Get Demo
↑

NIS2 Transposition Status by Country (2026 Tracker)

Qualitative 2026 view of NIS2 Member State transposition themes — confirm national law; this is not an official gazette status board.

Published: September 2026 Compliance · NIS2 8–12 min read

Member States were required to transpose Directive (EU) 2022/2555 into national law. By 2026, most jurisdictions have moved past the original deadline — but supervisory practices, registers, and secondary rules still differ. Use this page as a qualitative orientation, then confirm national law with counsel and your competent authority.

Related: NIS2 hub · Scope · Fines.

Verification note: This tracker avoids definitive country-by-country “official” statuses and gazette-style citations. Themes below are editorial summaries of commonly discussed 2026 patterns — always verify against national legislation and authority guidance.

Major Member State Themes (2026, qualitative)

What to Verify Locally

  1. National transposition act and any amending instruments
  2. Competent authority / CSIRT contacts and reporting portals
  3. Entity registration or notification duties
  4. Sector-specific guidance and implementing measures for digital providers

Update Cadence

Revisit this tracker when your footprint changes (new MS subsidiary, new MSP contract, merger). Treat ENISA and national authority publications as primary sources over vendor blogs — including this one.

How CyberSilo Helps

Build Controls That Survive National Variation

Map Article 21/23 once, then overlay Member State reporting portals and registers.

Frequently Asked Questions

Is this an official EU transposition scoreboard?

No. It is a qualitative 2026 editorial framing. Confirm national law and authority guidance for each Member State where you operate.

Did every Member State transpose on time?

Transposition pace varied; by 2026 most states have frameworks in force or substantially advanced, but details differ — verify locally.

Where should multi-country groups start?

Identify lead competent authorities per entity, align on Article 21 evidence once, and localise Article 23 reporting contacts.

NIS2 hub · Non-EU companies · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!