Glossary · Term

National transposition explained

NIS2 is a directive. It binds organisations only through national transposing law, which is why dates, authorities and portals differ per country.

At a glance
Meaning
Turning the NIS2 Directive into national law
Legal basis
Directive (EU) 2022/2555
Transposition deadline
17 October 2024
Applicable since
18 October 2024
Supervision
National cybersecurity authorities
Updated
June 2026
Editorial team
Compliance Compass

What is national transposition?

The National transposition of a directive is the step that turns European rules into binding national law. The NIS2 Directive 2022/2555 sets the objectives; each Member State then passes its own act that makes those objectives enforceable against the organisations on its territory. That is why a directive, unlike a regulation, does not reach you directly. The name of the act differs everywhere; what all of them are is a national transposition law which is why there is no single EU statute to comply with. In Germany, for instance, the transposing act amends the existing BSI Act; other Member States amend or replace their own cybersecurity legislation. The Union-wide core is fixed – scope, risk management measures and the reporting chain – while wording, supervisory structure and the penalty framework are national.

When it applies

The directive has applied since 18 October 2024 under Union law, and Member States had to have their transposing act in place by 17 October 2024. From that point the cybersecurity duties bind the entities in scope – they are no longer a recommendation but a legal duty. The deadline for the Registration duty is fixed in national law and differs from country to country. In several Member States the first deadline has already passed; late registration remains possible and necessary, because an expired deadline does not remove the obligation.

What it requires in practice

Legal context: how the directive and national law fit together

A directive binds the Member States as to the result to be achieved; it does not bind a company directly. Transposition is therefore the step that produces enforceable duties, and most Member States do it by amending their existing cybersecurity law rather than writing an entirely new code. The main reference points at a glance:

Legal sourceWhat it covers
National transposition (national act)The national law itself. It carries all the amendments through which a Member State brings Directive (EU) 2022/2555 into force on its territory.
Amendment of the existing national cybersecurity actThe core of the reform. This is where the new duties on risk management, registration and notification sit, together with the powers of the National cybersecurity authorities as supervisor.
EU directive NIS2 (2022/2555)The European requirement. It does not bind organisations directly; it reaches them through the national transposing act.

What changes in practice

Who supervises it?

Supervision is a national matter. The competent authority is the body designated under National cybersecurity authorities. It supervises, operates the registration and reporting portal and can impose fines for breaches. Article 34 sets minimum ceilings of at least EUR 10 million or 2 % of total worldwide annual turnover for essential entities and at least EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts.

Example: a regional water utility realises it is in scope. It checks its exposure, classifies itself as an essential entity and registers through the national portal; it then documents its risk management, sets up a reporting process for significant incidents and has its management formally approve the measures, so that the core duties of the national act are demonstrable without gaps.

What you actually have to do

Further reading: European Commission – state of NIS2 transposition

Frequently asked questions

What is national transposition?

NIS2 is a directive, and a directive does not apply to organisations directly. Every EU Member State has to transpose it into its own law, and only that national act makes the requirements binding and enforceable for organisations established there. In most Member States the transposing act amends the existing cybersecurity legislation and lays down duties such as risk management, the three-stage reporting obligation and registration with the designated authority for essential and important entities.

Since when does the national transposition apply?

The directive entered into force on 16 January 2023 and has applied since 18 October 2024; Member States had to transpose it by 17 October 2024. Not every Member State met that date, so the moment at which the duties actually bind you depends on the country in which your organisation is established. The European Commission publishes the state of transposition per country, and that is the source to check.

Who supervises the national transposition?

The competent authority designated in the Member State concerned. It carries out supervision, operates the reporting and registration portal and receives the three-stage incident notifications. For breaches, Article 34 sets minimum ceilings of at least EUR 10 million or 2 % of total worldwide annual turnover for essential entities and at least EUR 7 million or 1.4 % for important entities, and Member States may go higher. On top of that, the directive makes management bodies responsible for approving and overseeing the measures.

NIS2 across the EU

National duties at a glance

Registration, reporting chain and management responsibility from your national transposing act – Compliance Compass shows which duty you have to meet and when.