Most NIS2 calendars stop at the transposition deadline, which was a deadline for governments. The dates that decide whether your organisation is in breach are national, they are not synchronised, and registering on time tells you nothing about the two obligations that follow it.
The Cyberbeveiligingswet took effect on 15 August 2026. Eight thousand entities moved from preparing to being supervised, registration stopped being voluntary, and a Court of Justice case that was filed a month earlier is still running.
In July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice over NIS2, asking for financial sanctions. The penalties fall on the states. The obligations, awkwardly, do not wait for them.
Depending on which NIS2 transposition tracker you open, between 18 and 23 member states have transposed. They are not contradicting each other. They are counting different things, and only one of the things they count is the one you need.
No, and the reason is more useful than the answer. A certificate proves you run a management system. NIS2 asks which measures you implemented. Those are different questions, and the gap between them is exactly the Statement of Applicability.
Almost every NIS2 conversation is about fines. Almost no NIS2 enforcement starts there. What supervisors actually do is inspect, and whether they can inspect you without a reason at all depends on one word in your classification.
Most incident response plans lose the first day of an article 23 deadline deciding whether the deadline has started. The directive is clearer than the confusion suggests — and the fix is a decision rule, not a faster escalation path.
The organisations most exposed to NIS2 enforcement are not the ones with weak controls. They are the ones with strong controls that no management body has ever formally approved.
Article 21(2)(d) reaches your direct suppliers, not the whole chain. The scope is narrower than most programmes assume, and the depth required within it is considerably greater.
The security baseline of NIS2 is genuinely common across the Union. Almost everything you have to do administratively is not. Knowing which is which stops multinational programmes from being rebuilt 27 times.
We use strictly necessary storage to remember your cart and your theme —
no consent needed for that. We would also like to measure how the site is
used, which does require your agreement. You can decline and everything
keeps working.
Privacy policy