Live Status Tracker

NIS2 Legislation Status

Track the implementation of the NIS2 Directive across all EU Member States. See which countries have adopted national laws, which are still pending, and which go beyond baseline requirements.

0
In Force
0
Pending
0
Stricter Implementation
🇩🇪
Germany Stricter
In Force
Effective Date 06.12.2025
Implementation Stricter than EU baseline
Compliance Deadline 06.03.2026

NIS2 Implementation Act (BSI-Gesetz) entered into force on 6 December 2025. No transition period — requirements applied immediately to approx. 29,500 entities across 18 sectors. Registration portal opened 6 January 2026. The registration deadline for essential entities passed on 6 March 2026; as of May 2026 only approx. 11,500 of 29,500 obligated entities (38.5 %) have registered — the BSI is actively following up. First BSI audits (Jan–May 2026) reveal common gaps: log retention below 12 months, missing risk registers, and untested incident response plans. Management personal liability under § 38 BSIG is actively enforced. Germany's approach goes beyond the EU baseline with stricter supply chain and vendor control requirements.

View Source: bundesregierung.de
Click for details
🇫🇷
France Stricter
Pending
Effective Date Q3 2026 (est.)
Implementation Stricter than EU baseline
Compliance Deadline TBD

France is the last major EU economy without an adopted NIS2 transposition law. The Loi Résilience (bundling NIS2, CER, and DORA) was adopted by the Senate in March 2025; the National Assembly vote is now expected in July 2026 (extraordinary session). ANSSI published the Référentiel Cyber France (ReCyF) technical framework on 17 March 2026, which will de facto set the compliance standard. The MesServicesCyber voluntary pre-registration portal is active. ANSSI will supervise approx. 15,000–18,000 entities. Once the law passes, registration and incident reporting obligations apply immediately; full compliance has a 3-year transition period.

View Source: economie.gouv.fr
Click for details
🇮🇹
Italy
In Force
Effective Date 16.10.2024
Implementation EU baseline
Compliance Deadline 01.10.2026

Legislative Decree 138/2024 entered into force 16 October 2024. Italy met the EU deadline with a close-to-baseline transposition. ACN (Agenzia per la Cybersicurezza Nazionale) has published categorization criteria and, as of Q2 2026, is notifying entities of their classification as essential or important. Full compliance obligations apply from 1 October 2026. Technical security requirements are based on the NIST Cybersecurity Framework. Entities have until 30 June 2026 to complete ACN pre-registration; non-compliance after October 2026 risks fines up to EUR 10 million or 2 % of global turnover.

View Source: acn.gov.it
Click for details
🇪🇸
Spain
Pending
Effective Date H2 2026 (est.)
Implementation EU baseline
Compliance Deadline TBD

Draft Law on Cybersecurity Coordination and Governance approved by Council of Ministers in January 2025, currently in urgent parliamentary procedure. Establishes Centro Nacional de Ciberseguridad (CNCS) as lead authority. Expected to cover approx. 12,000 entities with board-level accountability.

View Source: interior.gob.es
Click for details
🇳🇱
Netherlands
Pending
Effective Date 01.07.2026
Implementation EU baseline
Compliance Deadline TBD

Cybersecurity Act (Wet beveiliging netwerk- en informatiesystemen) passed by parliament; enters into force 1 July 2026. NCSC Netherlands designated as the central authority. Includes significant restructuring of national cybersecurity governance; approx. 5,000 entities expected in scope.

View Source: eversheds-sutherland.com
Click for details
🇧🇪
Belgium
In Force
Effective Date 18.10.2024
Implementation EU baseline
Compliance Deadline 18.10.2024

NIS2 transposed via the Act of 26 April 2024; effective at the EU deadline (18 October 2024). CCB enforcement milestone: from 18 April 2026, essential entities must demonstrate full implementation of Article 21 security measures. CCB confirmed incident-triggered investigations are the primary enforcement mechanism; every reported cyber incident at a registered entity can trigger a compliance review. Incident reports rose 70% in 2025 vs 2024. Fines up to EUR 10 million for essential entities.

View Source: ccb.belgium.be
Click for details
🇦🇹
Austria
In Force
Effective Date 01.10.2026
Implementation EU baseline
Compliance Deadline 30.09.2027

NISG 2026 passed 20 December 2025, published 23 December 2025. Enters into force 1 October 2026. Entities must register within 3 months (by 1 January 2027) and submit self-declaration on risk management within 12 months (by 30 September 2027). Establishes new Federal Cyber Security Office.

View Source: bundeskanzleramt.gv.at
Click for details
🇵🇱
Poland
In Force
Effective Date 08.04.2026
Implementation EU baseline
Compliance Deadline 08.10.2026

Amendment to the National Cybersecurity System Act (KSC Act) signed and entered into force 8 April 2026. CERT Polska and CSIRT GOV designated as national authorities. Entities have until 8 October 2026 to achieve full compliance.

View Source: copla.com
Click for details
🇸🇪
Sweden
Pending
Effective Date Q1/Q2 2026
Implementation EU baseline
Compliance Deadline TBD

Transposition bill Ds 2025:1 introduced in February 2025; approved in parliament but national cybersecurity framework not yet finalized. Law expected to enter into force Q2/Q3 2026. Sweden's approach maintains close alignment with the EU NIS2 baseline, supervised by NCSC Sweden (NCSC-SE).

View Source: digitaleurope.org
Click for details
🇩🇰
Denmark
In Force
Effective Date 01.07.2025
Implementation EU baseline
Compliance Deadline 01.07.2025

Danish NIS2 Act adopted 29 April 2025; implemented with minimal additions to the EU baseline requirements.

View Source: trafikstyrelsen.dk
Click for details
🇫🇮
Finland
In Force
Effective Date 08.04.2025
Implementation EU baseline
Compliance Deadline 08.04.2025

Cybersecurity Act 124/2025 implements NIS2 with a focus on clear sector-specific guidance.

View Source: traficom.fi
Click for details
🇮🇪
Ireland
Pending
Effective Date Q1/Q2 2026
Implementation EU baseline
Compliance Deadline TBD

National Cyber Security Bill in preparation; NIS2 implementation delayed beyond the original deadline.

View Source: ncsc.gov.ie
Click for details
🇵🇹
Portugal
In Force
Effective Date Q1 2026
Implementation EU baseline
Compliance Deadline TBD

Framework Law 59/2025 adopted to enable NIS2 implementation; detailed implementing decree still pending. Portugal recently adopted national implementing legislation.

View Source: twobirds.com
Click for details
🇬🇷
Greece
In Force
Effective Date 17.12.2024
Implementation EU baseline
Compliance Deadline 17.12.2024

Law 5160/2024 published in the Government Gazette; updates and strengthens the Greek NIS framework.

View Source: nis2certification.eu
Click for details
🇨🇿
Czech Republic Stricter
In Force
Effective Date 01.11.2025
Implementation Stricter than EU baseline
Compliance Deadline 01.11.2025

New Cybersecurity Act No. 264/2025 Sb. published 4 August 2025; extends obligations including to the defence sector.

View Source: e-sbirka.cz
Click for details
🇭🇺
Hungary Stricter
In Force
Effective Date 01.01.2025
Implementation Stricter than EU baseline
Compliance Deadline 30.06.2026

Government Decree 418/2024 and Decree 7/2024 implement NIS2 with additional national security provisions. First audit deadline changed from 31 December 2025 to 30 June 2026. Additional subsectors included: public transport, cement manufacturing, electronic communications.

View Source: nki.gov.hu
Click for details
🇷🇴
Romania
In Force
Effective Date 16.11.2024
Implementation EU baseline
Compliance Deadline 16.11.2024

Emergency Ordinance 155/2024 transposed NIS2; published in the Official Monitor on 15 November 2024.

View Source: dnsc.ro
Click for details
🇸🇰
Slovakia
In Force
Effective Date 01.01.2025
Implementation EU baseline
Compliance Deadline 01.01.2025

Act No. 69/2018 Coll. on Cybersecurity amended to implement NIS2; stricter requirements for some sectors.

View Source: nbu.gov.sk
Click for details
🇧🇬
Bulgaria
In Force
Effective Date 17.10.2024
Implementation EU baseline
Compliance Deadline 17.10.2024

Cybersecurity Act amendments adopted; Bulgaria among first to meet the EU deadline.

View Source: lex.bg
Click for details
🇭🇷
Croatia
In Force
Effective Date 17.10.2024
Implementation EU baseline
Compliance Deadline 17.10.2024

Act on Cybersecurity of Key and Important Entities published; met EU deadline.

View Source: zvrh.hr
Click for details
🇸🇮
Slovenia
In Force
Effective Date 19.02.2025
Implementation EU baseline
Compliance Deadline 19.02.2025

Information Security Act 2 (ZInfV-2) adopted; implements NIS2 with clear sector definitions.

View Source: gov.si
Click for details
🇱🇹
Lithuania Stricter
In Force
Effective Date 18.10.2024
Implementation Stricter than EU baseline
Compliance Deadline 18.10.2024

Law on Cybersecurity amended; Lithuania's implementation includes stricter requirements for financial sector.

View Source: nksc.lt
Click for details
🇱🇻
Latvia
In Force
Effective Date 17.10.2024
Implementation EU baseline
Compliance Deadline 17.10.2024

Law on the Security of Information Technologies published; among earliest adopters.

View Source: cert.lv
Click for details
🇪🇪
Estonia Stricter
In Force
Effective Date 18.10.2024
Compliance Deadline 18.10.2024

Cybersecurity Act amendments in force; Estonia's digital-first approach includes additional e-government protections.

View Source: ria.ee
Click for details
🇨🇾
Cyprus
In Force
Effective Date 25.04.2025
Compliance Deadline 25.04.2025

NIS2 transposed through amending Law 60(I)/2025; published on 25 April 2025.

View Source: dsa.cy
🇲🇹
Malta
In Force
Effective Date 08.04.2025
Compliance Deadline 08.04.2025

Subsidiary Legislation 460.41 (Legal Notice 71/2025) implementing NIS2 entered into force.

View Source: dataguidance.com
🇱🇺
Luxembourg
Pending
Expected In Force Q1/Q2 2026
Compliance Deadline TBD

Draft Cybersecurity Act under urgent parliamentary procedure; adoption expected soon.

View Source: eversheds-sutherland.com