Directive NIS2 European Union
Cart 0
Art. 26

One directive, 27 laws: what actually differs between member states


· Cryptaguard · 7 min read

The security baseline of NIS2 is genuinely common across the Union. Almost everything you have to do administratively is not. Knowing which is which stops multinational programmes from being rebuilt 27 times.

The distinction that saves the most money

A group operating in six member states does not have six NIS2 programmes. It has one security programme and six compliance relationships. Teams that miss this either build one programme and get caught by national procedure, or build six and spend five times what they needed to.

What is genuinely uniform

These come from the directive and will not differ meaningfully between member states:

  • The ten minimum measures of article 21(2), from risk analysis through to multi-factor authentication.
  • The reporting deadlines of article 23: 24 hours, 72 hours, one month.
  • The management body duties of article 20 — approve, oversee, follow training.
  • The fine ceilings of article 34: the higher of €10m or 2% for essential entities, €7m or 1.4% for important entities.
  • The definitions of essential and important entities, and the size-cap rule of article 2.

Build these once, centrally. A supplier questionnaire, an incident response plan, a policy set and a set of board reporting templates are portable across all 27.

What is national, and why it bites

Registration

Every member state runs its own registration procedure: its own portal, its own required information, its own deadline. Article 3(4) sets the minimum content — name, address, sector, contacts — and article 27 adds a separate registry for digital infrastructure and digital provider categories. Everything procedural above that minimum is national.

This is the single most common failure among otherwise well-prepared organisations. The security work is done, and nobody registered.

Scope extensions

The directive sets a floor, not a ceiling. Several member states brought entities below the size cap into scope, or added sectors of national importance. An entity that is out of scope on the directive's own thresholds can be firmly in scope under a national law.

Public administration

Central government is in Annex I. Regional level is in scope "where a member state so provides", and local level is entirely at national discretion. This produces the widest divergence in the directive — municipal utilities and regional health bodies are in scope in some member states and outside it in others.

Supervision and penalties

The article 32 and 33 powers are common; the appetite to use them is not. Inspection frequency, audit intensity and how an authority calibrates a fine within the ceilings are national in practice, and already visibly different between member states with comparable economies.

Reporting channels

Deadlines are fixed by the directive. The portal, the form and the language are national. Some member states run a single channel for all sectors; others route by sector. Discovering which applies to you during an incident is an expensive way to find out.

Do this before you need it

Confirm your reporting channel per member state now, in writing, and put it in the incident response plan. The 24-hour clock is not the moment to be reading a national website in a language nobody on the bridge call speaks.

Which member state supervises you

Article 26 sets jurisdiction. The general rule is the member state of establishment, so an entity established in several member states answers to several authorities. There are specific rules for certain categories: DNS providers, TLD registries, cloud, data centre, CDN, managed service and managed security service providers, and online marketplaces, search engines and social networks fall under the jurisdiction of the member state of their main establishment.

Entities established outside the Union that offer services within it must designate a representative in one of the member states where they do so — and that choice determines jurisdiction.

A practical operating model

  1. Build the article 21 programme once, centrally, and treat it as portable.
  2. Maintain a per-member-state register: authority, CSIRT, registration status and date, reporting channel, national scope peculiarities.
  3. Assign a named owner per member state — someone who reads the national authority's publications, not a shared mailbox.
  4. Re-check the register on a cycle. Transposition is still moving, and infringement procedures opened in 2025 are producing late national laws.

The register is the artefact that makes a multinational programme defensible. It is also the thing an inspector can be shown in two minutes, which is worth more than it sounds.

What to do about it
  • Build article 21 once and centrally — it is the same in all 27 member states.
  • Treat registration, scope extensions, supervision and reporting channels as strictly national.
  • Keep a per-member-state register with a named owner for each.
  • Confirm and document your reporting channel per jurisdiction before an incident, not during one.
Cart 0