Skip to main content
EU Member States

NIS2 by Country

Every EU member state transposes NIS2 in its own way, with different competent authorities, registration portals, and national additions. Select your country for a detailed compliance guide.

🏛️ Competent authorities📋 Registration portals⚖️ National fine levels📅 Deadlines
📊 Quick Test

Find out if your company is in scope

Does your organisation fall under Annex I (Essential) or Annex II (Important) entities?

Check NIS2 Scope →
Implemented

Germany

Germany transposed NIS2 via the NIS2UmsuCG (KRITIS-Dachgesetz + BSI-Gesetz update). BSI is the primary supervisory authority with fines up to €10 million.

Federal Office for Information Security (BSI)
Country guide →
Implemented

France

France transposed NIS2 through Loi n°2024-1177 (the RGCP law) in January 2025. ANSSI leads supervision with a graduated enforcement approach.

ANSSI
Country guide →
Implemented

Netherlands

The Netherlands transposed NIS2 via the Cyberbeveiligingswet (CBW), which entered into force in late 2024. NCSC-NL and sector-specific regulators share supervisory duties.

NCSC-NL
Country guide →
Implemented

Belgium

Belgium enacted its NIS2 law in April 2024, one of the first EU member states to fully transpose. CCB leads enforcement with fines up to €10 million.

Centre for Cybersecurity Belgium (CCB)
Country guide →
Implemented

Italy

Italy transposed NIS2 via Legge 90/2024, with ACN (Agenzia per la Cybersicurezza Nazionale) as the central authority. Enforcement is phased through 2026.

Agenzia per la Cybersicurezza Nazionale (ACN)
Country guide →
Implemented

Sweden

Sweden transposed NIS2 via the Cybersäkerhetslagen (2024:1247) effective January 2025. NCSC Sweden coordinates, with MSBFS issuing sector-specific binding regulations.

NCSC Sweden
Country guide →
In progress

Poland

Poland is updating its national cybersecurity act (UKSC) to transpose NIS2. The draft NIS2 law is in final legislative stages with enforcement expected mid-2025.

CERT Polska / CSIRT GOV
Country guide →
Implemented

Austria

Austria transposed NIS2 via the Netz- und Informationssystemsicherheitsgesetz 2024 (NISG 2024). The Federal Ministry of the Interior (BMI) is the primary supervisory authority.

Federal Ministry of the Interior (BMI)
Country guide →
In progress

Bulgaria

Bulgaria is transposing NIS2 through amendments to the national Cybersecurity Act. The Ministry of Electronic Governance acts as the primary coordinator.

Ministry of Electronic Governance
Country guide →
Implemented

Croatia

Croatia transposed NIS2 through the Zakon o kibernetičkoj sigurnosti. ZSIS coordinates the cybersecurity framework across all sectors.

Information Systems Security Bureau (ZSIS)
Country guide →
Implemented

Cyprus

Cyprus implemented NIS2 through the Security of Network and Information Systems Law. The Digital Security Authority (DSA) supervises compliance.

Digital Security Authority (DSA)
Country guide →
Implemented

Czechia

Czechia transposed NIS2 through the new Cybersecurity Act. NÚKIB regulates compliance with robust technical guidelines and strict penalties.

National Cyber and Information Security Agency (NÚKIB)
Country guide →
Implemented

Denmark

Denmark transposed NIS2 via amendments to the national Netsikkerhedslov. CFCS coordinates cross-sector cybersecurity strategies.

Center for Cyber Security (CFCS)
Country guide →
Implemented

Estonia

Estonia transposed NIS2 via the Küberturvalisuse seadus. RIA enforces advanced cyber protocols across the highly digitized nation.

Estonian Information System Authority (RIA)
Country guide →
Implemented

Finland

Finland transposed NIS2 via the Cybersecurity Governance Act. Traficom handles supervisory coordination and incident tracking.

Finnish Transport and Communications Agency (Traficom)
Country guide →
Implemented

Greece

Greece enacted Law 5160/2024 to transpose NIS2. The National Cybersecurity Authority (NCSA) manages compliance across all critical infrastructure.

National Cybersecurity Authority (NCSA)
Country guide →
Implemented

Hungary

Hungary transposed NIS2 via Act XXIII of 2023. SZTFH coordinates audits, registrations, and enforcement structures.

Supervisory Authority for Regulatory Activities (SZTFH)
Country guide →
In progress

Ireland

Ireland is in the final legislative phases of passing the National Cyber Security Bill 2024. NCSC-IE is designated as the primary supervisor.

National Cyber Security Centre (NCSC-IE)
Country guide →
Implemented

Latvia

Latvia implemented NIS2 through the Nacionālās kiberdrošības likums. Coordination is handled jointly by the NCSC-LV and CERT.LV.

National Cybersecurity Centre (NCSC-LV) / CERT.LV
Country guide →
Implemented

Lithuania

Lithuania transposed NIS2 into the national Cybersecurity Act. NKSC coordinates compliance audits and threat alerts.

National Cyber Security Centre (NKSC)
Country guide →
In progress

Luxembourg

Luxembourg is transposing NIS2 via Projet de loi n°8385. ANSSI-LU is the designated competent authority for broad cybersecurity coordination.

National Agency for the Security of Information Systems (ANSSI-LU) / ILR
Country guide →
Implemented

Malta

Malta transposed NIS2 via the Cybersecurity Act, 2024. MITA regulates network defense and guides organizations through self-registration.

Malta Information Technology Agency (MITA) / CSIRT-MT
Country guide →
Implemented

Portugal

Portugal transposed NIS2 through Decreto-Lei n.º 65/2024. GNS coordinates standards, with CNCS coordinating incident response.

Gabinete Nacional de Segurança (GNS) / CNCS
Country guide →
Implemented

Romania

Romania transposed NIS2 through amendments to its cybersecurity legislation. DNSC acts as the central supervisory authority.

National Cyber Security Directorate (DNSC)
Country guide →
Implemented

Slovakia

Slovakia transposed NIS2 via amendments to its Cybersecurity Act. The National Security Authority (NBÚ) directs enforcement and audits.

National Security Authority (NBÚ)
Country guide →
Implemented

Slovenia

Slovenia transposed NIS2 via amendments to the Information Security Act. URSIV regulates network standards and audits.

Government Information Security Office (URSIV)
Country guide →
In progress

Spain

Spain is transposing NIS2 through a draft national Cybersecurity Governance Act. CCN-CERT and INCIBE share coordination duties.

CCN-CERT / INCIBE
Country guide →

EU-wide NIS2 Transposition

NIS2 had to be transposed by all EU member states by 17 October 2024. While core obligations (Articles 20-23) are harmonised, registration procedures, competent authorities, and national additions vary significantly.

For entities operating across multiple EU countries, the law of the member state where you have your main establishment generally applies.