NIS‑2 in Euro­pe: Free Gui­de to Natio­nal Imple­men­ta­ti­on Requirements

The Euro­pean Uni­on’s NIS‑2 Direc­ti­ve estab­lishes a com­mon base­line for cyber­se­cu­ri­ty requi­re­ments across the EU. Howe­ver, unli­ke a direct­ly appli­ca­ble regu­la­ti­on, NIS‑2 must be trans­po­sed into natio­nal law by each Mem­ber Sta­te. As a result, busi­nesses ope­ra­ting in Euro­pe face not one sin­gle cyber­se­cu­ri­ty law, but up to 27 dif­fe­rent natio­nal imple­men­ta­ti­on regimes.

A Prac­ti­cal Gui­de to NIS‑2 Across the EU

To sup­port orga­ni­sa­ti­ons navi­ga­ting this com­plex regu­la­to­ry land­scape, we have pre­pared a com­pre­hen­si­ve gui­de cove­ring all EU Mem­ber Sta­tes. The gui­de includes infor­ma­ti­on on:

  • the cur­rent sta­tus of NIS‑2 implementation,
  • com­pe­tent super­vi­so­ry authorities,
  • regis­tra­ti­on requirements,
  • inci­dent report­ing obli­ga­ti­ons and report­ing por­tals, and
  • key obli­ga­ti­ons under the respec­ti­ve natio­nal NIS‑2 laws.

The gui­de covers the fol­lo­wing Mem­ber Sta­tes: Bel­gi­um, Bul­ga­ria, Croa­tia, Cyprus, Czech Repu­blic, Den­mark, Esto­nia, Fin­land, France, Ger­ma­ny, Greece, Hun­ga­ry, Ire­land, Ita­ly, Lat­via, Lithua­nia, Luxem­bourg, Mal­ta, Net­her­lands, Aus­tria, Pol­and, Por­tu­gal, Roma­nia, Slo­va­kia, Slove­nia, Spain and Sweden.

Why Natio­nal Laws Matter

For com­pa­nies head­quar­te­red out­side the Euro­pean Uni­on, one of the most important aspects of NIS‑2 is that com­pli­ance obli­ga­ti­ons are often deter­mi­ned at natio­nal level. A com­pa­ny may have its glo­bal head­quar­ters in North Ame­ri­ca, Asia or ano­ther regi­on, yet still be sub­ject to NIS-2-related obli­ga­ti­ons if it ope­ra­tes sub­si­dia­ries, bran­ches or other estab­lish­ments within the EU.

In addi­ti­on, cer­tain digi­tal ser­vice pro­vi­ders may fall within the scope of NIS‑2 even wit­hout a phy­si­cal pre­sence in the Euro­pean Uni­on. Simi­lar to other EU digi­tal regu­la­ti­ons, NIS‑2 part­ly fol­lows a market-based approach, mea­ning that orga­ni­sa­ti­ons offe­ring rele­vant ser­vices into the EU mar­ket may beco­me sub­ject to regu­la­to­ry requi­re­ments despi­te being estab­lished out­side the EU.

In prac­ti­ce, the rele­vant obli­ga­ti­ons will gene­ral­ly be gover­ned by the natio­nal imple­men­ta­ti­on law appli­ca­ble to the respec­ti­ve EU enti­ty or loca­ti­on. This means that regis­tra­ti­on requi­re­ments, super­vi­so­ry rela­ti­onships and inci­dent report­ing obli­ga­ti­ons are typi­cal­ly hand­led with the com­pe­tent aut­ho­ri­ty in the rele­vant Mem­ber Sta­te rather than at EU level.

You may also use our free NIS‑2 Quick Check tool to per­form an initi­al assess­ment of poten­ti­al appli­ca­bi­li­ty and rele­van­ce to your busi­ness ope­ra­ti­ons: https://nis2-check.com

    Request the Gui­de now

    Fields mark­ed with * are mandatory.

    Plea­se sel­ect one of the following*

    Bil­ling address

    Legal state­ment

    back

    Stay up-to-date

    We use your email address exclusively for sending our newsletter. You have the right to revoke your consent at any time with effect for the future. For further information, please refer to our privacy policy.