NIS2 Scoring
EUEuropean Union · English
a service bySightadel

NIS2 guide

NIS2 transposition status by country

NIS2 only binds organisations through national law. Member States had to apply their laws from 18 October 2024, but many were late. This overview covers all 27 Member States: 13 with a country version of this guide and a law in force, three without a law in force, and 11 further Member States without a country version. It shows the law, the date of entry into force and the competent authority.

Last updated: October 2026 · Legal basis: Directive (EU) 2022/2555 (NIS2); details depend on national law

Why the national law matters

Directive (EU) 2022/2555 sets the common framework. The details that matter in daily practice are set by each Member State: the registration portal and deadline, the authority that receives incident reports, the supervisory authority, the exact fines and any additional sectors or duties. Under Article 41(1), Member States had to adopt and publish their laws by 17 October 2024 and apply them from 18 October 2024. Several missed this deadline by a long way.

For organisations in several countries, the jurisdiction rules of Article 26 decide which national law applies to which legal entity. As a rule, it is the law of the Member State where the entity is established. You will find more on this on the pages about scope and registration.

Countries with a law in force

These 13 Member States have a country version of this guide. They are listed in order of entry into force.

Member StateNational lawIn force sinceCompetent authorityCountry version
LatviaNational Cybersecurity Law (Nacionālās kiberdrošības likums), Latvijas Vēstnesis No. 128A, 4 July 2024; amended with effect from 18 June 20261 September 2024National Cyber Security Centre (NKDC) within the Ministry of Defence; CERT.LV as CSIRT for most entities/lv/
ItalyLegislative Decree No. 138 of 4 September 2024 (Gazzetta Ufficiale No. 230, 1 October 2024)16 October 2024Agenzia per la cybersicurezza nazionale (ACN); CSIRT Italia for reports/it/
BelgiumLaw of 26 April 2024 establishing a framework for the cybersecurity of network and information systems of general interest for public security (Belgian Official Gazette, 17 May 2024)18 October 2024Centre for Cybersecurity Belgium (CCB); sector authorities for finance and digital infrastructure/be-nl/ · /be-fr/
LithuaniaLaw on Cybersecurity No. XII-1428 (Kibernetinio saugumo įstatymas), recast by Law No. XIV-2902 of 11 July 2024; last amended by Law No. XV-1076 of 25 June 202618 October 2024National Cyber Security Centre under the Ministry of National Defence (NKSC)/lt/
DenmarkNIS 2 Act (NIS 2-loven), Act No. 434 of 6 May 2025, with Executive Order No. 620 of 2 June 2025 on competent authorities1 July 2025Danish Agency for Civil Protection (Styrelsen for Samfundssikkerhed, SAMSIK) as coordinator, with sector authorities; Danish Defence Intelligence Service as national CSIRT/dk/
CzechiaAct No. 264/2025 Coll. on Cybersecurity (zákon o kybernetické bezpečnosti), with NÚKIB Decrees No. 334/2025, 408/2025, 409/2025 and 410/20251 November 2025National Cyber and Information Security Agency (NÚKIB); National CERT (CSIRT.CZ) for the lower-obligations regime/cz/
GermanyBSI Act (BSIG) as amended by the NIS2 Implementation and Cybersecurity Strengthening Act6 December 2025Federal Office for Information Security (BSI)/de/
EstoniaCybersecurity Act (Küberturvalisuse seadus) as amended by the act transposing NIS2, RT I, 30.12.2025, 41 January 2026Information System Authority (RIA), with CERT-EE for incident handling/ee/
PolandAct of 23 January 2026 amending the Act on the National Cybersecurity System (Dz.U. 2026 item 252)3 April 2026Sector authorities, mostly ministries; the Minister for Digital Affairs keeps the register; CSIRT NASK, CSIRT GOV and CSIRT MON/pl/
PortugalDecree-Law No. 125/2025 of 4 December 2025, approving the Legal Regime for Cybersecurity (Diário da República No. 234)3 April 2026Centro Nacional de Cibersegurança (CNCS); CERT.PT for reports/pt/
LuxembourgLaw of 5 May 2026 on measures to ensure a high level of cybersecurity (Mémorial A No. 225)10 May 2026Institut Luxembourgeois de Régulation (ILR); CSSF for the financial sector/lu/
NetherlandsCyberbeveiligingswet (Cbw), Staatsblad 2026, 187, with the Cyberbeveiligingsbesluit15 August 2026The responsible minister for each sector; supervision by sector supervisors such as the RDI; NCSC as CSIRT/nl/
AustriaNetwork and Information Systems Security Act 2026 (NISG 2026), BGBl. I No. 94/20251 October 2026Federal Office for Cybersecurity (Bundesamt für Cybersicherheit)/at/

Our country versions explain the national registration portal, deadlines, reporting channel and fines in the language of the country.

Countries without a law in force

Member StateStatusPlanned authorityCountry version
FranceBill on the resilience of critical infrastructure and the strengthening of cybersecurity, adopted by the Senate on 12 March 2025. On 6 October 2026 it was taken off the National Assembly’s agenda, with no new date.ANSSI/fr/ (in preparation)
SpainDraft Law on the Coordination and Governance of Cybersecurity, approved at first reading by the Council of Ministers on 14 January 2025. No law has been adopted; the NIS1 rules of Royal Decree-Law 12/2018 still apply.A new National Cybersecurity Centre/es/ (in preparation)
IrelandOnly the General Scheme of the National Cyber Security Bill 2024, published on 30 August 2024. As of early October 2026 the bill had not been introduced in the Oireachtas; it is on the government’s priority list for autumn 2026. The NIS1 rules continue to apply to operators of essential services.National Cyber Security Centre (NCSC) as lead authority, with sector regulatorsnone

In July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice of the EU for failing to transpose NIS2 and asked for financial penalties. The Netherlands has since adopted its law.

Ireland in detail

Irish organisations cannot yet register under NIS2, and there is no NIS2 reporting duty yet. The NCSC has announced a registration and reporting portal that will be available once the law is in force, and offers an “Am I in Scope?” tool and further information on its NIS2 page. According to the General Scheme, the bill is to follow the directive closely: the reporting stages of Article 23, the risk-management measures of Article 21 and fines of up to €10 million or 2% of worldwide turnover for essential entities and €7 million or 1.4% for important entities, whichever is higher. These are draft provisions and may change.

Until the law arrives, Irish organisations in scope can use the directive as their reference. That is what this EU version of the NIS2 scoring is built on.

Other Member States

We have not yet published a country version for the following 11 Member States. The information comes from official sources where they were available and otherwise from published overviews and law firm reports. Check the national law before relying on it.

Member StateNational lawIn force sinceCompetent authority
CroatiaCybersecurity Act (Zakon o kibernetičkoj sigurnosti), NN 14/2024, with the Cybersecurity Regulation, NN 135/2024. The first NIS2 law in the EU.15 February 2024National Cybersecurity Centre (within SOA), coordinating the sector authorities; CSIRTs: National CERT (CARNET) and SOA-CSIRT
GreeceLaw 5160/2024 (Government Gazette, 27 November 2024)28 November 2024National Cybersecurity Authority, which also hosts the CSIRT
HungaryAct LXIX of 2024 on the cybersecurity of Hungary, with Government Decree 418/2024 (XII. 23.)1 January 2025Supervisory Authority for Regulated Activities (SZTFH); CSIRT: National Cyber Security Center (NKI)
RomaniaEmergency Ordinance No. 155/2024, approved by Law No. 124/20251 January 2025National Cyber Security Directorate (DNSC), also the CSIRT
SlovakiaAct No. 366/2024 Coll., amending Act No. 69/2018 Coll. on Cybersecurity1 January 2025National Security Authority (NBÚ), alongside sector ministries; CSIRT: SK-CERT
FinlandCybersecurity Act (Kyberturvallisuuslaki) 124/20258 April 2025Sector authorities such as Traficom; NCSC-FI at Traficom as single point of contact and CSIRT
CyprusLaw 60(I)/2025, amending the Security of Networks and Information Systems Law 89(I)/202025 April 2025Digital Security Authority (DSA); CSIRT: CSIRT-CY
SloveniaInformation Security Act (ZInfV-1)19 June 2025Government Information Security Office (URSIV); CSIRTs: SI-CERT and SIGOV-CERT
SwedenCybersecurity Act (Cybersäkerhetslag), SFS 2025:150615 January 2026Swedish Civil Defence Agency (MCF, until 31 December 2025 MSB) as coordinator, with sector supervisors; CSIRT: CERT-SE
BulgariaAct amending the Cybersecurity Act (State Gazette, 13 February 2026)13 or 17 February 2026 (unconfirmed: sources conflict)Ministry of e-Government, alongside other authorities; CSIRT: CERT Bulgaria
MaltaMeasures for a High Common Level of Cybersecurity across the European Union (Malta) Order, 2025, L.N. 71 of 2025 (S.L. 460.41)Made on 8 April 2025; provisions take effect by ministerial notice. Full application from 23 January 2026 is reported but unconfirmed.Critical Infrastructure Protection Department (CIPD); MCA for digital infrastructure and postal services; CSIRT: CSIRTMalta

The national transposition measures notified to the Commission are listed on EUR-Lex. Until you have checked your national law, the directive is a reliable guide to the minimum requirements, and this EU version of the guide explains them.

EEA countries and Switzerland

As of October 2026, NIS2 has not been incorporated into the EEA Agreement. Liechtenstein has nevertheless adopted its Cybersecurity Act (Cyber-Sicherheitsgesetz, LGBl. 2025 No. 111), in force since 1 February 2025; until incorporation it treats the directive as national law. Its authority is the Cybersecurity Unit (Stabsstelle Cyber-Sicherheit). Norway’s Digital Security Act, in force since 1 October 2025, transposes NIS1 and takes over only parts of NIS2, mainly the reporting duties. Iceland applies only its NIS1 law, Act No. 78/2019, and plans to amend it once NIS2 becomes EEA law.

Switzerland is not an EU member, so NIS2 does not apply there. Swiss companies that are established or provide services in the EU can still fall under the national NIS2 law of a Member State.

Frequently asked questions

Which national law applies to my organisation?

As a rule, the law of the Member State where your entity is established (Art. 26(1)). Certain digital providers fall under the Member State of their main establishment in the EU, and telecoms providers under each Member State where they provide services.

My country has not adopted its law. What should I do?

Prepare on the basis of the directive. The core duties of Articles 20, 21 and 23 will be part of every national law. Registration and reporting become binding only once the law applies.

How many Member States have transposed NIS2?

As of October 2026, 24 of the 27 Member States have adopted a national law. In Bulgaria the exact date of entry into force and in Malta the date of full application are not confirmed. France, Spain and Ireland have no law in force.

Does NIS2 apply in Ireland yet?

No. Ireland has only published the General Scheme of the National Cyber Security Bill 2024. The NIS1 rules still apply to operators of essential services.