NIS2: Transposition Status Across Member States
Table of contents
- Key takeaways
- What NIS2 is
- Who is obligated
- Key obligations
- Risk management
- Incident reporting
- Management responsibility
- State by country
- Spain
- Germany
- France
- Netherlands
- Other countries in transposition
- If your state has not transposed
- How to prepare: a pragmatic roadmap
- Phase 1: Assessment
- Phase 2: Remediation
- Phase 3: Continuous operation
- Compliance framework
- The supply chain: the most complex point
- Conclusion
- Frequently asked questions
- Does NIS2 affect me if Spain has not yet transposed the directive?
- Is a mid-size manufacturing or food company in scope for NIS2?
- What incident reporting deadlines does NIS2 impose?
- Sources
The NIS2 directive entered into force on October 17, 2024, but by mid-2026 only part of the member states have fully transposed it: Germany and the Netherlands closed their law, Spain and France remain in process under pressure from Brussels. Here is what already applies and how to prepare without panic.
The NIS2 directive (Network and Information Security 2, EU Directive 2022/2555) entered force on October 17, 2024. Member states reached that date at stages ranging from a law already in force to a stalled bill. This article covers the state in main countries, what concrete obligations it introduces, and how companies should prepare without panic.
Key takeaways
-
NIS2 expands NIS1’s scope to more sectors and companies, including mid-size firms with more than 50 employees in important sectors.
-
The most demanding obligations are 24/72-hour incident reporting and personal executive liability.
-
The supply chain is the most complex compliance point: NIS2 makes you responsible for your suppliers with system access.
-
A framework like ISO 27001 + NIST CSF covers most technical requirements, but NIS2 goes beyond the annual checkbox.
-
First significant penalties are expected from 2025–2026.
What NIS2 is
NIS2 is the major NIS1 (2016) update:
-
Scope expansion: more sectors, more obligated companies.
-
Categories: Essential Entities (EE) + Important Entities (IE).
-
Obligations: risk management, 24 h/72 h/30-day incident reporting, supply-chain security.
-
Penalties: up to €10 M or 2 % of turnover (EE), €7 M or 1.4 % (IE).
-
Improved cross-border cooperation between member states.
Obligated sectors: energy, transport, banking, health, drinking water, digital infrastructure, ICT management, public administration, space, waste, manufacturing, food, digital providers, research and chemistry.
Who is obligated
The simplified rule:
-
Essential Entity (EE): critical sectors and companies with more than 250 employees or more than €50 M turnover.
-
Important Entity (IE): important sectors and mid-size firms (50–250 employees).
-
Exemption: micro-enterprises (<10 employees, <€2 M) excluded by default.
If your company is in listed sectors and exceeds size thresholds, NIS2 applies. The frequent grey area in consulting is mid-size firms in "important" sectors (manufacturing, food, digital management): they are in.
Key obligations
Risk management
Technical and organisational measures explicitly required by NIS2:
-
Documented security policies.
-
Incident management with active procedures.
-
Business continuity, backup and crisis management.
-
Supply-chain security: evaluate suppliers with system access.
-
Network segmentation and encryption.
-
Access control, MFA and least privilege.
-
Vulnerability disclosure.
-
Cyber hygiene practices (updates, patches).
Incident reporting
Timelines are strict:
-
24 hours: brief early warning to the competent authority.
-
72 hours: initial notification with impact assessment.
-
30 days: detailed final report.
This timeline is more demanding than NIS1: meeting it needs a mature incident response process. The operational implication is direct: without a mature incident response process, compliance is impossible. See blameless incident response as a foundation.
Management responsibility
Executives are personally liable:
-
Obligation to train in cybersecurity.
-
Approve security measures.
-
Legal liability for non-compliance, including possible disqualification.
This makes cybersecurity a board-level topic, not just an IT concern.
State by country
Here is where things stand in mid-2026, almost two years past the transposition deadline. The picture is uneven: some states already have a law in force, others are still stuck in parliament.
Spain
-
Draft Law on Cybersecurity Coordination and Governance approved by the Council of Ministers on January 14, 2025.
-
Still in parliamentary process in mid-2026, without a sufficient majority to move forward.
-
INCIBE and CCN-CERT as competent authorities.
-
Spain is among the EU states with the worst record of pending transpositions, and already received a second formal reasoned opinion from the European Commission[1] in May 2026 for still not transposing.
Germany
-
The implementation act (NIS2UmsuCG) was passed by the Bundestag on November 13, 2025, confirmed by the Bundesrat days later, and entered into force on December 6, 2025, according to the BSI itself[2].
-
No transition period: risk-management, incident-reporting and management-liability obligations applied from day one.
-
The BSI (Bundesamt für Sicherheit in der Informationstechnik) now supervises around 29,500 entities, up from 4,500 before.
France
-
The "Loi Résilience" bill transposing NIS2 remained stalled in mid-2026. The Senate passed it in 2025, but there is no firm date for a final vote in the National Assembly, according to Banque des Territoires[3].
-
ANSSI as competent authority; while the law stays unapproved, roughly 15,000 French entities remain without a definitive legal framework.
Netherlands
-
The Cyberbeveiligingswet was approved by the Tweede Kamer (lower house) on April 15, 2026, according to the Dutch government itself[4], and now awaits its turn in the Eerste Kamer (upper house).
-
NCSC-NL as authority.
Other countries in transposition
-
Italy transposed before the October 2024 deadline: one of the few states that made it on time.
-
Ireland and Poland remain among the countries with an open infringement procedure from the European Commission[5], at varying stages of real progress.
If your state has not transposed
The directive does not directly apply to companies, only to states. If on October 17, 2024 your state had not transposed:
-
The European Commission can start an infringement procedure.
-
Transposition will come sooner or later, sometimes with requirements stricter than the minimum.
-
Preparing before transposition is cheaper than doing so under time pressure with a deadline.
How to prepare: a pragmatic roadmap
Phase 1: Assessment
-
Determine whether NIS2 applies to your organisation (sector + size).
-
Current-state audit against requirements.
-
Identify gaps.
-
Executive buy-in: present to the board.
Phase 2: Remediation
-
Implement missing technical controls.
-
Establish incident response procedures matching NIS2 timelines.
-
Supply-chain audit: evaluate critical suppliers.
-
Personnel training, including executives.
-
Document everything.
Phase 3: Continuous operation
-
Incident response exercises (quarterly tabletop exercises).
-
Periodic audits.
-
Reporting to authorities when applicable.
Compliance framework
ISO 27001 is a solid base but not sufficient on its own:
-
ISO 27001 + 27005: complete ISMS.
-
NIST CSF: pragmatic framework aligned with NIS2.
-
CIS Controls: control prioritisation.
-
ENISA guides: European perspective, more NIS2-specific.
There is no "NIS2 checkbox". It is continuous operational compliance.
The supply chain: the most complex point
NIS2 makes you responsible for your suppliers:
-
Evaluate all suppliers with access to your systems.
-
Include security clauses in contracts.
-
Monitor continuously.
-
Be responsible for incidents caused by a supplier.
For companies with hundreds of suppliers, this is a months-long project. NIS2 also overlaps with DORA in the financial sector and the AI Act for AI systems.
Conclusion
NIS2 is not an annual checkbox: it is operational compliance that requires real changes to how cyber risk is managed. Companies waiting for the national transposition to be published with an imminent deadline will face concentrated costs, friction and urgency. Starting with assessment and gap remediation now is the prudent strategy. The investment is real, but the cost of non-compliance (financial penalty, personal executive liability, reputational damage) is greater.
Spanish version: NIS2: estado de la transposición en los estados miembros.
Sources:
- EUR-Lex: Directive (EU) 2022/2555 (NIS2), official text[6]
- European Commission: NIS2 Directive transposition in EU countries[5]
- BSI: NIS-2-Umsetzungsgesetz enters into force[2]
- Government of the Netherlands: Tweede Kamer approves the Cyberbeveiligingswet[4]
- Banque des Territoires: France’s NIS2 transposition, stalled[3]
- Digitalperito: the EU investigates Spain over non-transposition of NIS2[1]
Frequently asked questions
Does NIS2 affect me if Spain has not yet transposed the directive?
Not directly yet: the directive binds states, not companies. The Spanish draft law was approved by the Council of Ministers on January 14, 2025. It was still in parliamentary process in mid-2026, with a second formal reasoned opinion from the European Commission in May 2026. But transposition will come sooner or later, sometimes with requirements stricter than the minimum, and preparing beforehand is cheaper than doing it under a deadline.
Is a mid-size manufacturing or food company in scope for NIS2?
Yes. Mid-size firms of 50 to 250 employees in important sectors such as manufacturing, food or digital management are in as Important Entities, which is the frequent grey area in consulting. Essential Entities are critical-sector companies with more than 250 employees or over €50 M turnover, and micro-enterprises (under 10 employees and under €2 M) are excluded by default. Penalties reach €7 M or 1.4 % for IE and €10 M or 2 % for EE.
What incident reporting deadlines does NIS2 impose?
Three strict steps: a brief early warning to the competent authority within 24 hours, an initial notification with impact assessment within 72 hours, and a detailed final report within 30 days. The timeline is more demanding than NIS1, and without a mature incident response process compliance is impossible. That is why the roadmap includes establishing those procedures and rehearsing them with quarterly tabletop exercises.