- Meaning
- Turning the NIS2 Directive into national law
- Legal basis
- Directive (EU) 2022/2555
- Transposition deadline
- 17 October 2024
- Applicable since
- 18 October 2024
- Supervision
- National cybersecurity authorities
- Updated
- June 2026
- Editorial team
- Compliance Compass
What is national transposition?
The National transposition of a directive is the step that turns European rules into binding national law. The NIS2 Directive 2022/2555 sets the objectives; each Member State then passes its own act that makes those objectives enforceable against the organisations on its territory. That is why a directive, unlike a regulation, does not reach you directly. The name of the act differs everywhere; what all of them are is a national transposition law which is why there is no single EU statute to comply with. In Germany, for instance, the transposing act amends the existing BSI Act; other Member States amend or replace their own cybersecurity legislation. The Union-wide core is fixed – scope, risk management measures and the reporting chain – while wording, supervisory structure and the penalty framework are national.
When it applies
The directive has applied since 18 October 2024 under Union law, and Member States had to have their transposing act in place by 17 October 2024. From that point the cybersecurity duties bind the entities in scope – they are no longer a recommendation but a legal duty. The deadline for the Registration duty is fixed in national law and differs from country to country. In several Member States the first deadline has already passed; late registration remains possible and necessary, because an expired deadline does not remove the obligation.
What it requires in practice
- Registration duty through the national portal, including self-classification as an essential or an important entity.
- Risk management and appropriate technical and organisational measures reflecting the state of the art.
- Compliance with the three-stage reporting obligations for significant incidents: a 24-hour early warning, a 72-hour notification and a final report after one month.
- Responsibility, approval and oversight of the measures by the management body plus regular training.
Legal context: how the directive and national law fit together
A directive binds the Member States as to the result to be achieved; it does not bind a company directly. Transposition is therefore the step that produces enforceable duties, and most Member States do it by amending their existing cybersecurity law rather than writing an entirely new code. The main reference points at a glance:
| Legal source | What it covers |
|---|---|
| National transposition (national act) | The national law itself. It carries all the amendments through which a Member State brings Directive (EU) 2022/2555 into force on its territory. |
| Amendment of the existing national cybersecurity act | The core of the reform. This is where the new duties on risk management, registration and notification sit, together with the powers of the National cybersecurity authorities as supervisor. |
| EU directive NIS2 (2022/2555) | The European requirement. It does not bind organisations directly; it reaches them through the national transposing act. |
What changes in practice
- The circle of regulated entities grows far beyond the classic operators of critical infrastructure – many medium-sized organisations across 18 sectors are now covered.
- State of the art stops being voluntary and becomes an enforceable duty: an organisation that omits measures risks fines.
- The reporting chain is put on a binding timetable: a 24-hour early warning, a 72-hour notification and a final report after one month.
- The management body becomes personally liable for the first time for approving and overseeing the cybersecurity measures.
Who supervises it?
Supervision is a national matter. The competent authority is the body designated under National cybersecurity authorities. It supervises, operates the registration and reporting portal and can impose fines for breaches. Article 34 sets minimum ceilings of at least EUR 10 million or 2 % of total worldwide annual turnover for essential entities and at least EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts.
Example: a regional water utility realises it is in scope. It checks its exposure, classifies itself as an essential entity and registers through the national portal; it then documents its risk management, sets up a reporting process for significant incidents and has its management formally approve the measures, so that the core duties of the national act are demonstrable without gaps.
What you actually have to do
- Check your exposure: does your organisation fall under the national transposing act by sector and by size?
- Register through the national portal – also after the event, because an expired first deadline removes the deadline, not the duty.
- Document risk management and technical measures that reflect the state of the art.
- Set up and test a reporting process for the 24-hour and 72-hour deadlines.
- Train the management body and record the approval of the measures in writing.
Further reading: European Commission – state of NIS2 transposition
Frequently asked questions
What is national transposition?
NIS2 is a directive, and a directive does not apply to organisations directly. Every EU Member State has to transpose it into its own law, and only that national act makes the requirements binding and enforceable for organisations established there. In most Member States the transposing act amends the existing cybersecurity legislation and lays down duties such as risk management, the three-stage reporting obligation and registration with the designated authority for essential and important entities.
Since when does the national transposition apply?
The directive entered into force on 16 January 2023 and has applied since 18 October 2024; Member States had to transpose it by 17 October 2024. Not every Member State met that date, so the moment at which the duties actually bind you depends on the country in which your organisation is established. The European Commission publishes the state of transposition per country, and that is the source to check.
Who supervises the national transposition?
The competent authority designated in the Member State concerned. It carries out supervision, operates the reporting and registration portal and receives the three-stage incident notifications. For breaches, Article 34 sets minimum ceilings of at least EUR 10 million or 2 % of total worldwide annual turnover for essential entities and at least EUR 7 million or 1.4 % for important entities, and Member States may go higher. On top of that, the directive makes management bodies responsible for approving and overseeing the measures.