Skip to main content
EU Member States

NIS2 by Country

Every EU member state transposes NIS2 in its own way, with different competent authorities, registration portals, and national additions. Select your country for a detailed compliance guide.

🏛️ Competent authorities📋 Registration portals⚖️ National fine levels📅 Deadlines
📊 Quick Test

Find out if your company is in scope

Does your organisation fall under Annex I (Essential) or Annex II (Important) entities?

Check NIS2 Scope →
In force

Germany

Germany's NIS2UmsuCG (rewriting the BSI-Gesetz) entered into force on 6 December 2025 with no transition period. Around 29,500 entities are in scope and the BSI expects registration by 31 July 2026.

Federal Office for Information Security (BSI)
Country guide →
In legislature

France

France has not completed transposition. The projet de loi résilience (covering NIS2, CER and DORA together) passed the Senate in March 2025 but still awaits final adoption and implementing decrees. The Commission referred France to the CJEU on 8 July 2026.

ANSSI
Country guide →
Adopted, not yet in force

Netherlands

The Dutch Senate passed the Cyberbeveiligingswet (Cbw) on 7 July 2026 and it enters into force on 15 August 2026. There is no general transition period — obligations apply from day one for the roughly 8,000 entities in scope.

NCSC-NL
Country guide →
In force

Belgium

Belgium enacted its NIS2 law in April 2024, one of the first EU member states to fully transpose. CCB leads enforcement with fines up to €10 million.

Centre for Cybersecurity Belgium (CCB)
Country guide →
In force

Italy

Italy transposed NIS2 via Decreto Legislativo 138/2024, with ACN (Agenzia per la Cybersicurezza Nazionale) as the central authority. Enforcement is phased through 2026.

Agenzia per la Cybersicurezza Nazionale (ACN)
Country guide →
In force

Sweden

Sweden's Cybersäkerhetslagen (SFS 2025:1506) entered into force on 15 January 2026, over a year after the EU deadline. MSB coordinates, issuing sector-specific binding regulations.

NCSC Sweden
Country guide →
In force

Poland

Poland's amended Act on the National Cybersecurity System (KSC) entered into force on 3 April 2026, roughly 17 months late. It covers about 42,000 entities across 18 sectors, with registration running to October 2026.

CERT Polska / CSIRT GOV
Country guide →
Adopted, not yet in force

Austria

Austria's NISG 2026 was published in the Federal Law Gazette on 23 December 2025 and enters into force on 1 October 2026. Registration is due by December 2026.

Federal Ministry of the Interior (BMI)
Country guide →
In force

Bulgaria

Bulgaria's Cybersecurity Act amendments were finally adopted in February 2026 and entered into force on 17 February 2026. The transitional grace period on management fines ended on 1 June 2026.

Ministry of Electronic Governance
Country guide →
In force

Croatia

Croatia transposed NIS2 through the Zakon o kibernetičkoj sigurnosti. ZSIS coordinates the cybersecurity framework across all sectors.

Information Systems Security Bureau (ZSIS)
Country guide →
In force

Cyprus

Cyprus implemented NIS2 through the Security of Network and Information Systems Law. The Digital Security Authority (DSA) supervises compliance.

Digital Security Authority (DSA)
Country guide →
In force

Czechia

Czechia transposed NIS2 through the new Cybersecurity Act. NÚKIB regulates compliance with robust technical guidelines and strict penalties.

National Cyber and Information Security Agency (NÚKIB)
Country guide →
In force

Denmark

Denmark transposed NIS2 via amendments to the national Netsikkerhedslov. CFCS coordinates cross-sector cybersecurity strategies.

Center for Cyber Security (CFCS)
Country guide →
In force

Estonia

Estonia transposed NIS2 via the Küberturvalisuse seadus. RIA enforces advanced cyber protocols across the highly digitized nation.

Estonian Information System Authority (RIA)
Country guide →
In force

Finland

Finland transposed NIS2 via the Cybersecurity Governance Act. Traficom handles supervisory coordination and incident tracking.

Finnish Transport and Communications Agency (Traficom)
Country guide →
In force

Greece

Greece enacted Law 5160/2024 to transpose NIS2. The National Cybersecurity Authority (NCSA) manages compliance across all critical infrastructure.

National Cybersecurity Authority (NCSA)
Country guide →
In force

Hungary

Hungary transposed NIS2 via Act XXIII of 2023. SZTFH coordinates audits, registrations, and enforcement structures.

Supervisory Authority for Regulatory Activities (SZTFH)
Country guide →
Not transposed

Ireland

Ireland has not enacted the National Cyber Security Bill. NIS1 obligations continue to apply and the NCSC has confirmed the NIS2 registration and reporting portals stay closed until the Bill passes. The Commission referred Ireland to the CJEU on 8 July 2026.

National Cyber Security Centre (NCSC-IE)
Country guide →
In force

Latvia

Latvia implemented NIS2 through the Nacionālās kiberdrošības likums. Coordination is handled jointly by the NCSC-LV and CERT.LV.

National Cybersecurity Centre (NCSC-LV) / CERT.LV
Country guide →
In force

Lithuania

Lithuania transposed NIS2 into the national Cybersecurity Act. NKSC coordinates compliance audits and threat alerts.

National Cyber Security Centre (NKSC)
Country guide →
In force

Luxembourg

Luxembourg adopted its NIS2 law on 5 May 2026 and it entered into force on 10 May 2026. In-scope entities were required to self-register with their competent authority by 10 July 2026.

National Agency for the Security of Information Systems (ANSSI-LU) / ILR
Country guide →
In force

Malta

Malta transposed NIS2 via the NIS 2 Ordinance (Legal Notice 71 of 2025), in force since 8 April 2025. MITA regulates network defence and guides organisations through self-registration.

Malta Information Technology Agency (MITA) / CSIRT-MT
Country guide →
In force

Portugal

Portugal transposed NIS2 through Decreto-Lei n.º 125/2025, published on 4 December 2025. GNS coordinates standards, with CNCS coordinating incident response.

Gabinete Nacional de Segurança (GNS) / CNCS
Country guide →
In force

Romania

Romania transposed NIS2 through amendments to its cybersecurity legislation. DNSC acts as the central supervisory authority.

National Cyber Security Directorate (DNSC)
Country guide →
In force

Slovakia

Slovakia transposed NIS2 via amendments to its Cybersecurity Act. The National Security Authority (NBÚ) directs enforcement and audits.

National Security Authority (NBÚ)
Country guide →
In force

Slovenia

Slovenia transposed NIS2 via amendments to the Information Security Act. URSIV regulates network standards and audits.

Government Information Security Office (URSIV)
Country guide →
In legislature

Spain

Spain has not completed transposition. The Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad was approved by the Council of Ministers in January 2025 but remains in parliament. The NIS1 regime under Royal Decree 43/2021 still governs, and the Commission referred Spain to the CJEU on 8 July 2026.

CCN-CERT / INCIBE
Country guide →

EU-wide NIS2 Transposition

NIS2 had to be transposed by all EU member states by 17 October 2024. While core obligations (Articles 20-23) are harmonised, registration procedures, competent authorities, and national additions vary significantly.

For entities operating across multiple EU countries, the law of the member state where you have your main establishment generally applies.