Skip to content
NISDESK

When did NIS2 apply, and has my country transposed it?

Member states had to transpose NIS2 into national law by 17 October 2024 and apply those measures from 18 October 2024, when the original NIS Directive was repealed. Several countries missed the deadline, so your concrete obligations and registration dates depend on your national law. The table below summarises all 27 member states.

Last updated: 2026-09-30

Key dates

DateMilestone
16 January 2023NIS2 Directive (EU) 2022/2555 entered into force
17 October 2024Deadline for member states to adopt national transposition laws
18 October 2024National measures apply; the NIS Directive (EU) 2016/1148 is repealed
17 April 2025Member states to establish their list of essential and important entities

The European Commission opened infringement procedures against member states that did not transpose on time.

Status by member state

CountryTransposition note
AustriaNIS2 transposed via NISG 2024 amendment; BMI acts as central coordinator.
BelgiumTransposed via the Belgian NIS2 Act (Wet van 26 april 2024); CCB is the single competent authority.
BulgariaNIS2 transposition completed via amendments to the Cybersecurity Act; SANS oversees implementation.
CroatiaNIS2 transposed via the Croatian Cybersecurity Act (2024); NSA and SOA share supervisory duties.
CyprusTransposed via the NIS2 Law (2024); DSA acts as the single competent authority and national CSIRT.
CzechiaNIS2 transposed via Act No. 181/2014 Coll. amendment (Zákon o kybernetické bezpečnosti); NÚKIB is the primary authority.
DenmarkTransposed via the Danish NIS2 Act (2024); sector-specific authorities cooperate with CFCS.
EstoniaTransposed via amendments to the Cybersecurity Act (küberturvalisuse seadus); RIA supervises and CERT-EE handles incidents.
FinlandTransposed via the Finnish Cybersecurity Act (2024); Traficom's NCSC-FI unit is the single competent authority.
FranceTransposed via loi no. 2023-703 and decree; ANSSI is the single competent authority with extensive sector coverage.
GermanyTransposed via NIS2UmsuCG (Umsetzungsgesetz, 2024); BSI is the federal competent authority, Länder cooperate for regional entities.
GreeceTransposed via Law 5160/2024; the National Cybersecurity Authority within the Ministry of Digital Governance supervises compliance.
HungaryTransposed via Act XXIII of 2023 on cybersecurity; NBSZ acts as the primary competent authority.
IrelandTransposed via the Network and Information Security (Measures for a High Common Level of Cybersecurity) Regulations 2024.
ItalyTransposed via Legislative Decree 138/2024; ACN is the single competent authority with extensive national NIS2 registry.
LatviaTransposed via the Cybersecurity Law (Kiberdrošības likums, 2024); CERT.LV handles incidents and VARAM oversees sector compliance.
LithuaniaTransposed via the Law on Cybersecurity (2024 amendment); NKSC is both competent authority and national CSIRT.
LuxembourgTransposed via the Law of 17 February 2025; ILR acts as competent authority and CIRCL handles incident coordination.
MaltaTransposed via subsidiary legislation; MCA and MITA share supervisory responsibilities under NIS2.
NetherlandsTransposed via Cybersecurity Wet (Wbni amendment, 2024); NCSC-NL is the national CSIRT and sector-specific bodies act as competent authorities.
PolandTransposed via the Act on the National Cybersecurity System amendment (2024); three national CSIRTs (NASK, GOV, MON) share responsibility.
PortugalTransposed via Decree-Law 65/2021 updated for NIS2 (2024); CNCS is the single competent authority.
RomaniaTransposed via Law 58/2023; DNSC is both the competent authority and national CSIRT for NIS2.
SlovakiaTransposed via the Cybersecurity Act amendment (zákon č. 69/2018 Z. z., 2024); NBÚ and SK-CERT handle supervision and incidents.
SloveniaTransposed via the Information Security Act (ZInfV, 2024); SI-CERT serves as national CSIRT and the Information Commissioner oversees compliance.
SpainTransposed via Royal Decree-Law 2023; INCIBE covers private-sector entities and CCN covers public-sector entities.
SwedenTransposed via the Swedish Cybersecurity Act (Lag om cybersäkerhet, 2024); MSB, FRA, SÄPO and FMV jointly form the NCSC-SE.

Depends on national law: Country notes are a summary; always confirm the current status with the national competent authority.

Related question

Does NIS2 apply if my country has not finished transposing it?

The directive's obligations reach companies through national law, so concrete duties, registration and enforcement start when your country's law applies. Preparing for the Article 21 measures and Article 23 reporting early is still advisable, because the requirements themselves are fixed at EU level.

Next steps

For decision-support purposes only, not legal advice. Exact obligations depend on national transposition — use our free scope checker for a personalised assessment.