NIS2 is an EU directive. A directive is addressed to Member States: it sets a common target, and each country writes its own national law to reach it. Entities are bound by the national law of the country where they are established or provide services, not by the EU text itself.
This means obligations, competent authority, reporting portal, sanctions and even the list of covered entities can differ from one Member State to the next — and the transposition timeline differs too. Some countries were in force on 18 October 2024, others are still in parliamentary process well into 2025 and 2026.
Nix2 therefore tracks each national transposition (e.g. BE CyFun, NL Cyberbeveiligingswet, DE NIS2UmsuCG, IT D.Lgs. 138/2024, FR bill in progress) as its own framework, with its own catalog, evidence expectations and citations — because the EU directive alone is not what a compliance officer must satisfy.
Essential and important entities in the sectors listed in the national transposition (energy, transport, banking, health, digital infrastructure, ICT service management, public administration, postal, waste, food, manufacturing, digital providers, research…).
Size threshold generally follows the EU medium/large enterprise definition — indicatively >50 staff or >€10M turnover / balance sheet — but the exact wording is set by each national law.
Certain entities regardless of size when they play a critical role (e.g. sole DNS/TLD providers, trust service providers, certain public administrations).
Cybersecurity risk-management measures across governance, incident handling, business continuity, supply chain, access control, cryptography and HR security — implemented per the national law.
Management-body accountability, approval of the measures and mandatory training.
Incident reporting to the national CSIRT / competent authority: early warning without undue delay and in any event within 24h of awareness, incident notification within 72h, final report within 1 month.
Registration with the national authority and cooperation with national supervisory activity (inspections, audits, requests for information).
- 2020-12-16European Commission proposal for NIS2
- 2022-11-10European Parliament adopts NIS2
- 2022-11-28Council of the EU adopts NIS2
- 2022-12-27Directive (EU) 2022/2555 published in the Official Journal
- 2023-01-16EU entry into force (20 days after OJ publication)
- 2024-10-17Deadline for Member States to transpose NIS2 into national law
- 2024-10-18From this date, national transposition laws must apply — where they have actually been adopted and entered into force
Because NIS2 is a directive, what actually binds your organisation is the national law of each Member State. Below is the status of the transpositions Nix2 tracks with verified primary sources. Countries not listed yet are being added as their laws progress — no status is inferred from the EU text alone.
Status verified against official government sources. Not legal advice.
License · EU legislative texts are reusable under the EUR-Lex reuse policy (© European Union).