Every NIS2 deadline, state by state
· Cryptaguard · 9 min read
Most NIS2 calendars stop at the transposition deadline, which was a deadline for governments. The dates that decide whether your organisation is in breach are national, they are not synchronised, and registering on time tells you nothing about the two obligations that follow it.
The date everyone knows is the article 41 transposition deadline of 17 October 2024. It is also the least useful date in NIS2, because it bound governments rather than entities, and it was comprehensively missed. What binds you is your national law, and the calendar that law sets.
The table below holds every national obligation date we have been able to verify, for all 27 member states, in five kinds. It is generated from the same data as the country pages, so it cannot drift away from them — and neither can this article, which contains no dates of its own.
The calendar
| Member state | In force | Registration | Measures | Proof of conformity | Supervision |
|---|---|---|---|---|---|
| Austria | | Not recorded yet | Not recorded yet | None published | None published |
| Belgium | | | None published | essential only essential only | Not recorded yet |
| Bulgaria | | Not recorded yet | None published | None published | None published |
| Croatia | | Not recorded yet | None published | None published | None published |
| Cyprus | | Not recorded yet | None published | None published | None published |
| Czechia | | | Not recorded yet | None published | None published |
| Denmark | | | None published | None published | None published |
| Estonia | | | Not recorded yet | None published | None published |
| Finland | | | | None published | None published |
| France | No law in force | No law in force | No law in force | No law in force | No law in force |
| Germany | | | | None published | None published |
| Greece | | | None published | None published | None published |
| Hungary | | Not recorded yet | None published | | |
| Ireland | No law in force | No law in force | No law in force | No law in force | No law in force |
| Italy | | | Not recorded yet | None published | None published |
| Latvia | | | None published | | None published |
| Lithuania | | Not recorded yet | Not recorded yet | None published | None published |
| Luxembourg | | | None published | None published | None published |
| Malta | | Not recorded yet | None published | None published | None published |
| Netherlands | | | | None published | None published |
| Poland | | | | None published | None published |
| Portugal | | | | None published | None published |
| Romania | | | None published | None published | None published |
| Slovakia | | Not recorded yet | None published | None published | None published |
| Slovenia | | Not recorded yet | | None published | None published |
| Spain | No law in force | No law in force | No law in force | No law in force | No law in force |
| Sweden | | | | None published | None published |
Of the 27 member states, 15 publish a registration date, 7 an implementation date, 3 a proof-of-conformity date, and 1 a date on which supervision became active. An empty cell means no date was published, not that nothing is owed.
Sources and notes
Austria
- Registration — not recorded. The NISG 2026 sets the registration period, but the Austrian legal information system (RIS) could not be reached to quote it, and secondary sources give December 2026 without agreeing on the day. The registration regulation was still a draft on 30 January 2026.
- Measures — not recorded. The NISG 2026 provides for a self-declaration within twelve months of the registration duty taking effect, but the period could not be quoted from the law itself.
Belgium
- — Register with the CCB through the Safeonweb@Work portal. Five months from entry into force on 18 October 2024. Entities that come into scope later register on coming into scope, not on this date. Source: Loi du 26 avril 2024 (Moniteur belge), five-month period from entry into force.
- (essential entities only) — Show at least a CyFun Basic or Important verification, or submit an ISO/IEC 27001 Statement of Applicability to the CCB instead. Two tracks, either is accepted. Source: CCB, NIS2 implementation timeline.
- (essential entities only) — The target CyberFundamentals level must be CERTIFIED by a conformity assessment body accredited by BELAC and authorised by the CCB. An external assessment, not a self-assessment. Source: CCB, NIS2 implementation timeline.
- Supervision — not recorded. The CCB began NIS2 inspections in April 2026 but has not published a start date, and a month is not a date.
Bulgaria
- Registration — not recorded. The amended Cybersecurity Act sets a two-month period running from when the information arises rather than a calendar date, and the register is compiled by the Ministry of e-Government rather than by entity filing. No fixed registration date could be quoted from the State Gazette text.
Croatia
- Registration — not recorded. The register is kept by SOA on the basis of categorisation rather than entity filing, and the periods run thirty days from each entity being categorised, so no national date exists.
Cyprus
- Registration — not recorded. The Digital Security Authority publishes scope guidance and a self-assessment tool but no dated registration deadline.
Czechia
- — Notify the regulated service (ohlaseni) through the NUKIB Portal, which became the compulsory channel between the office and regulated entities on the day the act took effect. Sixty days from entry into force on 1 November 2025. NUKIB reported 4,825 entities notified as at 8 February 2026 — the count is the authority's own, and it is what makes this date checkable. Source: NUKIB, Ohlaseni podle noveho zakona o kyberneticke bezpecnosti.
- Measures — not recorded. The act gives one year from delivery of the registration decision, so the date is personal to each entity and no calendar date exists for the country as a whole.
Denmark
- — Register on virk.dk, signed in with MitID Erhverv. The authority states the same rule the other member states apply: an entity that comes into scope after this date registers within two weeks of coming into scope, not retroactively. Source: Styrelsen for Samfundssikkerhed (SAMSIK), Registrering af enheder efter NIS 2-loven.
Estonia
- — Notify RIA of the details of your activity, through eesti.ee. Three months from the NIS2 amendments extending the act on 1 January 2026 — RIA writes « kolme kuu jooksul » and gives the period, not the date. The amendment brought roughly 3,000 more companies into scope, to about 6,500. Source: RIA, Uuest aastast laienes kuberturvalisuse seadus.
- Measures — not recorded. RIA describes a three-year transition, five years for vital service providers, but does not say what the period runs from. Computing a date from an anchor we are guessing at would be worse than leaving it out.
Finland
- — Register in the operator list of your own supervising authority. An entity active in several sectors registers with each sector supervisor separately. One month from entry into force on 8 April 2025. Finland splits supervision across sector authorities, so this is not a single filing. Source: Traficom, Kyberturvallisuusdirektiivin (NIS 2) mukaiset velvoitteet.
- — Have the risk-management operating model in place. Three months from entry into force. Kyberturvallisuuslaki 124/2025. Source: Traficom, Kyberturvallisuuslain keskeiset velvoitteet.
Germany
- — Register with the BSI, in two steps: an account on Mein Unternehmenskonto, then registration in the BSI portal. Three months from entry into force on 6 December 2025. § 33 Abs. 1 BSIG sets a period — « spätestens drei Monate nachdem sie erstmals oder erneut als eine der vorgenannten Einrichtungen gelten » — not a calendar date, so an entity coming into scope later has its own three months. Source: § 33 Abs. 1 BSIG, as stated in the BSI FAQ on NIS-2.
- — The § 30 BSIG risk-management measures apply in full. There is no phase-in: obligations attach on the day the act enters into force. The BSI FAQ is explicit — « Das NIS-2-Umsetzungsgesetz sieht keine allgemeine Übergangsfrist vor. » Enforcement forbearance on the registration date is a separate matter and is described in the registration note above; it never moved a legal date. Source: BSI, Allgemeine FAQ zu NIS-2.
Greece
- — Submit the information required by law 5160/2024 to the National Cybersecurity Authority. An EXTENDED deadline: the ministry and the authority pushed the original date back to 28 March 2025 for both essential and important entities. Until the platform went live, submissions were made by email and acknowledged with a protocol number. Source: Ypourgeio Psifiakis Diakyvernisis, Paratasi ton prothesmion ypovolis stoicheion.
Hungary
- — Sign the contract with the auditor who will carry out the first cybersecurity audit. A preparatory obligation with its own date, ten months before the audit itself. Missing it is one of the two failures the authority says it screens for first. Source: SZTFH, Tajekoztatas a kiberbiztonsagi auditra vonatkozo hatarido modositasarol.
- — Complete the first cybersecurity audit, for organisations that began operating before 1 January 2025. Section 16(1) of Act LXIX of 2024. Organisations that began operating later have two years from their entry in the register instead, so this date does not bind them. Source: SZTFH, on section 16(1) of Act LXIX of 2024.
- — The SZTFH began checks, targeting first the entities that had not registered and those that had not signed an audit contract. The authority announced what it would look at first. That is worth more than the date alone: it tells you which two omissions are visible from outside without an inspection. Source: SZTFH, Jelentos elorelepes a kiberbiztonsagi megfeleles erdekeben.
- Registration — not recorded. The duty runs thirty days from coming into scope rather than from a calendar date, so no single national date exists.
Italy
- — Registration on the ACN platform for the subjects of article 42, comma 1, lettera a): cloud computing providers, data centres, managed services including security services, and online marketplaces. Source: ACN, Normativa NIS: date e informazioni utili.
- — Registration on the ACN platform for every other subject within the scope of decreto legislativo 138/2024. The platform opened on 1 December 2024. ACN draws up the list of essential and important subjects by 31 March each year and notifies each subject of its inclusion, so an entity may be designated after this date. Source: ACN, Normativa NIS: date e informazioni utili.
- Measures — not recorded. ACN gives eighteen months for the security measures, running from the April 2025 finalisation of the NIS list, and states the result as October 2026 without a day. A month is not a date, and the determination fixing the day could not be quoted.
Latvia
- — File the registration questionnaire with the National Cybersecurity Centre. Source: CERT.LV / Aizsardzibas ministrija, Nacionalas kiberdrosibas likums.
- — Submit the first self-assessment report to the competent supervisory authority, and have a cybersecurity manager appointed by the same date. A self-assessment, not a third-party certification: it proves conformity to the supervisor without an accredited body, which is a materially lighter obligation than the Belgian one on the same line. Source: CERT.LV / Aizsardzibas ministrija, Nacionalas kiberdrosibas likums.
Lithuania
- Registration — not recorded. The NKSC had to identify subjects and enter them in the register by 17 April 2025, notifying each one; entities may also ask to be registered voluntarily. There is no dated filing duty on entities.
- Measures — not recorded. Requirements apply after a transition of at least twelve months for organisational measures and twenty-four for technical ones, running from each entity being identified rather than from a national date.
Luxembourg
- — Self-register with the ILR through its self-registration form. Two months from entry into force on 10 May 2026, and the ILR states the resulting date itself rather than leaving it to be computed. Self-registrations made before entry into force remain valid if the data is kept accurate, and failing to self-register does not suspend any other obligation under the law. Source: ILR, Auto-enregistrement (NISS).
Malta
- Registration — not recorded. The Order obliged the CIP Department to establish the self-registration mechanism by 30 October 2025, but sets no dated filing obligation on entities, and guidance on the mechanism was still described as pending after the Order came into force on 23 January 2026.
Netherlands
- — Registration in the national entity register via Mijn.NCSC.nl became compulsory. Organisations are responsible for registering themselves. Not a cut-off but the day the duty attached: « Registratie is verplicht sinds 15 augustus 2026. » It coincides with entry into force because the Cyberbeveiligingswet grants no phase-in. Source: Rijksinspectie Digitale Infrastructuur (RDI), FAQ Cyberbeveiligingswet.
- — The zorgplicht — the duty of care to manage network and information system risk and to limit the consequences of incidents — applies. The RDI states it plainly: « Sinds 15 augustus 2026 gelden de verplichtingen van deze wet voor uw organisatie. » Source: Rijksinspectie Digitale Infrastructuur (RDI), FAQ Cyberbeveiligingswet.
Poland
- — After self-assessment, file an application for entry in the Wykaz podmiotow kluczowych i podmiotow waznych through the S46 system. The Wykaz opened on 13 April 2026; existing operators of essential services, trust service providers, telecoms undertakings and public bodies were entered by the Minister of Digital Affairs ex officio between 13 April and 6 May 2026, so this date binds the entities that must come forward themselves. Source: Ministerstwo Cyfryzacji, Nowelizacja KSC — najwazniejsze terminy.
- — Have a complete information security management system (SZBI) in place. Twelve months for entities that already met the criteria of a key or important entity on 3 April 2026, the day the amendment entered into force. Source: Ministerstwo Cyfryzacji, Nowelizacja KSC — najwazniejsze terminy.
Portugal
- — Submit the asset list on the MyCiber platform. Or six months after being notified of final qualification, whichever falls first — so an entity qualified late in 2026 has less than this date suggests, never more. Source: CNCS, Regulamento n. 756/2026 do Regime Juridico da Ciberseguranca.
- — Adapt to the minimum cybersecurity measures. Twenty-four months from the publication of Regulation 756/2026 on 22 June 2026, which is the anchor the CNCS uses — not the entry into force of the decree-law on 3 April 2026. Source: CNCS, Medidas Minimas de Ciberseguranca.
Romania
- — File the notification for entry in the register of essential and important entities, through the NIS2@RO evaluation tool and the ATHENA platform. Article 18(2) of OUG 155/2024. The DNSC announced the expiry itself, and said the duty survives it: an entity that missed the date is still required to register, and remains exposed to fines of up to 500,000 lei for not having done so. A deadline that has passed is not a deadline that has lapsed. Source: DNSC, Comunicat de presa privind expirarea termenului de notificare.
Slovakia
- Registration — not recorded. The NBU describes JISKB as the registration channel but publishes no dated filing deadline, and its NIS2 portal carries none either.
Slovenia
- — Operators bound under the electronic communications code (ZEKom-2) must align their security documentation and security measures with ZInfV-1. Twelve months from entry into force on 19 June 2025. The obligation is written for a category of operator, not for a class of entity, so it does not follow the essential/important split. Source: Zakon o informacijski varnosti (ZInfV-1), Uradni list RS 2025-01-1571.
- Registration — not recorded. URSIV publishes guidance on who is bound but no dated filing deadline for entities generally.
Sweden
- — The regulation on notification and identification entered into force and the notification service opened. The date the duty attached, not a cut-off: the regulation sets the filing period rather than a single national date. Source: MSB / NCSC Sverige, Tidsplan for inforandet av cybersakerhetslagen.
- — The regulations on security measures and on training for the management body entered into force. Source: MSB / NCSC Sverige, Tidsplan for inforandet av cybersakerhetslagen.
How to read it
Registering, implementing and proving are three obligations
They have three dates, and clearing the first tells you nothing about the other two. Several member states separate registration from implementation by six months or more, and a few separate implementation from proof of conformity by a further year. An organisation that registered on time and then stopped is the easiest profile for a supervisor to open a file on, precisely because the register told them you exist.
This is the most common shape of failure among otherwise well-prepared organisations. The security work is genuinely done, the entity is genuinely registered, and the obligation that carries the later date was never assigned to anyone.
Proof of conformity does not bind everyone
The proof-of-conformity column is the only one whose entries can be restricted to one class of entity, and where that is the case the table says so in the cell rather than in a footnote. Belgium is the worked example: essential entities must be able to show a CyberFundamentals verification or an ISO/IEC 27001 Statement of Applicability, and later a certification issued by a body accredited by BELAC and authorised by the CCB. Important entities are not under that obligation.
An important entity that reads the date without reading the class buys an external assessment it does not owe. That is a five-figure mistake, and it is made by reading a table exactly like this one that left the class out.
The part you cannot compress
Certification bodies are a queue, not a service you can summon. Where a member state sets a certification date, the market of accredited assessors is finite and the date is fixed. Book early, or do not plan to certify.
Supervision has its own date, and it is often already behind you
An authority that inspects does not wait for the last milestone on its own calendar. The supervision column records when each authority began exercising its powers, where that is published. It answers the question most boards ask badly — not "when must we be ready" but "are we already accountable".
An empty cell is not an absence of obligation
Two different things can leave a cell without a date, and the table distinguishes them. "None published" means we searched and the member state has not set a date of that kind. "Not recorded yet" means we searched and could not reach a source we are willing to stand behind, and the reason is given under the table.
Neither means you owe nothing. The substantive duties come from the national law whether or not the state has published a calendar for them. A member state that sets no registration deadline still requires registration; it simply has not told you by when.
Two traps worth naming
Enforcement discretion is not an extension. Where a supervisor announces that it will not enforce a registration date for some months, the legal date does not move, an entity that missed it has been in breach since, and the forbearance is withdrawn without ceremony. A great many entities have read one such announcement as a new deadline. It was not one.
Late transposition does not buy you time. A member state that transposes years late does not compensate by giving entities years. Several applied their law on entry into force with no transitional period at all, and the only concession was a window of reduced sanctions that has since closed. The runway you get is the one your national legislator chose, and it bears no relation to how long that legislator took.
What to do with this
Build a register of the member states where you have establishments, and give it a column per obligation kind rather than a single NIS2 deadline column. Most multinational programmes track obligations without tracking dates, and dates are what supervisors ask about first.
Then read the class column. Half the work of a group programme is discovering that an obligation you assumed was universal binds only your essential entities, or only in one country — and the other half is discovering the reverse, that a duty you scoped to one subsidiary applies across the group.
- Track three dates per member state, not one: registration, implementation, proof of conformity.
- Read the class column before buying an assessment — some obligations bind essential entities only.
- Check when supervision started where you operate. It is often earlier than the compliance dates.
- Treat enforcement forbearance as discretion, never as an extension: the legal date does not move.
- An empty cell means no date was published, not that no obligation is owed.