Track the implementation of the NIS2 Directive across all EU Member States. See which countries have adopted national laws, which are still pending, and which go beyond baseline requirements.
Data reviewed 2 August 2026. Prioritizing official gazettes, national cybersecurity authorities, and EU sources.
No countries match your search
Map data: Al MacDonald & Fritz Lekschas, simple-world-map, CC BY-SA 3.0
The NISG 2026 was passed by the Nationalrat on 12 December 2025 and promulgated on 23 December 2025 (BGBl. I No. 94/2025). It enters into force on 1 October 2026 — the obligations only start running from that date. Estimates put 4,000 to 5,000 entities across the 18 sectors in scope, with wider figures up to 7,000 depending on how sectors are delimited. The timetable is staged: registration with the competent authority by 31 December 2026 (three months after entry into force), and the self-declaration evidencing implementation of the security measures by 30 September 2027. Austria goes beyond the EU baseline with a broadened scope and tightened organisational and technical duties, backed by a restructured supervisory and sanctions regime. Fines reach up to EUR 10 million or 2 % of global annual turnover for essential entities.
View Source: nis.gv.atNIS2 transposed via the Act of 26 April 2024; effective at the EU deadline (18 October 2024). CCB enforcement milestone: from 18 April 2026, essential entities must demonstrate full implementation of Article 21 security measures. CCB confirmed incident-triggered investigations are the primary enforcement mechanism; every reported cyber incident at a registered entity can trigger a compliance review. Incident reports rose 70% in 2025 vs 2024. Fines up to EUR 10 million for essential entities.
View Source: ccb.belgium.beBulgaria adopted NIS2 amendments on time; the initial implementation largely mirrored the EU baseline. A further amendment (State Gazette No. 17/2026, in force since 13 February 2026) extended coverage to 18 sectors and introduced personal management liability plus 24-hour incident reporting.
View Source: dv.parliament.bgAct on Cybersecurity of Key and Important Entities published; met EU deadline.
View Source: nn.hrNIS2 transposed through amending Law 60(I)/2025; published on 25 April 2025.
View Source: dsa.cyNew Cybersecurity Act No. 264/2025 Sb. published 4 August 2025; extends obligations including to the defence sector.
View Source: e-sbirka.czDanish NIS2 Act adopted 29 April 2025; implemented with minimal additions to the EU baseline requirements.
View Source: trafikstyrelsen.dkCybersecurity Act amendments in force; Estonia's digital-first approach includes additional e-government protections.
View Source: ria.eeCybersecurity Act 124/2025 implements NIS2 with a focus on clear sector-specific guidance.
View Source: traficom.fiThe Loi Résilience, which bundles NIS2, the CER Directive and DORA into a single act, has not been promulgated. The Senate adopted it at first reading on 12 March 2025; committee examination in the National Assembly followed, and plenary treatment is expected in autumn 2026, on current indications from September. There is therefore no NIS2 transposition law in force in France and no binding date for registration or reporting duties. Scope is expected to expand roughly tenfold, from approx. 300 regulated OIV entities to approx. 15,000 entities across 18 sectors, split into Entités Essentielles and Entités Importantes, with ANSSI as the central supervisory authority; a three-year transition to full compliance is envisaged after promulgation. Until then the reference document is the Référentiel Cyber France (ReCyF), published by ANSSI on 17 March 2026 — a working document without direct legal effect that indicates the direction the implementing decrees will take. The European Commission referred France to the CJEU on 8 July 2026 for incomplete transposition.
View Source: cyber.gouv.frNIS2 Implementation Act (BSI-Gesetz) entered into force on 6 December 2025. No transition period — requirements applied immediately to approx. 29,500 entities across 18 sectors. Registration portal opened 6 January 2026. As of 26 July 2026, 27,800 of 29,500 obligated entities (94 %) have registered in the MIRT portal — a final surge before the 31 July 2026 deadline. Remaining gaps: digital infrastructure (87 %), ICT service management (88 %), municipal administrations (83 %). From 1 August 2026 the BSI will launch formal supervisory proceedings against non-registrants, with fines of up to €10 million for essential entities. First BSI audits (Jan–Jul 2026) reveal common gaps: log retention below 12 months, missing risk registers, and untested incident response plans. Management personal liability under § 38 BSIG is actively enforced. Germany's approach goes beyond the EU baseline with stricter supply chain and vendor control requirements.
View Source: bundesregierung.deLaw 5160/2024 published in the Government Gazette; updates and strengthens the Greek NIS framework.
View Source: cyber.gov.grGovernment Decree 418/2024 and Decree 7/2024 implement NIS2 with additional national security provisions. First audit deadline changed from 31 December 2025 to 30 June 2026. Additional subsectors included: public transport, cement manufacturing, electronic communications.
View Source: nki.gov.huThe National Cyber Security Bill is progressing through the Oireachtas but has not been enacted. Enactment is expected during 2026; no binding date has been set, which makes Ireland the least predictable timeline among the EU laggards. On 8 July 2026 the European Commission referred Ireland to the CJEU (alongside France, Spain and the Netherlands) over its failure to transpose NIS2 more than 20 months after the October 2024 deadline. Obligations are nevertheless already reaching Irish firms ahead of the law: in July 2026 Ireland's NCSC published cyber governance guidance for management boards, and NIS2 clauses arrive through customer and supply-chain contracts from member states that have already transposed.
View Source: ncsc.gov.ieLegislative Decree 138/2024 entered into force 16 October 2024. Italy met the EU deadline with a close-to-baseline transposition. ACN (Agenzia per la Cybersicurezza Nazionale) has published categorization criteria and, as of Q2 2026, is notifying entities of their classification as essential or important. Full compliance obligations apply from 1 October 2026. Technical security requirements are based on the NIST Cybersecurity Framework. Entities have until 30 June 2026 to complete ACN pre-registration; non-compliance after October 2026 risks fines up to EUR 10 million or 2 % of global turnover.
View Source: acn.gov.itLaw on the Security of Information Technologies published; among earliest adopters.
View Source: cert.lvLaw on Cybersecurity amended; Lithuania's implementation includes stricter requirements for financial sector.
View Source: nksc.ltThe Law of 5 May 2026 on cybersecurity measures transposes NIS2 and entered into force on 10 May 2026. Around 2,000 essential and important entities across 18 sectors had to self-register with the Institut Luxembourgeois de Régulation (ILR) by 10 July 2026. Fines reach up to EUR 10 million or 2% of global turnover for essential entities, EUR 7 million or 1.4% for important entities.
View Source: legilux.public.luSubsidiary Legislation 460.41 (Legal Notice 71/2025) implementing NIS2 entered into force.
View Source: legislation.mtThe Cyberbeveiligingswet (Cbw) entered into force on 15 August 2026, replacing the earlier Wbni, together with the Wet weerbaarheid kritieke entiteiten (Wwke) transposing the CER Directive. Around 8,000 organisations across 18 sectors are in scope, split into essential and important entities with tiered obligations. There is no transition period: registration via the NCSC portal mijn.ncsc.nl, the duty of care (zorgplicht) and the three-stage reporting process (24-hour early warning, 72-hour notification, 1-month final report) all apply from day one. Board members are personally liable; fines reach up to EUR 10 million or 2 % of global annual turnover for essential entities. The NCSC is the central point of contact and CSIRT, while supervision sits with the sectoral authorities — for digital infrastructure and digital services the Rijksinspectie Digitale Infrastructuur (RDI). The European Commission referred the Netherlands to the CJEU on 8 July 2026 over the transposition delay; entry into force removes the grounds for the action, but formal withdrawal is still outstanding.
View Source: ncsc.nlOriginal KSC Act amendment entered into force 8 April 2026 (NIS2 baseline transposition). Additional KSC amendment adopted by Sejm on 18 July 2026, entering into force 1 September 2026: extends scope to e-commerce operators above PLN 50 million annual turnover and Polish media companies with national reach (~3,200 entities total). CERT Polska and CSIRT GOV designated as national authorities. Registration deadline: 1 October 2026. Fines up to PLN 10 million (approx. €2.3 million) for essential entities; managers personally liable for audit failures up to PLN 500,000.
View Source: gov.plDecree-Law 125/2025 — adopted under the enabling Lei 59/2025 — was published on 4 December 2025 and entered into force 120 days later, on 3 April 2026, establishing Portugal's new cybersecurity legal framework and transposing NIS2 into national law.
View Source: dre.ptEmergency Ordinance 155/2024 transposed NIS2; published in the Official Monitor on 15 November 2024.
View Source: dnsc.roAct No. 69/2018 Coll. on Cybersecurity amended to implement NIS2; stricter requirements for some sectors.
View Source: nbu.gov.skInformation Security Act 2 (ZInfV-2) adopted; implements NIS2 with clear sector definitions.
View Source: gov.siSpain has still not transposed NIS2. The Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad was approved by the Council of Ministers as long ago as 14 January 2025, but has not been published in the Boletín Oficial del Estado as at August 2026, and the parliamentary file has not visibly advanced through the Congreso. Until a transposition law is in force, Spanish entities remain governed by the NIS1 regime under Real Decreto-ley 12/2018. The draft follows the directive closely: all 18 sectors, EU-standard thresholds (50+ employees or EUR 10 million turnover), split supervision between INCIBE-CERT for the private sector and CCN-CERT for public entities and critical infrastructure, and fines of up to EUR 10 million or 2 % of global turnover for essential entities. On 8 July 2026 the European Commission referred Spain to the CJEU for incomplete transposition and additionally requested financial penalties — the only one of the four referred member states for which it did so.
View Source: dsn.gob.esCybersäkerhetslagen (2025:1506) entered into force on 15 January 2026, replacing the 2018 NIS-implementing act. Roughly 8,000 organisations across 18 sectors fall into scope; notification and self-assessment obligations under MSB (via NCSC-SE) became applicable on 2 February 2026. Sanctions follow the EU maximums: up to EUR 10 million or 2% of global turnover for essential entities, EUR 7 million or 1.4% for important entities. Sweden's transposition stays close to the EU baseline.
View Source: riksdagen.se