Directive (EU) 2022/2555
NIS2 explained: the Article 21 measures, the reporting clock, and where all 27 member states stand
NIS2 is a directive, so the thing that binds you is your member state's implementing law — and those laws arrived years apart, with different scope and different deadlines. This guide sets out the ten minimum measures, the reporting clock, who is personally liable, and a country-by-country tracker of what is actually in force.
Network and Information Security Directive · Transposition deadline was 17 October 2024 · 18 sectors
Verified as at . Positions change as bills pass and implementing acts land, so treat dates as a starting point for verification, not as authority. This is reference material, not legal advice.
- Instrument
- Directive (EU) 2022/2555
- Transposition deadline
- 17 October 2024
- Legal form
- Directive — your national implementing law is what binds you
- Scope
- 18 sectors, split into essential and important entities
- Reporting clock
- Early warning at 24 hours · notification at 72 hours · final report within a month
- Maximum fine
- €10 million or 2% of global turnover for essential entities
- In force as at 2 August 2026
- 21 of 27 member states
- Enacted or phased, not yet fully applicable
- 3: Austria, Malta and the Netherlands
- Still no law in force
- 3: France, Ireland and Spain
What NIS2 is, and what actually binds you
NIS2 is a directive rather than a regulation, so what binds you is your member state's implementing law and not the directive text. It covers eighteen sectors split into essential entities, including energy, transport, banking, health, water, digital infrastructure, public administration and space, and important entities, including post, waste, chemicals, food, several manufacturing categories, digital providers and research. The size threshold is broadly medium-sized and above, with carve-outs that catch certain providers regardless of headcount.
The ten Article 21 measures
Article 21 sets ten minimum measures every in-scope entity must have. They are minimums, not a ceiling — national law can and does go further.
- Risk analysis and information system security policies
- Incident handling
- Business continuity and crisis management
- Supply chain security
- Secure development and vulnerability handling
- Assessment of the effectiveness of the measures
- Cyber hygiene practices and training
- Cryptography policy
- Access control and asset management
- Multi-factor authentication
The reporting clock, liability and penalties
Reporting runs on a three-stage clock to the national CSIRT: an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within a month.
The performer is explicitly the management body, which must approve the measures, oversee implementation, undergo training and can be held personally liable. Essential entities face proactive supervision and inspections; important entities are supervised reactively, once a regulator has cause to look. Fines reach 10 million euro or 2% of global turnover for essential entities, and supervisors can suspend senior managers.
One important interaction: DORA is lex specialis for financial entities, so a bank satisfies the ICT risk and incident limbs of NIS2 through DORA rather than doing the work twice.
The state of play, and why it is the hard part
Three member states still have no NIS2 law in force
Only Belgium, Croatia, Italy and Lithuania met the October 2024 deadline. The Commission opened infringement proceedings against 23 member states in November 2024 and escalated to reasoned opinions against 19 of them in May 2025. On 8 July 2026 it referred Ireland, Spain, France and the Netherlands to the Court of Justice of the EU and asked for financial sanctions, though the Dutch law had in fact passed the day before.
France, Ireland and Spain remain without a law in force. That is not a reason to wait. Entry into force has repeatedly been followed by short compliance windows, and Belgium, Germany, Poland and Hungary have all attached national deadlines that arrive faster than a remediation programme can run.
Transposition status by member state
The table below is the operational view: what instrument is in force, who supervises, and which national deadline is the one that will actually catch you.
| Member state | Status | National instrument | Authority | What to watch |
|---|---|---|---|---|
| Austria | Applies 1 Oct 2026 | NISG 2026, BGBl. I 94/2025, published 23 Dec 2025 | Enacted but not yet applicable | NISG 2018 continues to apply until October |
| Belgium | In force | Law of 26 April 2024, in force 18 Oct 2024 | CCB, CERT.be | Essential entities had to evidence posture by 18 Apr 2026 via CyFun, ISO 27001 or CCB inspection. Full certification due 18 Apr 2027 |
| Bulgaria | In force | Cybersecurity Act amendment, promulgated 13 Feb 2026 | National cybersecurity authority | Reduced penalties applied to first breaches until 1 Jul 2026 |
| Croatia | In force | Cybersecurity Act, NN 14/2024, in force 15 Feb 2024 | National framework | Earliest transposer in the EU |
| Cyprus | In force | Law 60(I)/2025, in force 25 Apr 2025 | Digital Security Authority | Amends the earlier NIS1 law |
| Czechia | In force | Act 264/2025 Sb., in force 1 Nov 2025 | NÚKIB, GovCERT.CZ | Two-tier regime. Penalty cap CZK 250m. Later entrants register within 60 days |
| Denmark | In force | LOV nr 434, in force 1 Jul 2025 | CFCS, part of SAMSIK since 1 Jan 2026 | Registration ran through virk.dk. Energy sector on a parallel act |
| Estonia | In force | Amended Cybersecurity Act, in force 1 Jan 2026 | RIA | Broadened the set of essential and important entities |
| Finland | In force | Cybersecurity Act 124/2025, in force 8 Apr 2025 | Traficom coordinates, NCSC-FI is CSIRT and SPOC | Decentralised supervision via sector regulators including Finanssivalvonta |
| France | Not transposed | Loi Résilience. Senate first reading 12 Mar 2025, Assemblée plenary July 2026 | ANSSI designated | Referred to the CJEU 8 Jul 2026. ReCyF framework published 17 Mar 2026, pre-registration open. Around 15,000 entities. Scope extended to communes above 30,000 residents |
| Germany | In force | NIS2UmsuCG amending the BSIG, in force 6 Dec 2025 | BSI | No transition period. Registration due 6 Mar 2026, BSI set a de facto cut-off of 31 Jul 2026. Roughly 18,500 of an estimated 29,500 entities had registered by end May 2026 |
| Greece | In force | Law 5160/2024, in force 27 Nov 2024 | National Cyber Security Authority | Reorganised the national framework |
| Hungary | In force | Act LXIX of 2024, in force 1 Jan 2025 | SZTFH | National first-audit deadline of 30 Jun 2026 passed with 2,132 of 2,520 entities audited on time. Fines to HUF 150m. This audit duty is Hungarian, not EU-wide |
| Ireland | Not transposed | National Cyber Security Bill in pre-legislative scrutiny | NCSC-IE | Referred to the CJEU 8 Jul 2026. NCSC published board governance guidance on 7 Jul 2026, built on Belgium's CyFun |
| Italy | In force | D.Lgs. 138/2024, in force 16 Oct 2024 | ACN, CSIRT Italia | Annual registration window Jan to Feb. Categorisation closed 30 Jun 2026. Basic security measures due 31 Oct 2026. Extra annexes cover public administration and local transport |
| Latvia | In force | National Cybersecurity Law, in force 1 Sep 2024 | National cybersecurity authority | Transposed ahead of the deadline |
| Lithuania | In force | Amended Cybersecurity Law, in force 18 Oct 2024 | NKSC | One of four states that met the deadline |
| Luxembourg | In force | Law of 5 May 2026, in force 10 May 2026 | ILR, with HCPN as SPOC and CSSF for the financial sector | Self-registration window closed 10 Jul 2026. Implementing regulations on security measures and incident notification still in consultation |
| Malta | Phased | Legal Notice 71 of 2025, published 8 Apr 2025 | Malta Digital Innovation Authority | Provisions commence on dates set by ministerial order, so check what is actually live |
| Netherlands | In force 15 Aug 2026 | Cyberbeveiligingswet, adopted 7 Jul 2026, published Stb. 2026, 187 | NCSC | Registration mandatory via mijn.ncsc.nl from 15 Aug. Around 8,000 entities. First sectoral regulations for water published 13 Jul 2026 |
| Poland | In force | UKSC amendment, Dz.U. 2026 poz. 252, in force 3 Apr 2026 | Ministry of Digital Affairs. Three CSIRTs: NASK, GOV and MON | Scope jumped from roughly 400 to 42,000 entities. Registration via S46 by 3 Oct 2026. Full compliance 3 Apr 2027 |
| Portugal | In force | Decreto-Lei 125/2025, in force 3 Apr 2026 | CNCS, CERT.PT | MyCiber registration platform live since 23 Jun 2026. Security officer notification due within 20 working days of entry into force |
| Romania | In force | OUG 155/2024, approved by Law 124/2025, in force 10 Jul 2025 | DNSC | Competent authority for both essential and important entities |
| Slovakia | In force | Act 366/2024 Z.z., in force 1 Jan 2025 | NBÚ | Amends the 2018 cybersecurity act |
| Slovenia | In force | ZInfV-1, in force 19 Jun 2025 | URSIV | Defines essential and important entities under one act |
| Spain | Not transposed | Furthest behind of the 27 | Not yet designated in law | Referred to the CJEU 8 Jul 2026 with a request for financial sanctions |
| Sweden | In force | Cybersäkerhetslagen, SFS 2025:1506, in force 15 Jan 2026 | NCSC hosted at FRA since 1 Jul 2026, previously MSB then MCF | Incident reporting rules applied from 1 Jul 2026. Security measures, management training and audit rules follow on 1 Oct 2026. Decentralised sector supervision |
Authority names and registration routes move. Sweden reorganised its national body twice inside eighteen months and Denmark folded its CSIRT into a new agency, so verify the current route before filing anything.
Three things that catch multi-country operators
- Scope is not uniform. Member states may extend beyond the directive's annexes, and several have. France pulls in local authorities above 30,000 residents, Poland pulls in roughly 28,000 public sector bodies, Italy adds annexes for public administration and local transport. Being out of scope in one country tells you nothing about the next.
- Reporting routes differ. Most states run a single national CSIRT. Poland runs three, split by sector. Finland and Sweden supervise through sector regulators rather than one central body. You need a routing map keyed on member state and sector, not a single contact.
- National deadlines are the real deadlines. Hungary required a completed audit by June 2026, Belgium required essential entities to evidence posture by April 2026, Italy requires basic measures by October 2026. None of these come from the directive.
What is coming next
The Commission proposed targeted NIS2 amendments in January 2026 covering submarine infrastructure, digital wallet providers, a small mid-cap category, ransomware reporting detail and post-quantum migration timelines. Separately, the NIS Cooperation Group agreed common incident reporting templates in May 2026, which the Commission intends to make binding by implementing act. That would remove one of the more tedious cross-border differences.
Common questions
Does the NIS2 Directive bind us directly?
No. NIS2 is a directive rather than a regulation, so what binds you is your member state's implementing law and not the directive text. Scope, deadlines and registration routes are all set nationally, and several states have gone beyond the directive's annexes.
Which member states still have no NIS2 law in force?
Three: France, Ireland and Spain. All three were referred to the Court of Justice of the EU on 8 July 2026, with a request for financial sanctions in Spain's case. That is not a reason to wait — entry into force has repeatedly been followed by short compliance windows.
What are the NIS2 incident reporting deadlines?
Reporting runs on a three-stage clock to the national CSIRT: an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within a month.
Who is accountable for NIS2 inside the organisation?
The management body explicitly. It must approve the security measures, oversee implementation, undergo training, and can be held personally liable. Supervisors can also suspend senior managers.
What are the NIS2 fines?
Fines reach 10 million euro or 2% of global turnover for essential entities. Essential entities face proactive supervision and inspections; important entities are supervised reactively, once a regulator has cause to look.
We are a bank. Do we have to do NIS2 and DORA separately?
No. DORA is lex specialis for financial entities, so a bank satisfies the ICT risk and incident limbs of NIS2 through DORA rather than doing the work twice.
We are out of scope in one member state. Does that carry across the EU?
No. Member states may extend beyond the directive's annexes and several have — France pulls in local authorities above 30,000 residents, Poland pulls in roughly 28,000 public sector bodies, and Italy adds annexes for public administration and local transport. Being out of scope in one country tells you nothing about the next.
The other two guides
Regulation (EU) 2022/2554
DORA — Digital Operational Resilience Act
One binding set of ICT resilience rules across roughly twenty categories of EU financial entity: governance the board owns, an incident clock measured in hours, resilience testing, and a Register of Information covering every ICT contract.
Read the DORA guideRegulation (EU) 2023/1114
MiCA — Markets in Crypto-Assets Regulation
A single EU authorisation regime for crypto, split across issuers of ordinary tokens, asset-referenced tokens and e-money tokens, plus crypto-asset service providers. Every transitional window closed on 1 July 2026.
Read the MiCA guideProducing the evidence is the part that does not stop
ComplianceOS checks your policies, contracts and registers against the official regulatory text and returns findings with verbatim citations, page references and a confidence score — cross-checked by a second model and challenged by an adversarial reviewer. Built for firms that have to prove a control operated, repeatedly, on a supervisor's schedule.
Sources and status
These guides summarise publicly available primary sources including Regulation (EU) 2022/2554, Directive (EU) 2022/2555, Commission Implementing Regulation (EU) 2024/2690 and Regulation (EU) 2023/1114, together with national gazette publications and regulator announcements. The source texts are the binding authority. Nothing here is legal advice or a substitute for counsel in your jurisdiction.
Spotted something out of date? [email protected].