Transposition tracker
NIS2 had to be transposed by . What binds you is your national law — not the directive itself. Here is where each member state stands.
Last reviewed . Source: National official journals (Държавен вестник, Mémorial A, Malta Government Gazette, Staatsblad, Dziennik Ustaw), national authority publications (CCB, BSI, ANSSI, ACN, ILR, CIP Department, RDI/NCSC-NL, NCSC-IE, SAMSIK) and the European Commission infringement register. Transposition moves; verify against your national official journal before relying on this for a filing.
CSIRT links checked — 26 of 27 recorded. The rest are named but not linked: an unverified address is worth less than none.
Transposition dates checked — all 23 of the 23 states shown as transposed carry the date their law entered into force. States shown as partial or not complete carry no date because no law is in force yet.
Obligation dates checked — all 27 states searched, in their own language and on the competent authority's own publications. 15 publish a registration date, 7 an implementation date, 3 a proof-of-conformity date. A state with none has published none, which is not the same as owing nothing.
By member state
| Code | Member state | Status | Assessment framework | Competent authority | CSIRT | Country pack |
|---|---|---|---|---|---|---|
| AT | Austria | In force 2026-10-01 | None published | Bundesamt für Cybersicherheit | CERT.at | — |
| BE | Belgium | Transposed | CyFun | Centre for Cybersecurity Belgium | CCB / CSIRT.be | 129 € |
| BG | Bulgaria | Transposed | None published | Ministry of e-Government | CERT Bulgaria | — |
| CY | Cyprus | Transposed | None published | Digital Security Authority | CSIRT-CY | — |
| CZ | Czechia | Transposed | ZKB measures | NÚKIB | GovCERT.CZ | — |
| DE | Germany | Transposed | IT-Grundschutz Binding on the federal administration; the de facto benchmark for all | BSI | CERT-Bund | 129 € |
| DK | Denmark | Transposed | None published | Styrelsen for Samfundssikkerhed | FE/DDIS | — |
| EE | Estonia | Transposed | E-ITS | Information System Authority | CERT-EE | — |
| ES | Spain | Not complete | None published | INCIBE / CCN | INCIBE-CERT | — |
| FI | Finland | Transposed | Kybermittari | Traficom | NCSC-FI | — |
| FR | France | Not complete | ReCyF | ANSSI | CERT-FR | 129 € |
| GR | Greece | Transposed | None published | National Cybersecurity Authority | CSIRT-GR | — |
| HR | Croatia | Transposed | HR Uredba | SOA / ZSIS | CERT.hr | — |
| HU | Hungary | Transposed | HU protective measures | SZTFH | NBSZ NKI | — |
| IE | Ireland | Not complete | CyFun | NCSC Ireland | CSIRT-IE | — |
| IT | Italy | Transposed | ACN measures | ACN | CSIRT Italia | — |
| LT | Lithuania | Transposed | None published | NKSC | CERT-LT | — |
| LU | Luxembourg | Transposed | None published | ILR / HCPN | CIRCL / GOVCERT.LU | — |
| LV | Latvia | Transposed | None published | National Cybersecurity Centre | CERT.LV | — |
| MT | Malta | Transposed | None published | Critical Infrastructure Protection Dept. | CSIRTMalta | — |
| NL | Netherlands | Transposed | BIO2 Public sector only — private entities have none | RDI | NCSC-NL | — |
| PL | Poland | Transposed | NSC | Ministry of Digital Affairs | CSIRT NASK / GOV / MON | — |
| PT | Portugal | Transposed | QNRCS | CNCS | CERT.PT | — |
| RO | Romania | Transposed | CyFun | DNSC | DNSC | — |
| SE | Sweden | Transposed | None published | NCSC at FRA (Försvarets radioanstalt) | CERT-SE | — |
| SI | Slovenia | Transposed | None published | URSIV | SI-CERT | — |
| SK | Slovakia | Transposed | None published | NBU | SK-CERT | — |
On a narrow screen the ISO code, the competent authority and the national CSIRT columns are hidden. All three are on each member state's page — tap a country name.
Why this matters more than the directive text
A regulation applies directly and identically everywhere. A directive does not. NIS2 sets a floor, and each member state decides how to build on it — which is why a group operating in several countries does not have one compliance obligation but several.
What actually differs between countries:
- Registration. Different portals, different data, different deadlines. Some require registration within months of the law entering force; others tie it to sector-specific designation.
- Scope extensions. Several member states brought entities below the directive's size thresholds into scope, or added sectors of national importance.
- Supervision. Inspection powers, audit frequency and the appetite to use them vary widely.
- Penalty scales. The article 34 ceilings are common; how a national authority calibrates within them is not.
- Reporting channels. The 24h / 72h / one-month deadlines are fixed by the directive, but the portal, the language and the form are national.
Our country packs cover exactly this layer — the part no pan-European guide can tell you.