NIS2 in EU Countries

EU city picture

The EU NIS2 directive has to be transposed by EU member states into national law until October 17, 2024. State of completion of NIS2 law differs significantly between EU member states. Some countries have final drafts or enacted law, others have scant public information.

Implementations of NIS2 diverge between member states in many details – sectors and entities are defined differently, obligations are interpreted in multiple ways. Audit obligations will sometimes be fulfilled by operators, sometimes by authorities, sometimes not at all.

EU NIS2 Webinar

EU NIS2 Implementation in EU Member States

Discussion on national NIS2 implementation in: DE, BE, CZ, FI, HR
Webinar ∙ Register on LinkedIn ∙ English ∙ 27. February 2024

National legislation for NIS2 varies a lot throughout EU member states. Some laws and acts are available or already implemented, others are still in draft and non-public. We will add country-specific pages in English as information becomes available.

Implementation in EU member states

Status EU NIS2 in member states, January 2024
Many countries and much information still missing
Country National implementation Country-specific
Austria Public draft published, implementation until October
National implementation through Federal Interior Ministry BMI (Bundesminister für Inneres)
Extensive FAQ pages, initiatives for SMEs
Belgium One draft, consultation finished
Centre for Cybersecurity of Belgium (CCB) has published a draft law, which has been under consultation until December 2024.
Different possibilities for evidences, evidence deadline 18 months
Croatia Final draft published, consultation finished
National implementation by the Office of the National Security Council.
Many obligations also for important entities, no 24/74h reporting obligations, transition period 9 months
Czech Republic Final draft published, consultation finished
National implementation by Národní úřad pro kybernetickou a informační bezpečnost (NÚKIB), national agency for cyber and information security.
Law in two parts, many specific requirements for risk management measure, entities + strategic services
Hungary Commenced since May 2023, additional decrees until October 2024.
Cyber security oversight through Szabályozott Tevékenységek Felügyeleti Hatósága (SZTFH).
Many separate government decrees, deadlines from June 2024, security classes instead of essential und important
Germany Multiple drafts, consultation with businesses ongoing, commencement of law might be delayed
Federal interior ministry responsible for NIS2UmsuCG amending existing law (KRITIS), regulated by Bundesamt für Sicherheit in der Informations­technik, BSI.
More sectors, additional KRITIS operators, some audits, no transition periods
Finland One draft, consultation finished
Ministry of Transport and Communications (LVM) published draft law, consultation until November 2023.
No audit requirements, registration starts January 2025
France One draft, few public information
National implementation through Agence nationale de la sécurité des systemes d'information (ANSSI).
FAQ available on scope and obligations
Italy No draft known, timeline unknown
Regulation through Agenza per la cybersicurezza nazionale (ACN).
Netherlands Draft in progress, consultation Q1/2024
National implementation by Rijksinspectie Digitale Infrastructuur (RDI), probably by extending the existing NIS law.
NIS2 evaluation tool
Poland One draft from April 2024
Amends the existing NCSSA (NIS) law, steered by the Ministry of Digital Affairs currently awaiting comments from many other authorities
ISO 27001 and 22301 standards mentioned, audit obligations, complex regulation structure, many sector-specific government bodies involved in supervision
Sweden Draft expected February 2024
National implementation through Swedish Post and Telecom Authority (PTS).

up

National differences

There are differences between countries in implementing NIS2 as well as differences to the EU directive itself. Some examples for country-specific differences as follows.

Sectors

EU NIS2 defines economic sectors in Annex I and II that are implemented differently in national implementations. Some countries define additional sectors likes Croatia and Czech Republic.

Unterschiede NIS2-Sektoren je Mitgliedsstaat
eigene Zusammenstellung, Stand Januar 2024
Sector Differences
Germany IT and Telco Includes Digital Infrastructure and ICT Service Management (and more)
Public Administration Only parts of the federal government
Subsector Gasversorgung Combines Gas and Hydrogen
KRITIS sectors Additional sector definitions
Finland Annex II Sectors sometimes without names
Banking, Financial market infrastructure Definition missing
Croatia Education
Sustav Obrazovanja
Additional sector
Czech Republic Military industry
Vojenský Průmysl
Additional sector
Water administration
Vodní Hospodářství
Combines Water and Waster water
Financial market
Finanční Trh
Combines Banking and Financial market infrastructures
Digital infrastructure and services
Digitální Infrastruktura a Služby
Combines Digital infrastruktur and ICT service management
Hungary Public transportation
Tömegközlekedés
Additional sector
Banking, Financial market infrastructures, Public administration Definition missing
Water service
Víziközmű szolgáltatás
Combines Water and Waste water
Digital infrastructure
Digitális infrastruktúra
Implements partially Digital infrastructure
Communication services
Hírközlési szolgáltatás
Implements partially Digital infrastructure
Production of cement, lime, plaster
Cement-, mész-, gipszgyártás
Additional sector
Poland Energy
Energia
Additional subsectors Oil and Fuel, Supplies and Services for the Energy Sector, Supervised and subordinate units as well as wider scope of entities in the Mineral extraction subsector.
Banking and financial market infrastructure Bankowość i infrastruktura rynków finansowych Sectors combined
Public administration
Administracja publiczna
Wide scope of government bodies
Production, manufacture and distribution of chemicals
Produkcja, wytwarzanie i dystrybucja chemikaliów
Moved to Annex I
Food production, processing and distribution
Produkcja, przetwarzanie i dystrybucja żywności
Moved to Annex I
Production
Produkcja
Moved to Annex I

Obligations

National NIS2 implementations contain very similar definitions of NIS2 obligations for entities. The following table lists important articles and paragraphs from the national laws (drafts).

Examples of essential NIS2 obligations in EU member states
own compilation, January 2024
Scope Measures Reporting Registration Audits
Belgium § 3 § 30 § 34 §§ 13, 14 §§ 39, 41
Croatia §§ 9, 10 § 30
§ 37 §§ 20, 23 § 34
Czech Republic §§ 3, 4 part 1 § 15 part 1,
part 2
§§ 16, 17 part 1,
§ 3
§ 8 part 1 § 17 part 2
for essential
Finland § 3 § 9 § 11 §§ 43, 165 -
Germany § 28 § 30 § 31 §§ 32, 33 § 34
Hungary § 17 §§ 19, 20
+ more
§ 27 § 26
+ edict
§§ 23, 26 (3)
Poland §§ 4, 5 §§ 8, 9, 10 §§ 11, 12, 13 § 7 §§ 15, 16

up

Further Information

Literature

  1. NISD 2 Tracker, Bird & Bird LLP, 24.11.2023
  2. NIS 2 Directive Transposition, Cyber Risk GmbH, 24.11.2023