NIS2 by Country
Every EU member state transposes NIS2 in its own way, with different competent authorities, registration portals, and national additions. Select your country for a detailed compliance guide.
Find out if your company is in scope
Does your organisation fall under Annex I (Essential) or Annex II (Important) entities?
Germany
Germany's NIS2UmsuCG (rewriting the BSI-Gesetz) entered into force on 6 December 2025 with no transition period. Around 29,500 entities are in scope and the BSI expects registration by 31 July 2026.
France
France has not completed transposition. The projet de loi résilience (covering NIS2, CER and DORA together) passed the Senate in March 2025 but still awaits final adoption and implementing decrees. The Commission referred France to the CJEU on 8 July 2026.
Netherlands
The Dutch Senate passed the Cyberbeveiligingswet (Cbw) on 7 July 2026 and it enters into force on 15 August 2026. There is no general transition period — obligations apply from day one for the roughly 8,000 entities in scope.
Belgium
Belgium enacted its NIS2 law in April 2024, one of the first EU member states to fully transpose. CCB leads enforcement with fines up to €10 million.
Italy
Italy transposed NIS2 via Decreto Legislativo 138/2024, with ACN (Agenzia per la Cybersicurezza Nazionale) as the central authority. Enforcement is phased through 2026.
Sweden
Sweden's Cybersäkerhetslagen (SFS 2025:1506) entered into force on 15 January 2026, over a year after the EU deadline. MSB coordinates, issuing sector-specific binding regulations.
Poland
Poland's amended Act on the National Cybersecurity System (KSC) entered into force on 3 April 2026, roughly 17 months late. It covers about 42,000 entities across 18 sectors, with registration running to October 2026.
Austria
Austria's NISG 2026 was published in the Federal Law Gazette on 23 December 2025 and enters into force on 1 October 2026. Registration is due by December 2026.
Bulgaria
Bulgaria's Cybersecurity Act amendments were finally adopted in February 2026 and entered into force on 17 February 2026. The transitional grace period on management fines ended on 1 June 2026.
Croatia
Croatia transposed NIS2 through the Zakon o kibernetičkoj sigurnosti. ZSIS coordinates the cybersecurity framework across all sectors.
Cyprus
Cyprus implemented NIS2 through the Security of Network and Information Systems Law. The Digital Security Authority (DSA) supervises compliance.
Czechia
Czechia transposed NIS2 through the new Cybersecurity Act. NÚKIB regulates compliance with robust technical guidelines and strict penalties.
Denmark
Denmark transposed NIS2 via amendments to the national Netsikkerhedslov. CFCS coordinates cross-sector cybersecurity strategies.
Estonia
Estonia transposed NIS2 via the Küberturvalisuse seadus. RIA enforces advanced cyber protocols across the highly digitized nation.
Finland
Finland transposed NIS2 via the Cybersecurity Governance Act. Traficom handles supervisory coordination and incident tracking.
Greece
Greece enacted Law 5160/2024 to transpose NIS2. The National Cybersecurity Authority (NCSA) manages compliance across all critical infrastructure.
Hungary
Hungary transposed NIS2 via Act XXIII of 2023. SZTFH coordinates audits, registrations, and enforcement structures.
Ireland
Ireland has not enacted the National Cyber Security Bill. NIS1 obligations continue to apply and the NCSC has confirmed the NIS2 registration and reporting portals stay closed until the Bill passes. The Commission referred Ireland to the CJEU on 8 July 2026.
Latvia
Latvia implemented NIS2 through the Nacionālās kiberdrošības likums. Coordination is handled jointly by the NCSC-LV and CERT.LV.
Lithuania
Lithuania transposed NIS2 into the national Cybersecurity Act. NKSC coordinates compliance audits and threat alerts.
Luxembourg
Luxembourg adopted its NIS2 law on 5 May 2026 and it entered into force on 10 May 2026. In-scope entities were required to self-register with their competent authority by 10 July 2026.
Malta
Malta transposed NIS2 via the NIS 2 Ordinance (Legal Notice 71 of 2025), in force since 8 April 2025. MITA regulates network defence and guides organisations through self-registration.
Portugal
Portugal transposed NIS2 through Decreto-Lei n.º 125/2025, published on 4 December 2025. GNS coordinates standards, with CNCS coordinating incident response.
Romania
Romania transposed NIS2 through amendments to its cybersecurity legislation. DNSC acts as the central supervisory authority.
Slovakia
Slovakia transposed NIS2 via amendments to its Cybersecurity Act. The National Security Authority (NBÚ) directs enforcement and audits.
Slovenia
Slovenia transposed NIS2 via amendments to the Information Security Act. URSIV regulates network standards and audits.
Spain
Spain has not completed transposition. The Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad was approved by the Council of Ministers in January 2025 but remains in parliament. The NIS1 regime under Royal Decree 43/2021 still governs, and the Commission referred Spain to the CJEU on 8 July 2026.
EU-wide NIS2 Transposition
NIS2 had to be transposed by all EU member states by 17 October 2024. While core obligations (Articles 20-23) are harmonised, registration procedures, competent authorities, and national additions vary significantly.
For entities operating across multiple EU countries, the law of the member state where you have your main establishment generally applies.