Zum Inhalt springen
NISDESK

National transposition

NIS2 transposition tracker — all 27 EU countries

NIS2 is an EU directive: it only takes effect once each member state transposes it into national law — with its own authority, thresholds and deadlines. The EU-wide deadline was 17 October 2024, but national implementation has moved at different speeds. Here is where each of the 27 states stands, with the competent authority and national CSIRT for each.

Indicative reference, not certification. National transposition is still evolving and varies in detail (scope thresholds, registration deadlines, sector coverage). The notes below are compiled from public sources as of 2026-09-23 — always confirm the current status with the national authority before you rely on it. NISDESK does not certify transposition status.

CountryCompetent authorityNational CSIRTTransposition note (verify at source)
AustriaFederal Ministry of the Interior (BMI) / CERT.atCERT.atNIS2 transposed via NISG 2024 amendment; BMI acts as central coordinator.Details →
BelgiumCentre for Cybersecurity Belgium (CCB)CERT.beTransposed via the Belgian NIS2 Act (Wet van 26 april 2024); CCB is the single competent authority.Details →
BulgariaState Agency for National Security (SANS) / National CSIRTCERT BulgariaNIS2 transposition completed via amendments to the Cybersecurity Act; SANS oversees implementation.Details →
CroatiaNational Cybersecurity Authority (NSA) / SOACARNET-CERTNIS2 transposed via the Croatian Cybersecurity Act (2024); NSA and SOA share supervisory duties.Details →
CyprusDigital Security Authority (DSA)CSIRT-CYTransposed via the NIS2 Law (2024); DSA acts as the single competent authority and national CSIRT.Details →
CzechiaNÚKIB (National Cyber and Information Security Agency)CSIRT.CZNIS2 transposed via Act No. 181/2014 Coll. amendment (Zákon o kybernetické bezpečnosti); NÚKIB is the primary authority.Details →
DenmarkCentre for Cyber Security (CFCS) / Danish Business AuthorityCFCSTransposed via the Danish NIS2 Act (2024); sector-specific authorities cooperate with CFCS.Details →
EstoniaInformation System Authority (RIA)CERT-EETransposed via amendments to the Cybersecurity Act (küberturvalisuse seadus); RIA supervises and CERT-EE handles incidents.Details →
FinlandFinnish Transport and Communications Agency (Traficom / NCSC-FI)NCSC-FITransposed via the Finnish Cybersecurity Act (2024); Traficom's NCSC-FI unit is the single competent authority.Details →
FranceANSSI (Agence nationale de la sécurité des systèmes d'information)CERT-FRTransposed via loi no. 2023-703 and decree; ANSSI is the single competent authority with extensive sector coverage.Details →
GermanyBSI (Bundesamt für Sicherheit in der Informationstechnik)CERT-BundTransposed via NIS2UmsuCG (Umsetzungsgesetz, 2024); BSI is the federal competent authority, Länder cooperate for regional entities.Details →
GreeceNational Cybersecurity Authority (ENISA-GR) / GSRTGR-CSIRTTransposed via Law 5160/2024; the National Cybersecurity Authority within the Ministry of Digital Governance supervises compliance.Details →
HungaryNational Cybersecurity Authority (NBSZ)GovCERT HungaryTransposed via Act XXIII of 2023 on cybersecurity; NBSZ acts as the primary competent authority.Details →
IrelandNational Cyber Security Centre (NCSC Ireland)NCSC-IETransposed via the Network and Information Security (Measures for a High Common Level of Cybersecurity) Regulations 2024.Details →
ItalyACN (Agenzia per la Cybersicurezza Nazionale)CSIRT ItaliaTransposed via Legislative Decree 138/2024; ACN is the single competent authority with extensive national NIS2 registry.Details →
LatviaInformation Technology Security Incident Response Institution (CERT.LV) / VARAMCERT.LVTransposed via the Cybersecurity Law (Kiberdrošības likums, 2024); CERT.LV handles incidents and VARAM oversees sector compliance.Details →
LithuaniaNational Cyber Security Centre (NKSC)NKSC-LTTransposed via the Law on Cybersecurity (2024 amendment); NKSC is both competent authority and national CSIRT.Details →
LuxembourgInstitut Luxembourgeois de Régulation (ILR) / CIRCLCIRCL (Computer Incident Response Center Luxembourg)Transposed via the Law of 17 February 2025; ILR acts as competent authority and CIRCL handles incident coordination.Details →
MaltaMalta Information Technology Agency (MITA) / MCAMITA-CSIRTTransposed via subsidiary legislation; MCA and MITA share supervisory responsibilities under NIS2.Details →
NetherlandsNCSC-NL (Nationaal Cyber Security Centrum)NCSC-NLTransposed via Cybersecurity Wet (Wbni amendment, 2024); NCSC-NL is the national CSIRT and sector-specific bodies act as competent authorities.Details →
PolandCSIRT NASK / Ministry of DigitisationCSIRT NASKTransposed via the Act on the National Cybersecurity System amendment (2024); three national CSIRTs (NASK, GOV, MON) share responsibility.Details →
PortugalCNCS (Centro Nacional de Cibersegurança)CERT.PTTransposed via Decree-Law 65/2021 updated for NIS2 (2024); CNCS is the single competent authority.Details →
RomaniaDNSC (Directoratul Național de Securitate Cibernetică)DNSC-CERTTransposed via Law 58/2023; DNSC is both the competent authority and national CSIRT for NIS2.Details →
SlovakiaNBÚ (National Security Authority / Národný bezpečnostný úrad)SK-CERTTransposed via the Cybersecurity Act amendment (zákon č. 69/2018 Z. z., 2024); NBÚ and SK-CERT handle supervision and incidents.Details →
SloveniaSI-CERT / Information CommissionerSI-CERTTransposed via the Information Security Act (ZInfV, 2024); SI-CERT serves as national CSIRT and the Information Commissioner oversees compliance.Details →
SpainINCIBE / CCN (Centro Criptológico Nacional)INCIBE-CERT / CCN-CERTTransposed via Royal Decree-Law 2023; INCIBE covers private-sector entities and CCN covers public-sector entities.Details →
SwedenNCSC-SE (Swedish National Cyber Security Centre) / CERT-SECERT-SETransposed via the Swedish Cybersecurity Act (Lag om cybersäkerhet, 2024); MSB, FRA, SÄPO and FMV jointly form the NCSC-SE.Details →

Last reviewed: 2026-09-23. NISDESK is a decision-support tool, not legal advice.

Not sure if NIS2 applies to you in your country?

Run the free scope check — an immediate verdict on whether you're an essential or important entity, mapped to your sector and country.