National transposition
NIS2 transposition tracker — all 27 EU countries
NIS2 is an EU directive: it only takes effect once each member state transposes it into national law — with its own authority, thresholds and deadlines. The EU-wide deadline was 17 October 2024, but national implementation has moved at different speeds. Here is where each of the 27 states stands, with the competent authority and national CSIRT for each.
Indicative reference, not certification. National transposition is still evolving and varies in detail (scope thresholds, registration deadlines, sector coverage). The notes below are compiled from public sources as of 2026-09-23 — always confirm the current status with the national authority before you rely on it. NISDESK does not certify transposition status.
| Country | Competent authority | National CSIRT | Transposition note (verify at source) | |
|---|---|---|---|---|
| Austria | Federal Ministry of the Interior (BMI) / CERT.at | CERT.at | NIS2 transposed via NISG 2024 amendment; BMI acts as central coordinator. | Details → |
| Belgium | Centre for Cybersecurity Belgium (CCB) | CERT.be | Transposed via the Belgian NIS2 Act (Wet van 26 april 2024); CCB is the single competent authority. | Details → |
| Bulgaria | State Agency for National Security (SANS) / National CSIRT | CERT Bulgaria | NIS2 transposition completed via amendments to the Cybersecurity Act; SANS oversees implementation. | Details → |
| Croatia | National Cybersecurity Authority (NSA) / SOA | CARNET-CERT | NIS2 transposed via the Croatian Cybersecurity Act (2024); NSA and SOA share supervisory duties. | Details → |
| Cyprus | Digital Security Authority (DSA) | CSIRT-CY | Transposed via the NIS2 Law (2024); DSA acts as the single competent authority and national CSIRT. | Details → |
| Czechia | NÚKIB (National Cyber and Information Security Agency) | CSIRT.CZ | NIS2 transposed via Act No. 181/2014 Coll. amendment (Zákon o kybernetické bezpečnosti); NÚKIB is the primary authority. | Details → |
| Denmark | Centre for Cyber Security (CFCS) / Danish Business Authority | CFCS | Transposed via the Danish NIS2 Act (2024); sector-specific authorities cooperate with CFCS. | Details → |
| Estonia | Information System Authority (RIA) | CERT-EE | Transposed via amendments to the Cybersecurity Act (küberturvalisuse seadus); RIA supervises and CERT-EE handles incidents. | Details → |
| Finland | Finnish Transport and Communications Agency (Traficom / NCSC-FI) | NCSC-FI | Transposed via the Finnish Cybersecurity Act (2024); Traficom's NCSC-FI unit is the single competent authority. | Details → |
| France | ANSSI (Agence nationale de la sécurité des systèmes d'information) | CERT-FR | Transposed via loi no. 2023-703 and decree; ANSSI is the single competent authority with extensive sector coverage. | Details → |
| Germany | BSI (Bundesamt für Sicherheit in der Informationstechnik) | CERT-Bund | Transposed via NIS2UmsuCG (Umsetzungsgesetz, 2024); BSI is the federal competent authority, Länder cooperate for regional entities. | Details → |
| Greece | National Cybersecurity Authority (ENISA-GR) / GSRT | GR-CSIRT | Transposed via Law 5160/2024; the National Cybersecurity Authority within the Ministry of Digital Governance supervises compliance. | Details → |
| Hungary | National Cybersecurity Authority (NBSZ) | GovCERT Hungary | Transposed via Act XXIII of 2023 on cybersecurity; NBSZ acts as the primary competent authority. | Details → |
| Ireland | National Cyber Security Centre (NCSC Ireland) | NCSC-IE | Transposed via the Network and Information Security (Measures for a High Common Level of Cybersecurity) Regulations 2024. | Details → |
| Italy | ACN (Agenzia per la Cybersicurezza Nazionale) | CSIRT Italia | Transposed via Legislative Decree 138/2024; ACN is the single competent authority with extensive national NIS2 registry. | Details → |
| Latvia | Information Technology Security Incident Response Institution (CERT.LV) / VARAM | CERT.LV | Transposed via the Cybersecurity Law (Kiberdrošības likums, 2024); CERT.LV handles incidents and VARAM oversees sector compliance. | Details → |
| Lithuania | National Cyber Security Centre (NKSC) | NKSC-LT | Transposed via the Law on Cybersecurity (2024 amendment); NKSC is both competent authority and national CSIRT. | Details → |
| Luxembourg | Institut Luxembourgeois de Régulation (ILR) / CIRCL | CIRCL (Computer Incident Response Center Luxembourg) | Transposed via the Law of 17 February 2025; ILR acts as competent authority and CIRCL handles incident coordination. | Details → |
| Malta | Malta Information Technology Agency (MITA) / MCA | MITA-CSIRT | Transposed via subsidiary legislation; MCA and MITA share supervisory responsibilities under NIS2. | Details → |
| Netherlands | NCSC-NL (Nationaal Cyber Security Centrum) | NCSC-NL | Transposed via Cybersecurity Wet (Wbni amendment, 2024); NCSC-NL is the national CSIRT and sector-specific bodies act as competent authorities. | Details → |
| Poland | CSIRT NASK / Ministry of Digitisation | CSIRT NASK | Transposed via the Act on the National Cybersecurity System amendment (2024); three national CSIRTs (NASK, GOV, MON) share responsibility. | Details → |
| Portugal | CNCS (Centro Nacional de Cibersegurança) | CERT.PT | Transposed via Decree-Law 65/2021 updated for NIS2 (2024); CNCS is the single competent authority. | Details → |
| Romania | DNSC (Directoratul Național de Securitate Cibernetică) | DNSC-CERT | Transposed via Law 58/2023; DNSC is both the competent authority and national CSIRT for NIS2. | Details → |
| Slovakia | NBÚ (National Security Authority / Národný bezpečnostný úrad) | SK-CERT | Transposed via the Cybersecurity Act amendment (zákon č. 69/2018 Z. z., 2024); NBÚ and SK-CERT handle supervision and incidents. | Details → |
| Slovenia | SI-CERT / Information Commissioner | SI-CERT | Transposed via the Information Security Act (ZInfV, 2024); SI-CERT serves as national CSIRT and the Information Commissioner oversees compliance. | Details → |
| Spain | INCIBE / CCN (Centro Criptológico Nacional) | INCIBE-CERT / CCN-CERT | Transposed via Royal Decree-Law 2023; INCIBE covers private-sector entities and CCN covers public-sector entities. | Details → |
| Sweden | NCSC-SE (Swedish National Cyber Security Centre) / CERT-SE | CERT-SE | Transposed via the Swedish Cybersecurity Act (Lag om cybersäkerhet, 2024); MSB, FRA, SÄPO and FMV jointly form the NCSC-SE. | Details → |
Last reviewed: 2026-09-23. NISDESK is a decision-support tool, not legal advice.
Not sure if NIS2 applies to you in your country?
Run the free scope check — an immediate verdict on whether you're an essential or important entity, mapped to your sector and country.
Official sources
- NIS2 Directive (EU) 2022/2555 — EUR-Lex
- DORA Regulation (EU) 2022/2554 — EUR-Lex
- ENISA — EU Agency for Cybersecurity
Last reviewed: 2026-07-03