EuroComply
Sign up

NIS2 Transposition Status — All 27 EU Member States

The NIS2 Directive (Article 41 of Directive (EU) 2022/2555) required member states to transpose its provisions into national law by 2024-10-17. This tracker monitors progress across all 27 EU countries, citing the national implementing act where available.

Directive (EU) 2022/2555 — EUR-Lex · Informational only — not legal advice.

12
Fully transposed
15
In progress (past deadline)
27
EU member states tracked

Implementation Status by Country

🇧🇪 BelgiumTransposed

Loi du 26 avril 2024 établissant un cadre pour la cybersécurité des réseaux et des systèmes d'information

Belgium was among the first member states to fully transpose NIS2.

🇭🇷 CroatiaTransposed

Zakon o kibernetičkoj sigurnosti (NN 14/2024)

2024-02-07SOA / HAKOM

Croatia adopted its NIS2 cybersecurity act in February 2024, ahead of the October deadline.

🇨🇿 CzechiaTransposed

Zákon č. 181/2014 Sb. o kybernetické bezpečnosti (amended 2024)

NÚKIB led a comprehensive revision of the existing cybersecurity act to implement NIS2.

🇪🇪 EstoniaTransposed

Küberturvalisuse seadus (Cybersecurity Act amendment 2024)

🇫🇮 FinlandTransposed

Laki kyberturvallisuudesta (Cybersecurity Act 1175/2024)

🇩🇪 GermanyTransposed

NIS-2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG)

Significantly delayed beyond the October 2024 EU deadline due to parliamentary dissolution and federal elections. NIS2UmsuCG introduces personal management liability (§38 BSIG).

🇭🇺 HungaryTransposed

2023. évi XXIII. törvény a kiberbiztonságról

Hungary adopted its NIS2 implementing law in 2023, well ahead of the EU transposition deadline.

🇮🇹 ItalyTransposed

Decreto Legislativo 4 settembre 2024, n. 138

Italy transposed NIS2 on the exact deadline date. Registration obligations for essential/important entities phased in through 2025.

🇱🇻 LatviaTransposed

Informācijas tehnoloģiju drošības likums (amended 2024)

2024-09-01CERT.lv / NIC
🇱🇹 LithuaniaTransposed

Kibernetinio saugumo įstatymas (Cybersecurity Law amendment 2024)

🇸🇰 SlovakiaTransposed

Zákon č. 69/2018 Z. z. o kybernetickej bezpečnosti (amended 2024)

🇸🇪 SwedenTransposed

Lag om cybersäkerhet (Cybersecurity Act, SFS 2024:xxx)

2024-10-01NCSC-SE (MSB)
🇦🇹 AustriaIn progress
Date pendingBMI / CERT.at

NIS2-implementing bill under parliamentary review as of 2025.

🇧🇬 BulgariaIn progress
🇨🇾 CyprusIn progress
Date pendingDCCL / CSIRT-CY
🇩🇰 DenmarkIn progress
🇫🇷 FranceIn progress
Date pendingANSSI

ANSSI published extensive NIS2 guidance and sectoral requirements. Full legislative transposition pending as of mid-2025.

🇬🇷 GreeceIn progress
🇮🇪 IrelandIn progress
Date pendingNCSC Ireland

Ireland's NIS2 implementing legislation in progress through Oireachtas.

🇱🇺 LuxembourgIn progress
Date pendingCIRCL / ILR
🇲🇹 MaltaIn progress
Date pendingMITA / MDIA
🇳🇱 NetherlandsIn progress
Date pendingNCSC-NL (via RDI)

Draft implementing bill (Wet Beveiliging Netwerk- en Informatiesystemen) under parliamentary review.

🇵🇱 PolandIn progress

KSC (national cybersecurity system) amendment bill in parliamentary process as of mid-2025.

🇵🇹 PortugalIn progress
🇷🇴 RomaniaIn progress
🇸🇮 SloveniaIn progress
Date pendingSI-CERT / AKOS
🇪🇸 SpainIn progress
Date pendingINCIBE / CCN-CERT

Ley de Ciberseguridad Nacional still in legislative process as of mid-2025. INCIBE-CERT and CCN-CERT continue in interim supervisory roles.

Penalty Ceilings (Article 34 NIS2)

  • Essential entities: up to €10,000,000 or 2% of total worldwide annual turnover (whichever is higher)
  • Important entities: up to €7,000,000 or 1.4% of total worldwide annual turnover (whichever is higher)

Member states may set higher maximums. Data sourced from official national authority publications. This tracker is informational — verify current national law before relying on it for compliance.

Check your NIS2 obligations

Use the EuroComply NIS2 compliance checker to assess your organisation’s scope and duties.

Check compliance →