News

NIS2 National Transposition: Where EU Member States Stand

NIS2 is a directive, not a regulation — so the exact rules depend on how your country transposed it. Here's what that means for your compliance timeline.

By Auditra Team · Published · Updated

Directive (EU) 2022/2555 — NIS2 — had to be written into national law by 17 October 2024, with the national rules applying from 18 October 2024. A directive binds member states to a result, not to a text: each of the 27 governments passes its own act, and until that act exists there is nothing for a national authority to enforce. That single legal fact explains most of the confusion organisations run into when they try to pin down their obligations.

One deadline, twenty-seven speeds

Only a small group of member states had their implementing legislation in force on the deadline. Others adopted it during 2025, and a number continued to work through parliamentary procedure well after that. The European Commission responded in the usual way: letters of formal notice to the states that had not notified complete transposition, followed by reasoned opinions and, for the slowest, referral to the Court of Justice. Those proceedings are aimed at governments rather than companies, but they are a reliable public indicator of where a national regime is not yet settled.

The practical consequence is that two subsidiaries of the same group can face different registration deadlines, different supervisory contacts and different reporting portals, while both are nominally "NIS2 entities".

Find the act that actually applies to you

Work from the national law, not the directive, whenever you need a concrete answer. In Germany that is the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) with the BSI as supervisor; other member states have their own instruments and their own designated competent authority and CSIRT. National acts routinely go beyond the baseline: they can bring additional sectors or public bodies into scope, adjust or clarify the size thresholds, set registration windows measured in weeks, and add sanctions such as periodic penalty payments or management bans that the directive itself does not spell out.

A workable approach for a multi-country group is to keep a short register: for every country where you provide in-scope services, record the implementing act, the competent authority, the CSIRT reporting channel, the registration deadline and any national extension of scope. Review it each quarter — the picture is still moving.

Keeping this current

We update this page periodically as transposition progresses and infringement cases close. If you are still deciding whether any of this applies to you, start with the scope self-assessment rather than the national detail.

Related reading

Related

Who must comply with NIS2? — the full reference page behind this article.

← All news