When did NIS2 apply, and has my country transposed it?
Member states had to transpose NIS2 into national law by 17 October 2024 and apply those measures from 18 October 2024, when the original NIS Directive was repealed. Several countries missed the deadline, so your concrete obligations and registration dates depend on your national law. The table below summarises all 27 member states.
Last updated: 2026-09-30
Key dates
| Date | Milestone |
|---|---|
| 16 January 2023 | NIS2 Directive (EU) 2022/2555 entered into force |
| 17 October 2024 | Deadline for member states to adopt national transposition laws |
| 18 October 2024 | National measures apply; the NIS Directive (EU) 2016/1148 is repealed |
| 17 April 2025 | Member states to establish their list of essential and important entities |
The European Commission opened infringement procedures against member states that did not transpose on time.
Status by member state
| Country | Transposition note |
|---|---|
| Austria | NIS2 transposed via NISG 2024 amendment; BMI acts as central coordinator. |
| Belgium | Transposed via the Belgian NIS2 Act (Wet van 26 april 2024); CCB is the single competent authority. |
| Bulgaria | NIS2 transposition completed via amendments to the Cybersecurity Act; SANS oversees implementation. |
| Croatia | NIS2 transposed via the Croatian Cybersecurity Act (2024); NSA and SOA share supervisory duties. |
| Cyprus | Transposed via the NIS2 Law (2024); DSA acts as the single competent authority and national CSIRT. |
| Czechia | NIS2 transposed via Act No. 181/2014 Coll. amendment (Zákon o kybernetické bezpečnosti); NÚKIB is the primary authority. |
| Denmark | Transposed via the Danish NIS2 Act (2024); sector-specific authorities cooperate with CFCS. |
| Estonia | Transposed via amendments to the Cybersecurity Act (küberturvalisuse seadus); RIA supervises and CERT-EE handles incidents. |
| Finland | Transposed via the Finnish Cybersecurity Act (2024); Traficom's NCSC-FI unit is the single competent authority. |
| France | Transposed via loi no. 2023-703 and decree; ANSSI is the single competent authority with extensive sector coverage. |
| Germany | Transposed via NIS2UmsuCG (Umsetzungsgesetz, 2024); BSI is the federal competent authority, Länder cooperate for regional entities. |
| Greece | Transposed via Law 5160/2024; the National Cybersecurity Authority within the Ministry of Digital Governance supervises compliance. |
| Hungary | Transposed via Act XXIII of 2023 on cybersecurity; NBSZ acts as the primary competent authority. |
| Ireland | Transposed via the Network and Information Security (Measures for a High Common Level of Cybersecurity) Regulations 2024. |
| Italy | Transposed via Legislative Decree 138/2024; ACN is the single competent authority with extensive national NIS2 registry. |
| Latvia | Transposed via the Cybersecurity Law (Kiberdrošības likums, 2024); CERT.LV handles incidents and VARAM oversees sector compliance. |
| Lithuania | Transposed via the Law on Cybersecurity (2024 amendment); NKSC is both competent authority and national CSIRT. |
| Luxembourg | Transposed via the Law of 17 February 2025; ILR acts as competent authority and CIRCL handles incident coordination. |
| Malta | Transposed via subsidiary legislation; MCA and MITA share supervisory responsibilities under NIS2. |
| Netherlands | Transposed via Cybersecurity Wet (Wbni amendment, 2024); NCSC-NL is the national CSIRT and sector-specific bodies act as competent authorities. |
| Poland | Transposed via the Act on the National Cybersecurity System amendment (2024); three national CSIRTs (NASK, GOV, MON) share responsibility. |
| Portugal | Transposed via Decree-Law 65/2021 updated for NIS2 (2024); CNCS is the single competent authority. |
| Romania | Transposed via Law 58/2023; DNSC is both the competent authority and national CSIRT for NIS2. |
| Slovakia | Transposed via the Cybersecurity Act amendment (zákon č. 69/2018 Z. z., 2024); NBÚ and SK-CERT handle supervision and incidents. |
| Slovenia | Transposed via the Information Security Act (ZInfV, 2024); SI-CERT serves as national CSIRT and the Information Commissioner oversees compliance. |
| Spain | Transposed via Royal Decree-Law 2023; INCIBE covers private-sector entities and CCN covers public-sector entities. |
| Sweden | Transposed via the Swedish Cybersecurity Act (Lag om cybersäkerhet, 2024); MSB, FRA, SÄPO and FMV jointly form the NCSC-SE. |
Depends on national law: Country notes are a summary; always confirm the current status with the national competent authority.
Related question
Does NIS2 apply if my country has not finished transposing it?
The directive's obligations reach companies through national law, so concrete duties, registration and enforcement start when your country's law applies. Preparing for the Article 21 measures and Article 23 reporting early is still advisable, because the requirements themselves are fixed at EU level.
Next steps
More answers:
For decision-support purposes only, not legal advice. Exact obligations depend on national transposition — use our free scope checker for a personalised assessment.