NIS2 does not bind your company. Your national law does.
Directive (EU) 2022/2555 addresses Member States, not undertakings. The fines, the reporting clocks and the authority you answer to are written in national law, and those laws arrived on twenty-seven different calendars.

Open almost any NIS2 gap analysis in circulation and the obligation column says something like: NIS2, Article 21(2). That citation appears in questionnaires, internal audit plans, board packs and vendor security schedules across the Union. It is the most common reference in European cyber compliance, and as a statement of what binds a company it is wrong.
Directive (EU) 2022/2555 does not address undertakings. Under Article 288 TFEU, a directive binds each Member State as to the result to be achieved (Consolidated Version of the Treaty on the Functioning of the European Union, OJ C 326, 26.10.2012). The Court of Justice settled the corollary decades ago: directives cannot of themselves impose obligations on private parties. Van Duyn v Home Office (Case 41/74, judgment of 4 December 1974) established that a directive can be invoked against a state, not between private parties, and Faccini Dori (Case C-91/92, judgment of 14 July 1994) confirmed the rule in the horizontal direction: a private company cannot be sued on the text of an untransposed directive, and individuals cannot rely on directives against each other. There is one narrow exception that matters in practice: after a transposition deadline has passed, a party may rely on the directive against state bodies and emanations of the state (Faccini Dori, following Becker). States also cannot rely on their own failure to transpose. None of that makes Article 21 of the directive a rule your company must follow. It makes it a rule your government must implement.
So the instrument that binds a company is the national transposition law in each Member State where it operates. That sounds like a pedantic distinction until you look at what actually happened between October 2024 and today.
Twenty-seven calendars, one deadline
Article 41(1) of the directive required Member States to adopt and publish their transposition measures by 17 October 2024, and Article 41(3) required them to apply those measures from 18 October 2024 (Directive (EU) 2022/2555, OJ L 333, 27.12.2022). Only a handful of states had a law in force on that date.
The Commission's response is now a documented sequence. On 28 November 2024 it sent letters of formal notice to 23 Member States for failing to notify full transposition. On 7 May 2025 it sent reasoned opinions to 19 of them. On 8 July 2026 it referred Ireland, Spain, France and the Netherlands to the Court of Justice and asked the Court to impose financial sanctions on those states for the failure (European Commission infringement packages INF/24/5988 and INF/25/982; press release IP/26/1499). Read that last line twice, because it is the argument in miniature: when the Union wants NIS2 enforced, it sues governments. Companies are not parties to that case and never were. Enforcement of this directive runs on national machinery, or it does not run at all.
For the countries referred in July 2026, the practical situation was stranger than any compliance framework anticipates: France, Spain, Ireland and the Netherlands spent close to two years with no binding national NIS2 law at all. The Netherlands finally closed the gap when its Cyberbeveiligingswet entered into force on 15 August 2026 (Staatsblad 2026, 187). A Dutch in-scope entity's "NIS2 compliance position" was, for most of that period, a citation to a law that did not exist.
Minimum harmonisation is the clause everyone skips
The next reason the directive-only register fails is structural. NIS2 is a minimum harmonisation instrument. Article 5 provides that Member States may, in accordance with Union law, maintain or provide for more stringent measures (Directive (EU) 2022/2555, Article 5; see Recital 9). The directive is a floor. It guarantees that preparing against Article 21 is not wasted work. It does not guarantee that your preparation is complete in any given state.
What varies in practice is not exotic. It is the operational spine of the programme:
- The competent authority you answer to, and the CSIRT that receives your notifications, are named by national law. Article 23 sets the reporting chain and its clocks (early warning within 24 hours of becoming aware, an incident notification within 72 hours, a final report within one month), but the recipient on the other end is a national appointment (Directive (EU) 2022/2555, Article 23).
- Registration duties and their deadlines are national. Several transposition laws gave in-scope entities only a few months to register once the law entered into force; our transposition tracker documents the range with a dated source per country (NIS2 transposition tracker).
- Sanction schemes are national. Article 34(4) requires Member States to provide for fines of at least EUR 10,000,000 or 2% of total worldwide annual turnover for essential entities, and Article 34(5) requires at least EUR 7,000,000 or 1.4% for important entities, whichever is higher in each case. Those are floors on what national law must make possible. The actual fine a supervisor can impose on you, and the procedure that leads to it, exist only in the national text (Directive (EU) 2022/2555, Article 34).
- Designation of essential and important entities, and the supervision regime attached to each, are administered nationally, with national variation in how proactive the supervisor is.
Two programmes can therefore run the same Article 21 measures in the same sector and still face different authorities, different registration clocks and different fine exposure, because the obligations that matter operationally live at the national layer.
The objection, and why it does not survive
The standard rebuttal goes: the directive is the superset, so a programme built against Article 21 covers whatever each state adds. Even granting that, it fails on the citation itself. A register that says "NIS2, Article 21(2)" cannot answer the first question a competent supervisor, an auditor or a procurement security reviewer actually asks: which national law, which authority, which reporting channel, which fine ceiling. An obligation register is a legal document, not a thematic map. If it cites a text that imposes no obligation on the company, it cites the wrong text.
The failure mode is not theoretical. Programmes that scoped against the directive in late 2024, in the states that had not yet transposed, produced work with no legal object in their own jurisdiction for up to two years. Programmes in states that transposed early with stricter provisions are now bound by requirements the directive never mentions, and a directive-level register misses them by construction. And because Article 5 makes every national law free to exceed the floor, the gap between "directive-compliant" and "law-compliant" is not an edge case. It is the design of the instrument.
The rule worth keeping
Treat the directive as your scoping input and the national law as your obligation baseline. The directive tells you which categories of entity are in scope, gives the minimum set of Article 21 measures, and fixes the reporting architecture. The national law tells you who supervises you, by when you must register, what you must actually file, and what it costs if you do not. A defensible register cites both, with the national text doing the binding.
For multi-market operators this is a per-state discipline, not a programme-level footnote: one register per Member State of operation, each row with a dated primary source, refreshed as transposition law moves. The Commission's infringement file is the calendar to watch; the national gazettes are the texts to read.
If the near-term task is turning that structure into an obligation register with per-state citations, that cross-referencing work is the kind of thing ISMS Copilot is built to accelerate: the framework knowledge is in the assistant, and the register discipline is the practitioner's to enforce.
This is practical compliance analysis, not legal advice. Confirm the transposition status and operative national law for every Member State where you operate, and take qualified counsel where the stakes require it.
Related Posts

The internal audit that never finds anything
ISO 19011 changed edition in May 2026. The failure mode it exists to prevent did not: the internal audit that has, by drift, stopped disagreeing with management.

Under NIS2, "important" is not a lighter security tier
Teams read the important label as NIS2-lite and scope their controls down. The security measures in Article 21 are the same either way; the tier changes supervision, some enforcement tools, and the floor on the national fine maximum.

Your ISO 27001 certificate does not start DORA's clocks
Financial entities keep mapping ISO 27001 controls onto DORA articles and calling the residue paperwork. DORA's real additions are duties that must be performed, to a specification and on a clock, that a certificate was never designed to test.
