ISMS Copilot

Last updated: 2026-07-29· Jurisdiction: EU (Directive (EU) 2022/2555, which binds organisations only through each Member State's own transposition law) · Each row shows the date we last verified it against the linked source

NIS 2 transposition tracker: where all 27 EU Member States stand

NIS 2 is a directive, not a regulation. For private organisations, obligations, registration duties, deadlines and penalties arrive through the Member State's own transposition law (EU law recognises narrow direct-effect exceptions, mainly against public bodies once a deadline has been missed), and the Member States are moving at very different speeds. This page tracks that one variable, per country, against a dated authoritative source you can re-check yourself.

The state of play at our last verification

22 of 27 Member States had a national NIS 2 transposition law adopted and in force, and 5 were still legislating (bill in progress, or adopted but not yet in force), even though the Article 41 transposition deadline passed on 17 October 2024. Counts are computed from the table below, so they always match it.

Status by Member State

Sorted alphabetically. “National law in force” means we verified that a transposition act has been adopted and has entered into force; “not yet in force” covers everything from an early bill to an adopted law awaiting its commencement date, with the detail in the note. Every row links the most authoritative source we could verify: the national authority where we track one, otherwise the European Commission's official tracker.

Member StateStatusWhat we last verifiedVerifiedSource
AustriaNot yet in forceAdopted but not yet in force: the NISG 2026 was published on 23 Dec 2025 (BGBl. I Nr. 94/2025) and its main obligations apply from 1 Oct 2026, with registration due within three months of applicability and no later than 31 Dec 2026. A new Federal Office for Cybersecurity takes over supervision. Verify via the source.2026-07-29parlament.gv.at
BelgiumNational law in forceTransposed; the Centre for Cybersecurity Belgium (CCB) is the national competent authority and single point of contact. Confirm your entity's classification and registration duties with the CCB via the source.2026-07-17digital-strategy.ec.europa.eu
BulgariaNational law in forceTransposed by amending the Cybersecurity Act; the amending act was promulgated in State Gazette No 17 of 13 Feb 2026 (the linked source is the official gazette text) and is in force since February 2026, with public sources differing between 13 and 17 Feb on the exact commencement day. Reduced sanctions applied until 1 Jun 2026 while secondary legislation phases in; the Ministry of e-Government leads the entity register. The EU tracker page lagged this change at our last check. Verify via the source.2026-07-29dv.parliament.bg
CroatiaNational law in forceTransposed via the Cybersecurity Act (OG 14/2024), in force since 15 Feb 2024, months ahead of the EU deadline, with an implementing regulation adopted in Nov 2024. The National Cyber Security Centre within the SOA is the central state authority; entity categorisation is carried out by it and the sectoral competent authorities, with the resulting lists centralised. Verify via the source.2026-07-29ncsc.hr
CyprusNational law in forceTransposed via the Security of Networks and Information Systems (Amendment) Law 60(I)/2025, published 25 Apr 2025 and in force from publication. The Digital Security Authority supervises, with express top-management responsibility for cyber-risk management. Verify via the source.2026-07-29cylaw.org
CzechiaNational law in forceTransposed via Act No 264/2025 Coll. on cybersecurity, in force since 1 Nov 2025 together with its implementing decrees, replacing the 2014 act. Regulated entities had 60 days from effectiveness to self-identify to NÚKIB, whose portal provides a scoping calculator. Verify via the source.2026-07-29nukib.gov.cz
DenmarkNational law in forceTransposed via the NIS 2 Act (Act No 434 of 6 May 2025), in force since 1 Jul 2025. Entities in scope from day one had to register via Virk.dk by 1 Oct 2025; the Danish Agency for Societal Security coordinates supervision with sector authorities. Verify your duties via the source.2026-07-29samsik.dk
EstoniaNational law in forceTransposed by amending the Cybersecurity Act (KüTS), adopted 10 Dec 2025 and in force since 1 Jan 2026. Newly in-scope entities register with the Information System Authority (RIA) within three months of qualifying, with multi-year transition periods for some requirements. Verify via the source.2026-07-29ria.ee
FinlandNational law in forceTransposed via the Cybersecurity Act (124/2025); obligations apply since 8 Apr 2025. Registration with the supervisory authority was due by 8 May 2025, with risk-management arrangements required from 8 Jul 2025; Traficom's National Cyber Security Centre leads a sector-based supervision model. Verify via the source.2026-07-29kyberturvallisuuskeskus.fi
FranceNot yet in forceThe transposition bill (resilience bill) is still before the National Assembly: the Senate adopted it in March 2025, the special commission completed its work in Sept 2025, and no plenary vote has been recorded. On 8 July 2026 the Commission announced its decision to refer France to the Court of Justice of the EU (press release IP/26/1499). Track progress via the source.2026-07-17assemblee-nationale.fr
GermanyNational law in forceNIS2UmsuCG in force since 6 Dec 2025 (BGBl. 2025 I Nr. 301). The BSI registration portal is open and the statutory registration deadline for entities in scope from day one has already expired; verify your registration duty via the source.2026-07-17bsi.bund.de
GreeceNational law in forceTransposed via Law 5160/2024 (Gazette A' 195, 27 Nov 2024), in force since 27 Nov 2024. The National Cybersecurity Authority maintains a registry of in-scope entities, with registration windows set by ministerial decisions and a scope self-test on its site. Verify via the source.2026-07-29cyber.gov.gr
HungaryNational law in forceTransposed via Act LXIX of 2024 on Hungary's cybersecurity, in force since 1 Jan 2025, with implementing decrees including Government Decree 418/2024. Private-sector registration and supervision sit with the SZTFH (the linked source is its supervision hub), and biennial cybersecurity audits are a national feature; at our last check the EU tracker still recorded the Commission's May 2025 reasoned opinion on incomplete notification. Verify via the source.2026-07-29sztfh.hu
IrelandNot yet in forceNot yet transposed: the National Cyber Security Bill is still being drafted, and on 8 July 2026 the Commission announced its decision to refer Ireland to the Court of Justice of the EU over the missed deadline (press release IP/26/1499). The NIS 1 regime remains in effect; verify the current status via the source.2026-07-17ncsc.gov.ie
ItalyNational law in forceTransposed via Legislative Decree 138/2024, in force since 16 Oct 2024. Obligations phase in by cohort: for entities in the ACN's initial lists, incident reporting applies from Jan 2026 and security measures by Oct 2026; entities listed later receive later deadlines. Verify your deadlines with the ACN via the source.2026-07-17acn.gov.it
LatviaNational law in forceTransposed via the National Cybersecurity Law, adopted 20 Jun 2024 and in force since 1 Sep 2024. The National Cybersecurity Centre under the Ministry of Defence is the single point of contact, and in-scope providers self-notify under the law's transitional deadlines. Verify via the source.2026-07-29likumi.lv
LithuaniaNational law in forceTransposed via Law No XIV-2902 restating the Law on Cybersecurity, adopted 11 Jul 2024 and in force since 18 Oct 2024, one of the earliest transpositions in the EU. The National Cyber Security Centre under the Ministry of National Defence is competent authority, single point of contact and CSIRT; entities register via the Cybersecurity Information System. Verify via the source.2026-07-29e-seimas.lrs.lt
LuxembourgNational law in forceTransposed via the Law of 5 May 2026 on a high level of cybersecurity, in force since 10 May 2026. The ILR is the competent authority for most sectors (the CSSF covers the financial sector it supervises); self-registration via the ILR portal was due by 10 Jul 2026, and incident reporting runs through its SERIMA platform. Verify via the source.2026-07-29ilr.lu
MaltaNational law in forceTransposed via Subsidiary Legislation 460.41 (L.N. 71 of 2025), brought into force on 23 Jan 2026 by L.N. 22 of 2026 and amended by L.N. 89 of 2026. Entities notify the Critical Infrastructure Protection Department; the EU tracker page lagged this change at our last check. Verify via the source.2026-07-29legislation.mt
NetherlandsNot yet in forceThe Cyberbeveiligingswet has been adopted by both chambers (Eerste Kamer on 7 Jul 2026) and enters into force on 15 Aug 2026 per the government announcement. Not yet in force at our last check; verify via the source.2026-07-17rijksoverheid.nl
PolandNational law in forceTransposed via the amendment to the National Cybersecurity System Act (Dz.U. 2026 poz. 252), in force since 3 Apr 2026. For entities meeting the criteria at entry into force, registration applications are due by 3 Oct 2026 and the information-security management system (SZBI) by 3 Apr 2027; entities qualifying later have their own deadlines. Verify via the source.2026-07-17gov.pl
PortugalNational law in forceTransposed via Decree-Law 125/2025 of 4 Dec 2025 approving the cybersecurity legal regime (RJC), in force since 3 Apr 2026. The National Cybersecurity Centre (CNCS) is the national authority; existing entities self-identify on its platform under phased deadlines, and certain enumerated obligations defer until up to 24 months after the implementing regulations. Verify via the source.2026-07-29anacom.pt
RomaniaNational law in forceTransposed via Government Emergency Ordinance 155/2024 (Official Gazette No 1332, 31 Dec 2024), in force since 31 Dec 2024 and approved with amendments by Law 124/2025. The National Cybersecurity Directorate (DNSC) supervises; registration ran 30 days from its implementing orders of Aug 2025. Verify via the source.2026-07-29digital-strategy.ec.europa.eu
SlovakiaNational law in forceTransposed via Act No 366/2024 Coll. amending the Cybersecurity Act (Act No 69/2018), in force since 1 Jan 2025. The National Security Authority (NBÚ) supervises; entities in scope on day one had 60 days to register, and transition periods for security measures depend on when and how an entity came into scope, per NBÚ guidance. Verify via the source.2026-07-29digital-strategy.ec.europa.eu
SloveniaNational law in forceTransposed via the Information Security Act (ZInfV-1, Official Gazette No 40/25), in force since 19 Jun 2025. The Government Information Security Office (URSIV) supervises; obliged entities self-register via its web form within 30 days of meeting the criteria. Verify via the source.2026-07-29uradni-list.si
SpainNot yet in forceSpain has not notified full transposition. On 8 July 2026 the Commission announced its decision to refer Spain to the Court of Justice of the EU over the missed deadline (press release IP/26/1499). Verify the current status via the source.2026-07-17digital-strategy.ec.europa.eu
SwedenNational law in forceTransposed via the Cybersecurity Act (SFS 2025:1506), in force since 15 Jan 2026. Entities identify themselves and register via the National Cyber Security Centre's notification service, with supervision by sector authorities; the authority landscape was reorganised in 2026, so re-check current guidance via the source.2026-07-29ncsc.se

This table reports our last-verified read of public sources on the dates shown. It is not a statement of binding legal status: re-check the linked source before relying on any row, and treat the national authority's own page as authoritative where the two ever disagree.

Why transposition status is the variable that matters

Regulations like DORA or the GDPR apply directly across the EU. A directive works differently: Article 41 of NIS 2 required Member States to adopt and publish national transposition measures by 17 October 2024 and to apply them from 18 October 2024. Until your Member State does, a private organisation generally faces no sanction under a national NIS 2 law that does not exist yet (EU law recognises narrow direct-effect exceptions, mainly against public bodies, and pre-existing national or sectoral duties keep applying). But you also cannot register with your NIS 2 authority, and you do not know your exact deadlines, because those live in the national act, not in the directive.

The practical consequences of a country flipping to “in force” are concrete: registration windows open and expire (Germany's and Poland's laws both started statutory registration clocks), phase-in schedules start (Italy sequences obligations by cohort), and the management-body accountability of Article 20, approval and oversight of the risk-management measures with personal liability exposure, becomes enforceable through national law. Waiting for transposition is not the same as having nothing to do: the entities in scope, the Article 21 measures and the Article 23 reporting architecture are already set by the directive as a minimum, so the work you prepare now is the floor of what the national law will demand. NIS 2 is minimum harmonisation (Article 5), so a Member State can go further than the directive, and several have; the national act is always the binding text.

Start with whether NIS 2 catches your organisation at all: our free NIS 2 applicability checker runs the sector, size and activity tests and shows this same per-country transposition data for your Member State. For the directive itself, see the NIS 2 framework page.

The EU-level enforcement timeline

Late transposition is not a paperwork issue: the European Commission has escalated it through every stage of the infringement procedure.

  1. 17 October 2024

    The transposition deadline passes

    Article 41 of Directive (EU) 2022/2555 required Member States to adopt and publish their national transposition measures by 17 October 2024 and to apply them from 18 October 2024. Only a handful of states had a law in force on time; Croatia had transposed as early as February 2024, Italy and Lithuania around the deadline itself.

  2. 28 November 2024

    Letters of formal notice to 23 Member States

    Six weeks after the deadline, the Commission opened infringement proceedings against 23 of the 27 Member States for failing to notify full transposition: Bulgaria, Czechia, Denmark, Germany, Estonia, Ireland, Greece, Spain, France, Cyprus, Latvia, Luxembourg, Hungary, Malta, the Netherlands, Austria, Poland, Portugal, Romania, Slovenia, Slovakia, Finland and Sweden.

  3. 7 May 2025

    Reasoned opinions to 19 Member States

    The second infringement stage. Greece, Malta, Romania and Slovakia were no longer on the list; 19 states received reasoned opinions: Bulgaria, Czechia, Denmark, Germany, Estonia, Ireland, Spain, France, Cyprus, Latvia, Luxembourg, Hungary, the Netherlands, Austria, Poland, Portugal, Slovenia, Finland and Sweden.

  4. 8 July 2026

    Ireland, Spain, France and the Netherlands referred to the CJEU

    In press release IP/26/1499 the Commission announced its decision to refer the four states that had yet to notify full transposition to the Court of Justice of the European Union, with a request that the Court impose financial sanctions consisting of a lump sum and daily penalties until complete transposition is notified. The Netherlands' referral came one day after its parliament finished adopting the Cyberbeveiligingswet, which enters into force on 15 August 2026.

How this tracker is maintained

Every row is verified by a person against the linked source, and the verification date is stored with the row, never bumped without a re-check. We prefer the national cybersecurity authority's own page as the source; where a Member State has no usable authority page, we cite the European Commission's per-country tracker instead. Status is deliberately coarse: two values plus a note, because “adopted but awaiting entry into force”, “in parliamentary committee” and “referred to the Court of Justice” are all states a binary cannot hold and a fifty-state enum cannot keep honest. The nuance lives in the note, in plain language.

One definitional honesty note: our status column reports whether a national transposition law is in force, which is not the same thing as the Commission having accepted the Member State's notification of completetransposition. Hungary, for example, has had a law in force since January 2025 while the Commission's tracker still recorded a reasoned opinion over incomplete notification at our last check. Where the two diverge, the row note says so. Counts on this page use the in-force reading.

The same dataset powers the per-country card inside our NIS 2 applicability checker, so the tool and this page cannot drift apart. Rows are re-verified on a schedule (stale dates are visible by design), and between checks a country can change status: if the row's date looks old for a decision you care about, follow the source link and read the current state yourself.

Frequently asked questions

What was the NIS 2 transposition deadline?

17 October 2024. Article 41 of Directive (EU) 2022/2555 required Member States to adopt and publish their transposition measures by that date and to apply them from 18 October 2024. Most Member States missed it, which is why the Commission has since escalated through letters of formal notice (November 2024), reasoned opinions (May 2025) and, for Ireland, Spain, France and the Netherlands, referral to the Court of Justice (July 2026).

How many EU countries have a NIS 2 law in force?

At our verification of 29 July 2026, 22 of the 27 Member States had a national transposition law adopted and in force. Austria had adopted its law (the NISG 2026) with entry into force set for 1 October 2026, the Netherlands had adopted the Cyberbeveiligingswet with entry into force on 15 August 2026, and Ireland, Spain and France were still legislating. The table on this page is re-verified on a schedule, so check the per-row dates.

My country has not transposed NIS 2 yet. Can I ignore it?

For most private organisations no sanction can bite under a national NIS 2 law that does not exist yet (EU law recognises narrow direct-effect exceptions, mainly against public bodies after a missed deadline), but ignoring the directive is still the wrong read. The scope categories, the Article 21 risk-management measures and the Article 23 reporting architecture are set by the directive as a minimum, so the floor of what your national law will demand is already known, and because NIS 2 is minimum harmonisation a Member State can add to it. Once a law lands, the clocks are short: Germany, Luxembourg, Czechia and Slovakia all gave in-scope entities roughly two to three months to register. Preparing against the directive now is how you avoid scrambling later.

What is the difference between adopted, transposed and in force?

A transposition law can be adopted by parliament but not yet applicable: Austria's NISG 2026 was published in December 2025 but its main obligations apply from 1 October 2026, and the Dutch Cyberbeveiligingswet was adopted on 7 July 2026 but enters into force on 15 August 2026. This tracker's status column therefore turns on in force, not adopted, because obligations only bite from entry into force. The note on each row spells out which stage the country is at.

Which countries were referred to the Court of Justice over NIS 2?

On 8 July 2026 the European Commission decided to refer Ireland, Spain, France and the Netherlands to the Court of Justice of the European Union for failing to notify measures fully transposing NIS 2, and asked the Court to impose financial sanctions (a lump sum plus daily penalties until complete transposition is notified). That is press release IP/26/1499. No other Member State was referred.

Why does this page sometimes differ from the EU's own tracker?

The European Commission's per-country tracker pages are the canonical EU-level source, but at our July 2026 verification several had not been updated since mid-2025 and still showed pre-transposition status for countries whose laws had since entered into force, including Bulgaria, Malta, Slovenia and Sweden. Where that happens we cite the national authority or official gazette instead and say so in the row note. If a row and the EU tracker disagree, follow the national source.

How do I know if NIS 2 applies to my organisation at all?

The directive's sector annexes and size thresholds set the EU baseline for applicability, independent of transposition status; national laws can extend that scope, so check the national act too. Our free NIS 2 applicability checker at /resources/nis-2-applicability-checker runs the sector, size and activity tests and returns a structured assessment, including this same transposition note for your Member State. It is a starting point, not a binding determination: confirm with your competent national authority.

Primary sources

  • Directive (EU) 2022/2555 (NIS 2), including Article 41 setting the 17 October 2024 transposition deadline and Article 20 on management-body accountability. eur-lex.europa.eu (checked 2026-07-29).
  • European Commission, NIS 2 Directive national transposition tracker (the official EU-level status page, with per-country sub-pages). digital-strategy.ec.europa.eu (checked 2026-07-29).
  • European Commission, 28 November 2024: letters of formal notice to 23 Member States for failure to notify full transposition of NIS 2. digital-strategy.ec.europa.eu (checked 2026-07-29).
  • European Commission, 7 May 2025: reasoned opinions to 19 Member States for failure to notify full transposition of NIS 2. digital-strategy.ec.europa.eu (checked 2026-07-29).
  • European Commission press release IP/26/1499, 8 July 2026: referral of Ireland, Spain, France and the Netherlands to the Court of Justice of the EU, with a request for financial sanctions. ec.europa.eu (checked 2026-07-29).

In addition to the sources above, every row of the table carries its own per-country source and verification date.

Written and maintained by the ISMS Copilot team. Our compliance content is produced by certified information security professionals, including a CISM-certified ISO 27001 Lead Implementer who still runs audits. Last reviewed 2026-07-29.

EU legal texts are cited by article number and summarised in original wording; read the official text at the linked source for the binding version. National-law names are given as identifiers with short plain-English descriptions. This is educational content, not legal advice: transposition status can change between our verification dates, and only your competent national authority or counsel can give you a binding answer.

Ready to do compliance work faster?

Built for speed, accuracy, and audit-ready output.