Directive (EU) 2022/2555

NIS2 explained: the Article 21 measures, the reporting clock, and where all 27 member states stand

NIS2 is a directive, so the thing that binds you is your member state's implementing law — and those laws arrived years apart, with different scope and different deadlines. This guide sets out the ten minimum measures, the reporting clock, who is personally liable, and a country-by-country tracker of what is actually in force.

Network and Information Security Directive · Transposition deadline was 17 October 2024 · 18 sectors

Verified as at . Positions change as bills pass and implementing acts land, so treat dates as a starting point for verification, not as authority. This is reference material, not legal advice.

Instrument
Directive (EU) 2022/2555
Transposition deadline
17 October 2024
Legal form
Directive — your national implementing law is what binds you
Scope
18 sectors, split into essential and important entities
Reporting clock
Early warning at 24 hours · notification at 72 hours · final report within a month
Maximum fine
€10 million or 2% of global turnover for essential entities
In force as at 2 August 2026
21 of 27 member states
Enacted or phased, not yet fully applicable
3: Austria, Malta and the Netherlands
Still no law in force
3: France, Ireland and Spain

What NIS2 is, and what actually binds you

NIS2 is a directive rather than a regulation, so what binds you is your member state's implementing law and not the directive text. It covers eighteen sectors split into essential entities, including energy, transport, banking, health, water, digital infrastructure, public administration and space, and important entities, including post, waste, chemicals, food, several manufacturing categories, digital providers and research. The size threshold is broadly medium-sized and above, with carve-outs that catch certain providers regardless of headcount.

The ten Article 21 measures

Article 21 sets ten minimum measures every in-scope entity must have. They are minimums, not a ceiling — national law can and does go further.

  • Risk analysis and information system security policies
  • Incident handling
  • Business continuity and crisis management
  • Supply chain security
  • Secure development and vulnerability handling
  • Assessment of the effectiveness of the measures
  • Cyber hygiene practices and training
  • Cryptography policy
  • Access control and asset management
  • Multi-factor authentication

The reporting clock, liability and penalties

Reporting runs on a three-stage clock to the national CSIRT: an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within a month.

The performer is explicitly the management body, which must approve the measures, oversee implementation, undergo training and can be held personally liable. Essential entities face proactive supervision and inspections; important entities are supervised reactively, once a regulator has cause to look. Fines reach 10 million euro or 2% of global turnover for essential entities, and supervisors can suspend senior managers.

One important interaction: DORA is lex specialis for financial entities, so a bank satisfies the ICT risk and incident limbs of NIS2 through DORA rather than doing the work twice.

The state of play, and why it is the hard part

Three member states still have no NIS2 law in force

Only Belgium, Croatia, Italy and Lithuania met the October 2024 deadline. The Commission opened infringement proceedings against 23 member states in November 2024 and escalated to reasoned opinions against 19 of them in May 2025. On 8 July 2026 it referred Ireland, Spain, France and the Netherlands to the Court of Justice of the EU and asked for financial sanctions, though the Dutch law had in fact passed the day before.

France, Ireland and Spain remain without a law in force. That is not a reason to wait. Entry into force has repeatedly been followed by short compliance windows, and Belgium, Germany, Poland and Hungary have all attached national deadlines that arrive faster than a remediation programme can run.

Transposition status by member state

The table below is the operational view: what instrument is in force, who supervises, and which national deadline is the one that will actually catch you.

NIS2 transposition status by member state, as at 2 August 2026
Member stateStatusNational instrumentAuthorityWhat to watch
AustriaApplies 1 Oct 2026NISG 2026, BGBl. I 94/2025, published 23 Dec 2025Enacted but not yet applicableNISG 2018 continues to apply until October
BelgiumIn forceLaw of 26 April 2024, in force 18 Oct 2024CCB, CERT.beEssential entities had to evidence posture by 18 Apr 2026 via CyFun, ISO 27001 or CCB inspection. Full certification due 18 Apr 2027
BulgariaIn forceCybersecurity Act amendment, promulgated 13 Feb 2026National cybersecurity authorityReduced penalties applied to first breaches until 1 Jul 2026
CroatiaIn forceCybersecurity Act, NN 14/2024, in force 15 Feb 2024National frameworkEarliest transposer in the EU
CyprusIn forceLaw 60(I)/2025, in force 25 Apr 2025Digital Security AuthorityAmends the earlier NIS1 law
CzechiaIn forceAct 264/2025 Sb., in force 1 Nov 2025NÚKIB, GovCERT.CZTwo-tier regime. Penalty cap CZK 250m. Later entrants register within 60 days
DenmarkIn forceLOV nr 434, in force 1 Jul 2025CFCS, part of SAMSIK since 1 Jan 2026Registration ran through virk.dk. Energy sector on a parallel act
EstoniaIn forceAmended Cybersecurity Act, in force 1 Jan 2026RIABroadened the set of essential and important entities
FinlandIn forceCybersecurity Act 124/2025, in force 8 Apr 2025Traficom coordinates, NCSC-FI is CSIRT and SPOCDecentralised supervision via sector regulators including Finanssivalvonta
FranceNot transposedLoi Résilience. Senate first reading 12 Mar 2025, Assemblée plenary July 2026ANSSI designatedReferred to the CJEU 8 Jul 2026. ReCyF framework published 17 Mar 2026, pre-registration open. Around 15,000 entities. Scope extended to communes above 30,000 residents
GermanyIn forceNIS2UmsuCG amending the BSIG, in force 6 Dec 2025BSINo transition period. Registration due 6 Mar 2026, BSI set a de facto cut-off of 31 Jul 2026. Roughly 18,500 of an estimated 29,500 entities had registered by end May 2026
GreeceIn forceLaw 5160/2024, in force 27 Nov 2024National Cyber Security AuthorityReorganised the national framework
HungaryIn forceAct LXIX of 2024, in force 1 Jan 2025SZTFHNational first-audit deadline of 30 Jun 2026 passed with 2,132 of 2,520 entities audited on time. Fines to HUF 150m. This audit duty is Hungarian, not EU-wide
IrelandNot transposedNational Cyber Security Bill in pre-legislative scrutinyNCSC-IEReferred to the CJEU 8 Jul 2026. NCSC published board governance guidance on 7 Jul 2026, built on Belgium's CyFun
ItalyIn forceD.Lgs. 138/2024, in force 16 Oct 2024ACN, CSIRT ItaliaAnnual registration window Jan to Feb. Categorisation closed 30 Jun 2026. Basic security measures due 31 Oct 2026. Extra annexes cover public administration and local transport
LatviaIn forceNational Cybersecurity Law, in force 1 Sep 2024National cybersecurity authorityTransposed ahead of the deadline
LithuaniaIn forceAmended Cybersecurity Law, in force 18 Oct 2024NKSCOne of four states that met the deadline
LuxembourgIn forceLaw of 5 May 2026, in force 10 May 2026ILR, with HCPN as SPOC and CSSF for the financial sectorSelf-registration window closed 10 Jul 2026. Implementing regulations on security measures and incident notification still in consultation
MaltaPhasedLegal Notice 71 of 2025, published 8 Apr 2025Malta Digital Innovation AuthorityProvisions commence on dates set by ministerial order, so check what is actually live
NetherlandsIn force 15 Aug 2026Cyberbeveiligingswet, adopted 7 Jul 2026, published Stb. 2026, 187NCSCRegistration mandatory via mijn.ncsc.nl from 15 Aug. Around 8,000 entities. First sectoral regulations for water published 13 Jul 2026
PolandIn forceUKSC amendment, Dz.U. 2026 poz. 252, in force 3 Apr 2026Ministry of Digital Affairs. Three CSIRTs: NASK, GOV and MONScope jumped from roughly 400 to 42,000 entities. Registration via S46 by 3 Oct 2026. Full compliance 3 Apr 2027
PortugalIn forceDecreto-Lei 125/2025, in force 3 Apr 2026CNCS, CERT.PTMyCiber registration platform live since 23 Jun 2026. Security officer notification due within 20 working days of entry into force
RomaniaIn forceOUG 155/2024, approved by Law 124/2025, in force 10 Jul 2025DNSCCompetent authority for both essential and important entities
SlovakiaIn forceAct 366/2024 Z.z., in force 1 Jan 2025NBÚAmends the 2018 cybersecurity act
SloveniaIn forceZInfV-1, in force 19 Jun 2025URSIVDefines essential and important entities under one act
SpainNot transposedFurthest behind of the 27Not yet designated in lawReferred to the CJEU 8 Jul 2026 with a request for financial sanctions
SwedenIn forceCybersäkerhetslagen, SFS 2025:1506, in force 15 Jan 2026NCSC hosted at FRA since 1 Jul 2026, previously MSB then MCFIncident reporting rules applied from 1 Jul 2026. Security measures, management training and audit rules follow on 1 Oct 2026. Decentralised sector supervision

Authority names and registration routes move. Sweden reorganised its national body twice inside eighteen months and Denmark folded its CSIRT into a new agency, so verify the current route before filing anything.

Three things that catch multi-country operators

  • Scope is not uniform. Member states may extend beyond the directive's annexes, and several have. France pulls in local authorities above 30,000 residents, Poland pulls in roughly 28,000 public sector bodies, Italy adds annexes for public administration and local transport. Being out of scope in one country tells you nothing about the next.
  • Reporting routes differ. Most states run a single national CSIRT. Poland runs three, split by sector. Finland and Sweden supervise through sector regulators rather than one central body. You need a routing map keyed on member state and sector, not a single contact.
  • National deadlines are the real deadlines. Hungary required a completed audit by June 2026, Belgium required essential entities to evidence posture by April 2026, Italy requires basic measures by October 2026. None of these come from the directive.

What is coming next

The Commission proposed targeted NIS2 amendments in January 2026 covering submarine infrastructure, digital wallet providers, a small mid-cap category, ransomware reporting detail and post-quantum migration timelines. Separately, the NIS Cooperation Group agreed common incident reporting templates in May 2026, which the Commission intends to make binding by implementing act. That would remove one of the more tedious cross-border differences.

Common questions

Does the NIS2 Directive bind us directly?

No. NIS2 is a directive rather than a regulation, so what binds you is your member state's implementing law and not the directive text. Scope, deadlines and registration routes are all set nationally, and several states have gone beyond the directive's annexes.

Which member states still have no NIS2 law in force?

Three: France, Ireland and Spain. All three were referred to the Court of Justice of the EU on 8 July 2026, with a request for financial sanctions in Spain's case. That is not a reason to wait — entry into force has repeatedly been followed by short compliance windows.

What are the NIS2 incident reporting deadlines?

Reporting runs on a three-stage clock to the national CSIRT: an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within a month.

Who is accountable for NIS2 inside the organisation?

The management body explicitly. It must approve the security measures, oversee implementation, undergo training, and can be held personally liable. Supervisors can also suspend senior managers.

What are the NIS2 fines?

Fines reach 10 million euro or 2% of global turnover for essential entities. Essential entities face proactive supervision and inspections; important entities are supervised reactively, once a regulator has cause to look.

We are a bank. Do we have to do NIS2 and DORA separately?

No. DORA is lex specialis for financial entities, so a bank satisfies the ICT risk and incident limbs of NIS2 through DORA rather than doing the work twice.

We are out of scope in one member state. Does that carry across the EU?

No. Member states may extend beyond the directive's annexes and several have — France pulls in local authorities above 30,000 residents, Poland pulls in roughly 28,000 public sector bodies, and Italy adds annexes for public administration and local transport. Being out of scope in one country tells you nothing about the next.

Producing the evidence is the part that does not stop

ComplianceOS checks your policies, contracts and registers against the official regulatory text and returns findings with verbatim citations, page references and a confidence score — cross-checked by a second model and challenged by an adversarial reviewer. Built for firms that have to prove a control operated, repeatedly, on a supervisor's schedule.

Sources and status

These guides summarise publicly available primary sources including Regulation (EU) 2022/2554, Directive (EU) 2022/2555, Commission Implementing Regulation (EU) 2024/2690 and Regulation (EU) 2023/1114, together with national gazette publications and regulator announcements. The source texts are the binding authority. Nothing here is legal advice or a substitute for counsel in your jurisdiction.

Spotted something out of date? [email protected].