Directive NIS2 European Union
Cart 0
One directive, 27 national laws

Transposition tracker


NIS2 had to be transposed by . What binds you is your national law — not the directive itself. Here is where each member state stands.

Last reviewed . Source: National official journals and European Commission infringement register. Transposition moves; verify against your national official journal before relying on this for a filing.

18
Transposed
9
Partial or staged
27
Member states

By member state


NIS2 transposition status, competent authority and national CSIRT for each of the 27 EU member states
Code Member state Status Competent authority CSIRT Country pack
AT Austria Partial BMI / NISKO CERT.at
BE Belgium Transposed Centre for Cybersecurity Belgium CCB / CSIRT.be 129 €
BG Bulgaria Partial Ministry of e-Government CERT Bulgaria
CY Cyprus Transposed Digital Security Authority CSIRT-CY
CZ Czechia Transposed NÚKIB GovCERT.CZ
DE Germany Transposed BSI CERT-Bund 129 €
DK Denmark Transposed Centre for Cyber Security CFCS
EE Estonia Transposed Information System Authority CERT-EE
ES Spain Partial INCIBE / CCN INCIBE-CERT
FI Finland Transposed Traficom NCSC-FI
FR France Transposed ANSSI CERT-FR 129 €
GR Greece Transposed National Cybersecurity Authority NCSA-GR
HR Croatia Transposed SOA / ZSIS CERT.hr
HU Hungary Transposed SZTFH NBSZ NKI
IE Ireland Partial NCSC Ireland CSIRT-IE
IT Italy Transposed ACN CSIRT Italia
LT Lithuania Transposed NKSC CERT-LT
LU Luxembourg Transposed ILR / HCPN CIRCL / GOVCERT.LU
LV Latvia Transposed National Cybersecurity Centre CERT.LV
MT Malta Partial Malta Digital Innovation Auth. CSIRTMalta
NL Netherlands Partial RDI / NCTV NCSC-NL
PL Poland Partial Ministry of Digital Affairs CSIRT NASK / GOV / MON
PT Portugal Partial CNCS CERT.PT
RO Romania Transposed DNSC DNSC
SE Sweden Partial MSB CERT-SE
SI Slovenia Transposed URSIV SI-CERT
SK Slovakia Transposed NBU SK-CERT

Why this matters more than the directive text


A regulation applies directly and identically everywhere. A directive does not. NIS2 sets a floor, and each member state decides how to build on it — which is why a group operating in several countries does not have one compliance obligation but several.

What actually differs between countries:

  • Registration. Different portals, different data, different deadlines. Some require registration within months of the law entering force; others tie it to sector-specific designation.
  • Scope extensions. Several member states brought entities below the directive's size thresholds into scope, or added sectors of national importance.
  • Supervision. Inspection powers, audit frequency and the appetite to use them vary widely.
  • Penalty scales. The article 34 ceilings are common; how a national authority calibrates within them is not.
  • Reporting channels. The 24h / 72h / one-month deadlines are fixed by the directive, but the portal, the language and the form are national.

Our country packs cover exactly this layer — the part no pan-European guide can tell you.

See country packs →

Cart 0