions |
In contrast, CSRD follows the requirements of the GDPR. The focus here is on annual sustainability reporting, especially transparent disclosure of cybersecurity risks and their management. Both regulations emphasize clear reporting and impose strict penalties for violations.
NIS2 requires not only precise technical measures but also comprehensive reporting and documentation. Violations can have serious consequences, including:
The levels sit in Article 34: for essential entities a maximum of at least €10 million or 2 % of total worldwide annual turnover, whichever is higher, and for important entities a maximum of at least €7 million or 1.4 %. CSRD sets no EU-wide ceiling, its sanctions come from national transposition and differ by member state. The NIS2 dates are national too: the Article 41 deadline was 17 October 2024, several member states legislated later, and the binding date is the one in your national act. I review transposition status and fine levels twice a year.
A unique feature of NIS2 is the introduction of cross-border reporting obligations. Companies are required to specify the impact in all affected countries in their initial report. This means:
The expanded requirements also entail an obligation for complete documentation. Under NIS2, companies must retain all relevant security incident records for at least five years, including:
For companies, it will be crucial to develop integrated reporting systems that meet both the strict timelines of NIS2 and the reporting obligations of CSRD. Only then can they fully comply with both regulations. Industry experts recommend leveraging automation and digital platforms to streamline compliance and reduce manual workload (Deloitte).
To efficiently meet the requirements of CSRD and NIS2, an integrated approach to risk analysis is essential. Companies should design their assessment processes to cover both regulations simultaneously. A structured approach should include the following areas:
| Analysis Area | CSRD Aspects | NIS2 Aspects | Joint Measures |
|---|---|---|---|
| Data protection | Sustainability data, ESG metrics | Critical infrastructure data | Unified data classification system |
| Risk assessment | Climate risks, resource efficiency | Cyber threats | Integrated risk matrix |
| Monitoring | CO₂ emissions, resource consumption | Security incidents | Shared dashboard |
By introducing an integrated risk matrix, you lay the foundation for effective and unified monitoring. This approach not only streamlines compliance but also provides a holistic view of organizational risks, enabling better decision-making (Deloitte).
One sequencing error turns up repeatedly: a team builds the CSRD data model first and retro-fits the NIS2 governance evidence into it. That duplicates the management-responsibility work, because board training, role definitions and the sign-off trail end up documented twice, in two formats that do not match. Reversing the order removes the second run.
Implementing shared monitoring tools enables efficient control of both compliance areas. Key aspects include:
Four artefacts carry most of the evidence for both regimes, maintained once, referenced twice:
The scale of the problem is documented: across 1,401 European sustainability reports from the 2024 and 2025 reporting cycles, 13 percent contain no extractable Scope data at all, and 8 percent of the reports with a Scope 3 figure show it below Scope 1 or 2. Compliance without comparable figures is a photograph, not a steering instrument.
After aligning risk analysis and monitoring, implementing both regulations requires a cost-efficient approach. Key steps include:
In summary, the intersection of CSRD and NIS2 presents both challenges and opportunities. By adopting integrated strategies, leveraging technology, and fostering a culture of compliance, organizations can not only meet regulatory requirements but also strengthen their resilience and reputation in a rapidly evolving business environment.
CSRD (Corporate Sustainability Reporting Directive) focuses on environmental, social, and governance (ESG) disclosure and sustainability reporting, including biodiversity and TNFD (Taskforce on Nature-related Financial Disclosures) requirements. NIS2 (Network and Information Security Directive 2) concentrates on cybersecurity risk management, incident reporting, and digital resilience across critical sectors. While CSRD is about transparent reporting of sustainability impacts, NIS2 is about protecting information systems and critical infrastructure from cyber threats.
CSRD applies to large EU companies (250+ employees, €50M+ turnover, or €25M+ assets), listed SMEs (with a 3-year transition period), and non-EU companies with significant EU revenues. NIS2 applies to operators of essential services (energy, transport, water, health, finance) and important digital service providers (cloud, DNS, content delivery networks) in the EU, with stricter requirements for critical entities and basic cyber hygiene requirements for other businesses. Some large enterprises will need to comply with both directives simultaneously.
CSRD applies to companies with more than 1,000 employees and more than 450 million euro in net turnover, with both criteria required to trigger the reporting obligation. The obligation applies to financial years starting from January 1, 2027, with first reports due in 2028. Listed SMEs are fully exempt, and there is no phased wave structure. Non-EU companies fall into scope once their EU branch or subsidiary turnover exceeds 200 million euro combined with more than 450 million euro in EU-wide turnover. NIS2 entered into force in December 2022 and had to be transposed by 17 October 2024, but the dates that bind a company come from the national act, so they differ across member states.
DORA, Regulation (EU) 2022/2554, covers financial entities: banks, insurers and reinsurers, investment firms, payment institutions, crypto-asset service providers, trading venues and fund managers, among the types listed in its Article 2. It has applied since 17 January 2025. Article 4 of NIS2 gives precedence to sector-specific acts with at least equivalent requirements, so for ICT risk management and ICT-related incident reporting a financial entity follows DORA instead of the corresponding NIS2 provisions. A group can still be caught by NIS2 through a subsidiary that is not itself a financial entity.
CSRD sets no EU-wide fine level. Sanctions follow national transposition, so the ceiling, the competent authority and the exposure of individual board members differ by member state. NIS2 does set levels, in Article 34: essential entities face a maximum of at least €10 million or 2 % of total worldwide annual turnover, whichever is higher, and important entities a maximum of at least €7 million or 1.4 %. Supervisors of essential entities can additionally suspend a certification and temporarily bar a person from management functions.
Companies should develop an integrated governance framework where sustainability reporting (CSRD) and cybersecurity management (NIS2) are coordinated under a single compliance program, with shared risk assessments and overlapping data systems. Maintain the policy, the risk register, the board minutes and the incident log once and reference them from both regimes instead of building parallel documentation. Establish a cross-functional team spanning sustainability, IT security, legal, and risk management, and start from the control system rather than from the reporting template.
ESG and sustainability consultant based in Hamburg, specialised in VSME reporting and climate risk analysis. Has supported 300+ projects for companies and financial institutions, from mid-sized manufacturers to major banks and insurers.
More aboutSustainability is not just an obligation, but an opportunity for SMEs. Companies that integrate ESG criteria (Environmental, Social, Governance) into their strategy benefit from ...
Read more →