Track the implementation of the NIS2 Directive across all EU Member States. See which countries have adopted national laws, which are still pending, and which go beyond baseline requirements.
NIS2 Implementation Act (BSI-Gesetz) entered into force on 6 December 2025. No transition period — requirements applied immediately to approx. 29,500 entities across 18 sectors. Registration portal opened 6 January 2026. The registration deadline for essential entities passed on 6 March 2026; as of May 2026 only approx. 11,500 of 29,500 obligated entities (38.5 %) have registered — the BSI is actively following up. First BSI audits (Jan–May 2026) reveal common gaps: log retention below 12 months, missing risk registers, and untested incident response plans. Management personal liability under § 38 BSIG is actively enforced. Germany's approach goes beyond the EU baseline with stricter supply chain and vendor control requirements.
View Source: bundesregierung.deFrance is the last major EU economy without an adopted NIS2 transposition law. The Loi Résilience (bundling NIS2, CER, and DORA) was adopted by the Senate in March 2025; the National Assembly vote is now expected in July 2026 (extraordinary session). ANSSI published the Référentiel Cyber France (ReCyF) technical framework on 17 March 2026, which will de facto set the compliance standard. The MesServicesCyber voluntary pre-registration portal is active. ANSSI will supervise approx. 15,000–18,000 entities. Once the law passes, registration and incident reporting obligations apply immediately; full compliance has a 3-year transition period.
View Source: economie.gouv.frLegislative Decree 138/2024 entered into force 16 October 2024. Italy met the EU deadline with a close-to-baseline transposition. ACN (Agenzia per la Cybersicurezza Nazionale) has published categorization criteria and, as of Q2 2026, is notifying entities of their classification as essential or important. Full compliance obligations apply from 1 October 2026. Technical security requirements are based on the NIST Cybersecurity Framework. Entities have until 30 June 2026 to complete ACN pre-registration; non-compliance after October 2026 risks fines up to EUR 10 million or 2 % of global turnover.
View Source: acn.gov.itDraft Law on Cybersecurity Coordination and Governance approved by Council of Ministers in January 2025, currently in urgent parliamentary procedure. Establishes Centro Nacional de Ciberseguridad (CNCS) as lead authority. Expected to cover approx. 12,000 entities with board-level accountability.
View Source: interior.gob.esCybersecurity Act (Wet beveiliging netwerk- en informatiesystemen) passed by parliament; enters into force 1 July 2026. NCSC Netherlands designated as the central authority. Includes significant restructuring of national cybersecurity governance; approx. 5,000 entities expected in scope.
View Source: eversheds-sutherland.comNIS2 transposed via the Act of 26 April 2024; effective at the EU deadline (18 October 2024). CCB enforcement milestone: from 18 April 2026, essential entities must demonstrate full implementation of Article 21 security measures. CCB confirmed incident-triggered investigations are the primary enforcement mechanism; every reported cyber incident at a registered entity can trigger a compliance review. Incident reports rose 70% in 2025 vs 2024. Fines up to EUR 10 million for essential entities.
View Source: ccb.belgium.beNISG 2026 passed 20 December 2025, published 23 December 2025. Enters into force 1 October 2026. Entities must register within 3 months (by 1 January 2027) and submit self-declaration on risk management within 12 months (by 30 September 2027). Establishes new Federal Cyber Security Office.
View Source: bundeskanzleramt.gv.atAmendment to the National Cybersecurity System Act (KSC Act) signed and entered into force 8 April 2026. CERT Polska and CSIRT GOV designated as national authorities. Entities have until 8 October 2026 to achieve full compliance.
View Source: copla.comTransposition bill Ds 2025:1 introduced in February 2025; approved in parliament but national cybersecurity framework not yet finalized. Law expected to enter into force Q2/Q3 2026. Sweden's approach maintains close alignment with the EU NIS2 baseline, supervised by NCSC Sweden (NCSC-SE).
View Source: digitaleurope.orgDanish NIS2 Act adopted 29 April 2025; implemented with minimal additions to the EU baseline requirements.
View Source: trafikstyrelsen.dkCybersecurity Act 124/2025 implements NIS2 with a focus on clear sector-specific guidance.
View Source: traficom.fiNational Cyber Security Bill in preparation; NIS2 implementation delayed beyond the original deadline.
View Source: ncsc.gov.ieFramework Law 59/2025 adopted to enable NIS2 implementation; detailed implementing decree still pending. Portugal recently adopted national implementing legislation.
View Source: twobirds.comLaw 5160/2024 published in the Government Gazette; updates and strengthens the Greek NIS framework.
View Source: nis2certification.euNew Cybersecurity Act No. 264/2025 Sb. published 4 August 2025; extends obligations including to the defence sector.
View Source: e-sbirka.czGovernment Decree 418/2024 and Decree 7/2024 implement NIS2 with additional national security provisions. First audit deadline changed from 31 December 2025 to 30 June 2026. Additional subsectors included: public transport, cement manufacturing, electronic communications.
View Source: nki.gov.huEmergency Ordinance 155/2024 transposed NIS2; published in the Official Monitor on 15 November 2024.
View Source: dnsc.roAct No. 69/2018 Coll. on Cybersecurity amended to implement NIS2; stricter requirements for some sectors.
View Source: nbu.gov.skCybersecurity Act amendments adopted; Bulgaria among first to meet the EU deadline.
View Source: lex.bgAct on Cybersecurity of Key and Important Entities published; met EU deadline.
View Source: zvrh.hrInformation Security Act 2 (ZInfV-2) adopted; implements NIS2 with clear sector definitions.
View Source: gov.siLaw on Cybersecurity amended; Lithuania's implementation includes stricter requirements for financial sector.
View Source: nksc.ltLaw on the Security of Information Technologies published; among earliest adopters.
View Source: cert.lvCybersecurity Act amendments in force; Estonia's digital-first approach includes additional e-government protections.
View Source: ria.eeNIS2 transposed through amending Law 60(I)/2025; published on 25 April 2025.
View Source: dsa.cySubsidiary Legislation 460.41 (Legal Notice 71/2025) implementing NIS2 entered into force.
View Source: dataguidance.comDraft Cybersecurity Act under urgent parliamentary procedure; adoption expected soon.
View Source: eversheds-sutherland.com