NIS2, Directive (EU) 2022/2555, is the EU's second Network and Information Security Directive, a sweeping upgrade of cybersecurity obligations for organisations that keep Europe's critical and important services running. But a directive is not a rulebook you can comply with directly: it only creates binding duties once each member state writes it into national law, which is why the state of NIS2 transposition, country by country, decides what you actually owe and when.
What NIS2 Requires
NIS2 dramatically widens the perimeter of EU cybersecurity regulation compared with the original 2016 NIS Directive. It sorts in-scope organisations into two tiers:
- Essential entities: larger operators in the highest-criticality sectors such as energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, and space.
- Important entities: organisations in sectors including postal and courier services, waste management, chemicals, food, manufacturing of critical products, digital providers, and research.
The two tiers face broadly the same obligations but different supervisory intensity: essential entities are subject to proactive supervision, while important entities are generally supervised reactively, after an incident or a credible indication of non-compliance. Size matters too. The directive applies a "size-cap" rule that generally brings in medium and large enterprises, with important exceptions for certain critical providers regardless of headcount.
Whatever their tier, in-scope entities must deliver on four core duties:
- Risk-management measures. A baseline of technical, operational and organisational controls: risk analysis, incident handling, business continuity and backups, supply-chain security, vulnerability handling and disclosure, encryption, access control, and cyber hygiene and training.
- Incident reporting. A staged timeline to the national CSIRT or competent authority: an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month.
- Management liability. Management bodies must approve the risk-management measures and oversee their implementation, can be held liable for breaches, and are required to undergo cybersecurity training.
- Registration and supervision. Entities must register with national authorities, submit to audits and inspections, and face administrative fines that can reach up to 10 million euro or 2% of global annual turnover for essential entities (up to 7 million euro or 1.4% for important entities).
The precise thresholds, sector definitions, registration mechanics and penalty ceilings are set by each country's transposing law, so the directive tells you the shape of the obligation, and national law tells you the exact edges.
The Deadline and Why Being Late Still Matters
Member states were required to adopt and publish the national measures transposing NIS2 by 17 October 2024, and to apply them from 18 October 2024. Most missed it. A large majority of the 27 have since caught up, but a stubborn minority remained mid-process well into 2026.
It is tempting to read "my country is late" as "I have more time." That is the wrong conclusion, for three reasons.
First, lateness is being enforced. On 8 July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice of the EU for failing to notify complete transposition, and asked the Court to impose financial sanctions: a lump sum plus daily penalties until each country notifies full transposition. Germany, separately, spent much of 2025 in infringement proceedings before finally legislating. The political pressure on laggards is intense, which means national laws can land (and switch on) quickly and with little warning.
Second, several national laws apply immediately on entry into force, with no grace period. Germany's implementing act is the clearest example: it became binding law in December 2025 with no transition window, and set an early registration deadline for in-scope entities. Waiting for your national text to be final is not the same as waiting to prepare.
Third, the substantive obligations do not change much between countries. The risk-management baseline, the 24/72-hour reporting rhythm and the management-accountability principle are set by the directive itself. You can, and should, build your programme against the directive now, then reconcile the details once your national law is published.
Country-by-Country Status Overview
The picture as of mid-August 2026 is that most large economies have transposed, a cluster of well-known laggards are being taken to court, and a few remain in the final stages of their legislative process. The table below covers the major economies. Where a status cannot be confidently confirmed, it is marked In progress and flagged as such rather than guessed.
| Country | Status | Notes / date |
|---|---|---|
| Germany | Transposed | NIS2 Implementation Act (NIS2UmsuCG) passed the Bundestag in Nov 2025; binding law from 6 Dec 2025 with no transition. BSI registration required by early 2026. Very late, after infringement proceedings. |
| Belgium | Transposed | Among the first movers; national law in force in 2024, close to the original deadline. |
| Italy | Transposed | Legislative Decree 138/2024, in force October 2024. |
| Sweden | Transposed | National cybersecurity legislation adopted during 2025; in live implementation. |
| Poland | In progress | Amendment to the National Cybersecurity System Act (KSC) advanced through 2025 but was repeatedly delayed; confirm the final in-force status against the national gazette. |
| Netherlands | Transposed (entering into force) | Cyberbeveiligingswet adopted by the Senate on 7 Jul 2026, entering into force 15 Aug 2026. Referred to the CJEU on 8 Jul 2026 for late notification, just before entry into force. |
| France | Overdue | Still in the legislative procedure; referred to the CJEU on 8 Jul 2026 with a request for financial sanctions. |
| Spain | Overdue | Still legislating; referred to the CJEU on 8 Jul 2026. |
| Ireland | Overdue | Still legislating; referred to the CJEU on 8 Jul 2026. |
| Luxembourg | In progress | Among the group still completing its legislative process in 2026; confirm current status locally. |
Two caveats belong with any tracker like this. "Transposed" means a national law has been adopted and is in force. It does not tell you that every implementing decree, sector designation or registration portal is live yet; several countries adopted framework laws with secondary rules still to follow. And status changes fast: a bill can move from "in progress" to "in force" between the day this was written and the day you read it. Always confirm against the primary sources.
What To Do: Late Country vs On-Time Country
If you operate in a country that has transposed (or is about to):
- Read the national text, not just the directive. Confirm your tier (essential vs important), your registration deadline, the exact reporting channel and timelines, and the national penalty ceilings.
- Register with the competent authority or CSIRT by the stated deadline. In some countries this is weeks, not months, after entry into force.
- Close the gap between the directive baseline and any stricter national add-ons (some states impose additional sector scope or documentation duties).
- Get your management body trained and on record as having approved the risk-management measures; personal accountability is a live obligation, not a formality.
If you operate in a country that is late or overdue:
- Do not wait. Build against Directive (EU) 2022/2555 directly. The risk-management controls, incident-reporting workflow and governance duties are stable and will carry over.
- Track the bill actively. Referrals to the CJEU and daily penalty threats mean laggard governments can finalise and switch on their laws with little runway.
- Watch for "no transition period" clauses, as seen in Germany, where obligations bit the moment the law entered into force.
- If you are cross-border, comply with the strictest applicable regime and standardise upward. It is cheaper than maintaining a different posture per subsidiary.