Skip to main content
Back to overview

NIS2 Implementation Timeline: Where Every EU Member State Stands

By NIS2Certify
NIS2transpositiontimelineEU member statesCourt of Justicecompliance

24 of 27 EU member states have a NIS2 law in force today. Still legislating: 3; adopted but not yet applying: 0. On 8 July 2026 the Commission referred four states, Ireland, Spain, France and the Netherlands, to the Court of Justice of the EU. Status checked on September 28, 2026.

Sources: the national authorities linked per country below, European Commission press release IP/26/1499 and the directive text on EUR-Lex.

Key takeaways

  • The deadline passed long ago. Member states had to transpose NIS2 by 17 October 2024. Most missed it.
  • The Commission escalated in three steps: formal notices on 28 November 2024, reasoned opinions on 7 May 2025, and a referral to the Court of Justice on 8 July 2026.
  • Your obligations follow the national law. Where it is in force, registration and security duties apply now. Where it is not, the old NIS1 rules may still apply to operators designated under them.
  • Working across borders means several regimes. Registration deadlines and supervisors differ per country, even though the directive's baseline is the same.

The EU enforcement timeline

DateWhat happened
17 October 2024Deadline for member states to transpose NIS2 into national law
28 November 2024The Commission sent letters of formal notice to 23 member states that had not notified full transposition
7 May 2025Reasoned opinions to 19 member states, the last step before court
8 July 2026Referral of Ireland, Spain, France and the Netherlands to the Court of Justice, with a request for a lump sum and daily penalties (IP/26/1499)

A referral does not change what companies must do in the meantime. It puts pressure on the member state to finish its law, and the Court can fine the state, not the companies in it.

Where each member state stands

NIS2 transposition by country

  • AustriaIn force
    • In force since October 1, 2026
    • Act: NISG 2026 (BGBl. I Nr. 94/2025)
    • Registration due December 31, 2026

    Authority: Federal Office for Cybersecurity · Source

  • NetherlandsIn force
    • In force since August 15, 2026
    • Act: Cyberbeveiligingswet (Stb. 2026, 187)
    • Registration required, no transition period

    Authority: NCSC (MijnNCSC) · Source

  • LuxembourgIn force
    • In force since May 10, 2026
    • Act: Law of 5 May 2026
    • Registration due July 10, 2026

    Authority: ILR (CSSF for finance) · Source

  • PolandIn force
    • In force since April 3, 2026
    • Act: UKSC (Dz.U. 2026 poz. 252)
    • Registration due October 3, 2026
    • Measures due April 3, 2027

    Authority: Minister Cyfryzacji (Wykaz KSC) · Source

  • PortugalIn force
    • In force since April 3, 2026
    • Act: Decree-Law 125/2025 (RJC)

    Authority: CNCS · Source

  • BulgariaIn force
    • In force since February 13, 2026
    • Act: Cybersecurity Act amendment (State Gazette No 17/2026)

    Authority: Ministry of e-Government · Source

  • MaltaIn force
    • In force since January 23, 2026
    • Act: S.L. 460.41

    Authority: Critical Infrastructure Protection Department · Source

  • SwedenIn force
    • In force since January 15, 2026
    • Act: SFS 2025:1506

    Authority: NCSC-SE · Source

  • EstoniaIn force
    • In force since January 1, 2026
    • Act: Cybersecurity Act (KüTS) amendment
    • Registration within 3 months

    Authority: RIA · Source

  • GermanyIn force
    • In force since December 6, 2025
    • Act: NIS2UmsuCG
    • Registration due March 6, 2026
    • 17,729 registered by June 30, 2026

    Authority: BSI · Source

  • CzechiaIn force
    • In force since November 1, 2025
    • Act: Act No 264/2025 Coll.
    • Registration within 60 days

    Authority: NÚKIB · Source

  • DenmarkIn force
    • In force since July 1, 2025
    • Act: NIS 2 Act No 434 of 6 May 2025
    • Registration due October 1, 2025

    Authority: Danish Agency for Societal Security · Source

  • SloveniaIn force
    • In force since June 19, 2025
    • Act: ZInfV-1 (OG 40/25)
    • Registration within 30 days

    Authority: URSIV · Source

  • CyprusIn force
    • In force since April 25, 2025
    • Act: Law 60(I)/2025

    Authority: Digital Security Authority · Source

  • FinlandIn force
    • In force since April 8, 2025
    • Act: Cybersecurity Act 124/2025
    • Registration due May 8, 2025
    • Measures due July 8, 2025

    Authority: Traficom (NCSC-FI) · Source

  • HungaryIn force
    • In force since January 1, 2025
    • Act: Act LXIX of 2024

    Authority: SZTFH · Source

  • SlovakiaIn force
    • In force since January 1, 2025
    • Act: Act No 366/2024 Coll.
    • Registration within 60 days

    Authority: NBÚ · Source

  • RomaniaIn force
    • In force since December 31, 2024
    • Act: GEO 155/2024 (Law 124/2025)
    • Registration within 30 days

    Authority: DNSC · Source

  • GreeceIn force
    • In force since November 27, 2024
    • Act: Law 5160/2024 (Gazette A' 195)

    Authority: National Cybersecurity Authority · Source

  • BelgiumIn force
    • In force since October 18, 2024
    • Registration due March 18, 2025

    Authority: CCB · Source

  • LithuaniaIn force
    • In force since October 18, 2024
    • Act: Law No XIV-2902

    Authority: NCSC (MoND) · Source

  • ItalyIn force
    • In force since October 16, 2024
    • Act: D.Lgs. 138/2024
    • Baseline measures due by October 2026 (entities listed in 2025)

    Authority: ACN · Source

  • LatviaIn force
    • In force since September 1, 2024
    • Act: National Cybersecurity Law

    Authority: National Cybersecurity Centre · Source

  • CroatiaIn force
    • In force since February 15, 2024
    • Act: Cybersecurity Act (OG 14/2024)

    Authority: NCSC (SOA) · Source

  • FranceNot yet transposed
    • Senate adopted the law on March 12, 2025
    • Regulator published its framework on March 17, 2026
    • Referred to the Court of Justice on July 8, 2026
    • Pre-registration open

    Authority: ANSSI · Source

  • SpainNot yet transposed
    • Draft bill approved on January 14, 2025
    • Referred to the Court of Justice on July 8, 2026
    • The NIS1 regime still applies

    Authority: CCN / INCIBE · Source

  • IrelandNot yet transposed
    • Referred to the Court of Justice on July 8, 2026
    • Bill not yet enacted

    Authority: NCSC Ireland · Source

Status as of September 28, 2026. Other member states: see the country-by-country timeline.

The infographic shows a status only for member states whose row we have re-checked against the national authority. For any country listed there without a status, confirm with its national authority before relying on a date.

Countries in detail

Netherlands: in force since 15 August 2026

The Cyberbeveiligingswet (Cbw) has applied since 15 August 2026. Registration with the NCSC through MijnNCSC is mandatory from that date, with no transition period. The Netherlands was one of the four states referred to the Court of Justice on 8 July 2026, weeks before its law entered into force. More in our guide to the Dutch Cybersecurity Act.

Germany: in force since 6 December 2025

The NIS2 implementation act has been in force since 6 December 2025, supervised by the BSI. Entities had to register by 6 March 2026, three months after entry into force (§ 33 BSIG). Registration is now simply overdue for anyone in scope who has not done it.

Italy: in force since 16 October 2024

Italy's Legislative Decree 138/2024 has applied since 16 October 2024, with the ACN as the national authority. Entities added to the ACN list in 2025 must meet the basic security measures by October 2026, 18 months after ACN notified them of their listing.

Poland: in force since 3 April 2026

Poland amended its National Cybersecurity System Act, in force since 3 April 2026. Entities must register in the list kept by the Minister of Digital Affairs (Wykaz KSC) by 3 October 2026 and implement the security measures by 3 April 2027.

Belgium: in force since 18 October 2024

Belgium's NIS2 law has applied since 18 October 2024, with the Centre for Cybersecurity Belgium (CCB) as the national authority. Most entities had to register by 18 March 2025.

France: still legislating

France has no NIS2 law in force yet. The Senate adopted the transposition bill on 12 March 2025, and the ANSSI published its security framework on 17 March 2026. Pre-registration with the ANSSI is open. France was referred to the Court of Justice on 8 July 2026. What that means for suppliers is in our post on the France and Spain referral.

Spain: still legislating

The Spanish government approved a draft transposition law on 14 January 2025, but it has not been enacted. Until it is, the NIS1 rules still apply, supervised by the CCN and INCIBE. Spain was referred to the Court of Justice on 8 July 2026.

Ireland: still legislating

The National Cyber Security Bill that will transpose NIS2 has not been enacted, so NIS1 still applies to designated operators of essential services. The NCSC is the national authority. Ireland was referred to the Court of Justice on 8 July 2026. More in our Ireland NIS2 guide.

What if you operate in several member states?

Most obligations attach to each member state where you provide services, so a group can face several registration deadlines and supervisors at once. Some digital providers, such as DNS service providers, cloud and data centre providers, and online marketplaces, fall under the member state of their main establishment instead.

The security measures themselves come from Article 21 of the directive and are the same everywhere. Build one programme on the directive, then map each national law's registration and reporting details onto it.

What should you do now?

  1. Check whether NIS2 applies to you. The directive covers 18 sectors and organisations with 50 or more employees, or fewer than 50 with both annual turnover and balance sheet total above €10 million, plus some providers at any size. See What is NIS2?.
  2. List the member states you operate in and check each one's status in the infographic above.
  3. Register where the law is in force and the deadline has passed or is close: Poland's registration deadline is 3 October 2026.
  4. Do not wait where the law is still pending. The directive's measures will not change much in transposition, and customers in countries with a law in force already pass the requirements down their supply chains.

Not sure where you stand? Take the free NIS2 Quick Scan. It maps your current security posture against the ten Article 21 measures in about 10 minutes.

Still have a question?

Answers are generated from our articles and are not legal advice. Do not enter personal or confidential data.