# NIS2 Repeal Provisions — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/nis2-repeal-provisions
> Sources are cited per item. Verify against the official texts before relying on them.

The content is titled 'Repeal' from NIS2 source material, indicating it contains provisions that repeal or supersede previous legislation. This is a distinct regulatory concept requiring its own topic for proper classification of legislative replacement and transition provisions.

## Overview

## Legal Framework
Article 44 NIS2 explicitly repeals Directive (EU) 2016/1148 (the original NIS Directive) with effect from 18 October 2024. This repeal is the central legislative mechanism for replacing the old regime with the new. The article also contains a crucial reference provision: all legal references to the repealed NIS Directive must now be construed as references to NIS2, and Annex III provides a correlation table to facilitate this interpretative transition. The rationale for this comprehensive replacement is underscored by Recital 5 NIS2, which identifies that divergences in national implementation of the first directive led to market fragmentation, inconsistent levels of cyber resilience, and increased vulnerability to cross-border cyber threats.

## Practical Application
The repeal is not a simple deletion but an active substitution. From 18 October 2024, the NIS2 Directive is the sole applicable framework. In practice, this means that any existing contractual clause, national law reference, or compliance program citing the original NIS Directive must now be read as applying the corresponding provisions of NIS2. The correlation table in Annex III is the key tool for this exercise, mapping articles of the old directive to those in the new. For instance, a reference to "Article 14 of Directive (EU) 2016/1148" must be understood as pointing to its successor provision within NIS2. National legislators must ensure their existing NIS-implementing laws are fully amended or replaced to align with NIS2 by the transposition deadline, as the old directive ceases to be valid EU law.

## Key Considerations
*   **Active Reference Conversion:** Organizations must audit all documentation (contracts, policies, audit reports) for references to Directive (EU) 2016/1148 and, using Annex III, understand and apply the corresponding NIS2 obligations from 18 October 2024 onward.
*   **Monitor National Transition:** The repeal at EU level triggers national legislative action. Entities must closely monitor how their Member State transitions its specific national laws from the old NIS framework to the new NIS2 regime, as this will dictate precise compliance requirements.

## Legislation (full text of key provisions)

### Repeal

*Source: NIS2, nis2-art-44-en, 2022-12-14 — https://overview.legal/posts/96524*

Directive (EU) 2016/1148 is repealed with effect from 18 October 2024.References to the repealed Directive shall be construed as references to this Directive and shall be read in accordance with the correlation table set out in Annex III.

### Recital 6 — expanded sectoral scope for critical infrastructure

*Source: NIS2, nis2-rec-6-en, 2022-12-14 — https://overview.legal/posts/96540*

With the repeal of Directive (EU) 2016/1148, the scope of application by sectors should be extended to a larger part of the economy to provide a comprehensive coverage of sectors and services of vital importance to key societal and economic activities in the internal market. In particular, this Directive aims to overcome the shortcomings of the differentiation between operators of essential services and digital service providers, which has been proven to be obsolete, since it does not reflect the importance of the sectors or services for the societal and economic activities in the internal market.

## Guidance

### Guidelines 1/2020 on processing personal data in the context of connected vehicles and mobility related applications

*Source: EDPB, edpb-guidelines-on-processing-personal-data-in-the-context-of-connected-vehicles-and-mobility-rel, 2020-01-01 — https://overview.legal/posts/38135*

The EDPB adopted Guidelines 1/2020 to provide guidance on the application of the GDPR to the processing of personal data in connected vehicles and mobility-related applications. The guidelines address key issues including data minimisation, data protection by design and by default, transparency obligations, data subjects' rights, security, third-party data sharing, and international transfers, with practical case studies covering services provided by third parties, eCall, accidentology, anti-theft measures, and rental car information. The document does not impose fines but offers recommendations to help controllers and processors in the automotive ecosystem comply with their GDPR obligations.

## Related topics

- **NIS2 Jurisdiction and Territoriality** — https://overview.legal/topics/nis2-jurisdiction-territoriality
  This new topic is needed because NIS2 has specific provisions on jurisdiction and territoriality that determine how the regulation applies across member states 
- **DPIA** — https://overview.legal/topics/dpia
  Data Protection Impact Assessment - systematic evaluation of processing risks
- **Profiling** — https://overview.legal/topics/profiling
  Automated processing to evaluate personal aspects
- **Insurance** — https://overview.legal/topics/insurance
  Processing by insurance companies
- **GDPR Article 5 Principles of Processing** — https://overview.legal/topics/gdpr-article-5-principles
  This content specifically addresses the foundational principles of personal data processing under GDPR Article 5, which encompasses multiple related but distinc
- **IP Address** — https://overview.legal/topics/ip-adres
  Internet protocol addresses as personal data

---
Generated by overview.legal · https://overview.legal/topics/nis2-repeal-provisions · 2026-08-22
