The European Union’s NIS‑2 Directive establishes a common baseline for cybersecurity requirements across the EU. However, unlike a directly applicable regulation, NIS‑2 must be transposed into national law by each Member State. As a result, businesses operating in Europe face not one single cybersecurity law, but up to 27 different national implementation regimes.
A Practical Guide to NIS‑2 Across the EU
To support organisations navigating this complex regulatory landscape, we have prepared a comprehensive guide covering all EU Member States. The guide includes information on:
- the current status of NIS‑2 implementation,
- competent supervisory authorities,
- registration requirements,
- incident reporting obligations and reporting portals, and
- key obligations under the respective national NIS‑2 laws.
The guide covers the following Member States: Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Austria, Poland, Portugal, Romania, Slovakia, Slovenia, Spain and Sweden.
Why National Laws Matter
For companies headquartered outside the European Union, one of the most important aspects of NIS‑2 is that compliance obligations are often determined at national level. A company may have its global headquarters in North America, Asia or another region, yet still be subject to NIS-2-related obligations if it operates subsidiaries, branches or other establishments within the EU.
In addition, certain digital service providers may fall within the scope of NIS‑2 even without a physical presence in the European Union. Similar to other EU digital regulations, NIS‑2 partly follows a market-based approach, meaning that organisations offering relevant services into the EU market may become subject to regulatory requirements despite being established outside the EU.
In practice, the relevant obligations will generally be governed by the national implementation law applicable to the respective EU entity or location. This means that registration requirements, supervisory relationships and incident reporting obligations are typically handled with the competent authority in the relevant Member State rather than at EU level.
You may also use our free NIS‑2 Quick Check tool to perform an initial assessment of potential applicability and relevance to your business operations: https://nis2-check.com