Directive NIS2 European Union
One directive, 27 national laws

Transposition tracker


NIS2 had to be transposed by . What binds you is your national law — not the directive itself. Here is where each member state stands.

Last reviewed . Source: National official journals (Държавен вестник, Mémorial A, Malta Government Gazette, Staatsblad, Dziennik Ustaw), national authority publications (CCB, BSI, ANSSI, ACN, ILR, CIP Department, RDI/NCSC-NL, NCSC-IE, SAMSIK) and the European Commission infringement register. Transposition moves; verify against your national official journal before relying on this for a filing.

CSIRT links checked — 26 of 27 recorded. The rest are named but not linked: an unverified address is worth less than none.

Transposition dates checked — all 23 of the 23 states shown as transposed carry the date their law entered into force. States shown as partial or not complete carry no date because no law is in force yet.

Obligation dates checked — all 27 states searched, in their own language and on the competent authority's own publications. 15 publish a registration date, 7 an implementation date, 3 a proof-of-conformity date. A state with none has published none, which is not the same as owing nothing.

23
Transposed and in force
1
Adopted, in force later
0
Partially transposed
3
Not complete
27
Member states

By member state


NIS2 transposition status, applicable assessment framework, competent authority and national CSIRT for each of the 27 EU member states
Code Member state Status Assessment framework Competent authority CSIRT Country pack
AT Austria In force 2026-10-01 None published Bundesamt für Cybersicherheit CERT.at
BE Belgium Transposed CyFun Centre for Cybersecurity Belgium CCB / CSIRT.be 129 €
BG Bulgaria Transposed None published Ministry of e-Government CERT Bulgaria
CY Cyprus Transposed None published Digital Security Authority CSIRT-CY
CZ Czechia Transposed ZKB measures NÚKIB GovCERT.CZ
DE Germany Transposed IT-Grundschutz Binding on the federal administration; the de facto benchmark for all BSI CERT-Bund 129 €
DK Denmark Transposed None published Styrelsen for Samfundssikkerhed FE/DDIS
EE Estonia Transposed E-ITS Information System Authority CERT-EE
ES Spain Not complete None published INCIBE / CCN INCIBE-CERT
FI Finland Transposed Kybermittari Traficom NCSC-FI
FR France Not complete ReCyF ANSSI CERT-FR 129 €
GR Greece Transposed None published National Cybersecurity Authority CSIRT-GR
HR Croatia Transposed HR Uredba SOA / ZSIS CERT.hr
HU Hungary Transposed HU protective measures SZTFH NBSZ NKI
IE Ireland Not complete CyFun NCSC Ireland CSIRT-IE
IT Italy Transposed ACN measures ACN CSIRT Italia
LT Lithuania Transposed None published NKSC CERT-LT
LU Luxembourg Transposed None published ILR / HCPN CIRCL / GOVCERT.LU
LV Latvia Transposed None published National Cybersecurity Centre CERT.LV
MT Malta Transposed None published Critical Infrastructure Protection Dept. CSIRTMalta
NL Netherlands Transposed BIO2 Public sector only — private entities have none RDI NCSC-NL
PL Poland Transposed NSC Ministry of Digital Affairs CSIRT NASK / GOV / MON
PT Portugal Transposed QNRCS CNCS CERT.PT
RO Romania Transposed CyFun DNSC DNSC
SE Sweden Transposed None published NCSC at FRA (Försvarets radioanstalt) CERT-SE
SI Slovenia Transposed None published URSIV SI-CERT
SK Slovakia Transposed None published NBU SK-CERT

On a narrow screen the ISO code, the competent authority and the national CSIRT columns are hidden. All three are on each member state's page — tap a country name.

Why this matters more than the directive text


A regulation applies directly and identically everywhere. A directive does not. NIS2 sets a floor, and each member state decides how to build on it — which is why a group operating in several countries does not have one compliance obligation but several.

What actually differs between countries:

  • Registration. Different portals, different data, different deadlines. Some require registration within months of the law entering force; others tie it to sector-specific designation.
  • Scope extensions. Several member states brought entities below the directive's size thresholds into scope, or added sectors of national importance.
  • Supervision. Inspection powers, audit frequency and the appetite to use them vary widely.
  • Penalty scales. The article 34 ceilings are common; how a national authority calibrates within them is not.
  • Reporting channels. The 24h / 72h / one-month deadlines are fixed by the directive, but the portal, the language and the form are national.

Our country packs cover exactly this layer — the part no pan-European guide can tell you.

See country packs →

Cart 0