NIS2 across the EU 🇪🇺

NIS2 by country: transposition status

NIS2 is one EU directive, but it takes effect through each Member State's own law, authority and reporting channel. Here is where all 27 stand and who supervises, with detailed pages for key markets.

22 in force · 5 in progress· Status reviewed: June 2026

National law in force

· 22
Austria

Bundesamt für Cybersicherheit (NISG 2026)

Detailed page →
Belgium

CCB — Centre for Cybersecurity Belgium

Detailed page →
Croatia

ZSIS — Zavod za sigurnost informacijskih sustava

Detailed page →
Czechia

NÚKIB — National Cyber and Information Security Agency

Detailed page →
Denmark

SAMSIK — Styrelsen for Samfundssikkerhed

Detailed page →
Estonia

RIA — Information System Authority

Detailed page →
Finland

Traficom — Kyberturvallisuuskeskus (NCSC-FI)

Detailed page →
Germany

BSI — Bundesamt für Sicherheit in der Informationstechnik

Detailed page →
Greece

National Cybersecurity Authority (NCSA)

Detailed page →
Hungary

SZTFH — Authority for the Supervision of Regulated Activities

Detailed page →
Italy

ACN — Agenzia per la Cybersicurezza Nazionale

Detailed page →
Latvia

CERT.LV / National Cyber Security Centre

Detailed page →
Lithuania

NKSC — National Cyber Security Centre

Detailed page →
Luxembourg

ILR — Institut Luxembourgeois de Régulation

Detailed page →
Malta

CIPD — Critical Infrastructure Protection (CSIRTMalta)

Detailed page →
Netherlands

RDI — Rijksinspectie Digitale Infrastructuur

Detailed page →
Poland

Ministerstwo Cyfryzacji & sector authorities

Detailed page →
Portugal

CNCS — Centro Nacional de Cibersegurança

Detailed page →
Romania

DNSC — Directoratul Național de Securitate Cibernetică

Detailed page →
Slovakia

NBÚ — Národný bezpečnostný úrad

Detailed page →
Slovenia

URSIV — Uprava RS za informacijsko varnost

Detailed page →
Sweden

NCSC — Nationellt cybersäkerhetscenter (FRA)

Detailed page →

Transposition in progress

· 5

National transposition evolves. Always confirm the current status with the authority below and the European Commission's transposition tracker. EU transposition tracker

See NIS2-grade supplier monitoring

A sample supplier report (findings, NIS2 mapping and evidence) in two minutes.

View sample report

NIS2 is being enforced. Can you show your supply chain is under control, every day, not once a year?

The EU's NIS2 Directive (due in national law by 17 October 2024) requires medium and large companies in critical sectors to actively manage the cybersecurity risk in their supply chains. Article 21(2)(d) names supply-chain security measures specifically, and failing to comply can mean fines of up to €10M or 2% of global turnover.

160,000–200,000 companies across the EU are directly obligated

Finance, energy, healthcare, transport, digital infrastructure: NIS2 applies EU-wide, with the same requirements in every Member State. ENISA's Threat Landscape 2026 found that 73% of all recorded events hit entities that are essential or important under NIS2.

An annual assessment alone is unlikely to be enough

NIS2 expects you to show how a supplier looks today, not how it looked at the last review. norppa.io cross-checks each supplier's answers against live scan evidence, so an attestation is backed by what we actually observe.

Under audit, you have to show ongoing monitoring

Competent authorities can ask for concrete evidence of supply-chain risk management, and management is personally accountable. An annual questionnaire is a weak defence; norppa.io generates dated, finding-level evidence automatically, every day, for every supplier.

A fraction of the cost

Continuous monitoring of up to 10 suppliers from €249/month (under €25 per supplier), set against fines of up to €10M or 2% of global turnover.

EU regulation, natively

One EU-native view across NIS2, CRA, DORA and the AI Act

Most platforms retrofit a US framework. norppa.io maps every supplier signal to the EU regime it actually informs, so the same monitoring answers four regulations at once.

NIS2

Every finding mapped to its Article 21(2) duty. In force across the EU today.

CRA

Readiness against the Cyber Resilience Act's essential requirements. Reporting from September 2026.

DORA

A pre-filled ICT third-party Register of Information export for financial entities.

AI Act

AI-in-use and exposed-AI-surface inventory for Article 26 deployer duties.

CRA and AI Act references are indicative readiness signals from external monitoring, not a conformity assessment. Read the CRA guide · AI Act guide