Every law firm with a cybersecurity practice publishes a NIS2 transposition tracker, and no two agree, because each is a person's reading of 27 parliaments' output. There is one list that is not a reading: the register of national measures the member states themselves have communicated to the Commission under Article 41 of Directive (EU) 2022/2555, which EUR-Lex shows under the Directive's "national transposition" tab and the Publications Office holds as data. It is the list the Commission's infringement decisions are checked against. This article is that register, read on 12 September 2026, with the full list of every communicated measure, per state, on its own page, and the two conclusions the register supports that the trackers tend to blur.

What the register is

Article 41(1) told the member states to "adopt and publish the measures necessary to comply with this Directive" by 17 October 2024, to "immediately inform the Commission thereof", and to apply those measures from 18 October 2024. Each measure a state communicates becomes one record: the title the state gave it, in its own language; the type of act; its date; the date it was communicated; and, where the state supplied them, the entry into force and the national journal. The Publications Office's CELLAR store links each record to the Directive, which is how a machine can read the whole set at once and how the page and the dataset behind this article are regenerated rather than retyped.

Two properties of the register matter more than any row in it. It holds only what was communicated: a state whose parliament passed a law last month and has not yet notified it shows nothing, and a state that communicated its 2018 framework for network and information security as partial transposition shows that framework, however much a later act supersedes it. And it does not say which of a state's measures is "the NIS2 law". The table below names one per state, chosen by a stated rule: the communicated measure of highest rank whose title names the Directive, cybersecurity or network and information security, the newest where there are several. That is our reading, and the page marks it as such.

What it shows on 12 September 2026

25 of the 27 member states have communicated at least one measure, 303 measures between them. 24 have communicated an act that names the Directive or cybersecurity in its title. Spain and Ireland have communicated nothing. France has communicated 15 texts, every one of them dated between 2005 and 2023: the 2018 law, decree and order that transposed the first NIS Directive, articles of the defence code, and interministerial instructions on the security of state information systems, and no act naming NIS2.

The dates tell the rest. Six of the 24 principal acts are dated on or before the 17 October 2024 deadline: Croatia's, the earliest, from February 2024; Belgium's law of April 2024, in force from 18 October 2024, the day the Directive applied from; Latvia's, Lithuania's and Italy's in the summer and autumn of 2024; and Slovakia's, which is the 2018 act as amended, in force 1 January 2025. The other 18 are dated after the deadline, and six of them entered into force in 2026: Estonia and Sweden in January, Bulgaria in February, Poland in April, Luxembourg in May, and the Netherlands, whose Cyberbeveiligingswet of 8 July 2026 applies from 15 August 2026 and is the newest act on the register.

The measure counts say something about how states notify rather than about how much law they have. Czechia's 83 records include acts communicated as far back as 2004 and later linked to the Directive; Hungary's 39 and Estonia's 28 are the same pattern of notifying the surrounding statute book; Germany's 20 are mostly the Länder's own implementation rules for their administrations, communicated one by one, beside the federal act of December 2025. Bulgaria, Cyprus, Italy, Luxembourg, Malta and Slovenia communicated one act each.

The register, one line per state

Member state The NIS2 law, as communicated Dated In force Measures
Austria Bundesgesetz, mit dem das Bundesgesetz zur Gewährleistung eines hohen Cybersicherheitsniveaus von Netz- und Informationssystemen (Netz- und Informationssystemsicherheitsgesetz 2026 – NISG 2026) erlassen wird und das Telekommunikationsgesetz 2021 und das Gesundheitstelematikgesetz 2012 geändert werden 23 December 2025 8
Belgium Loi du 26 avril 2024 établissant un cadre pour la cybersécurité des réseaux et des systèmes d'information d’intérêt général pour la sécurité publique (loi NIS2) 17 May 2024 18 October 2024 2
Bulgaria Закон за изменение и допълнение на Закона за киберсигурност 13 February 2026 17 February 2026 1
Croatia Zakon o kibernetičkoj sigurnosti 7 February 2024 2
Cyprus Ο Περί Ασφάλειας Δικτύων και Συστημάτων Πληροφοριών (Τροποποιητικός) Νόμος του 2025. 25 April 2025 25 April 2025 1
Czechia Zákon č. 264/2025 Sb., o kybernetické bezpečnosti 11 June 2025 83
Denmark Lov om foranstaltninger til sikring af et højt cybersikkerhedsniveau (NIS 2-loven) 6 May 2025 1 July 2025 10
Estonia Küberturvalisuse seaduse ja teiste seaduste muutmise seadus (küberturvalisuse 2. direktiivi ülevõtmine) 30 December 2025 1 January 2026 28
Finland Kyberturvallisuuslaki / Cybersäkerhetslag (124/2025) 4.4.2025, viimeksi muutettuna / ändrad senast genom (369/2025) 27.6.2025 9 July 2025 13
France no act naming the Directive among the communicated measures 15
Germany Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung 5 December 2025 6 December 2025 20
Greece Ενσωμάτωση της Οδηγίας (ΕΕ) 2022/2555 του Ευ- ρωπαϊκού Κοινοβουλίου και του Συμβουλίου, της 14ης Δεκεμβρίου 2022, σχετικά με μέτρα για υψη- λό κοινό επίπεδο κυβερνοασφάλειας σε ολόκλη- ρη την Ένωση, την τροποποίηση του Κανονισμού (ΕΕ) 910/2014 και της Οδηγίας (ΕΕ) 2018/1972, και την κατάργηση της Οδηγίας (ΕΕ) 2016/1148 (Οδη- γία NIS 2) και άλλες διατάξεις. 27 November 2024 27 November 2024 3
Hungary 2024. évi LXIX. törvény Magyarország kiberbiztonságáról 27 January 2025 39
Ireland nothing communicated 0
Italy Decreto legislativo 4 settembre 2024, n. 138, di recepimento nell’ordinamento italiano della direttiva 2022/2555. Notifica provvediemento di attuazione. 11 October 2024 1
Latvia Nacionālās kiberdrošības likums 4 July 2024 1 September 2024 2
Lithuania Lietuvos Respublikos kibernetinio saugumo įstatymo Nr. XII-1428 pakeitimo įstatymas Nr. XIV-2902 24 July 2024 18 October 2024 22
Luxembourg Loi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité et portant modification de : 1° la loi modifiée du 14 août 2000 relative au commerce électronique ; 2° la loi modifiée du 23 juillet 2016 portant création d’un Haut-Commissariat à la Protection nationale ; 3° la loi du 17 décembre 2021 sur les réseaux et les services de communications électroniques. 6 May 2026 10 May 2026 1
Malta Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order, 2025 8 April 2025 8 April 2025 1
Netherlands Wet van 8 juli 2026, houdende regels terimplementatie van Richtlijn (EU) 2022/2555 vanhet Europees Parlement en de Raad van14 december 2022 betreffende maatregelenvoor een hoog gezamenlijk niveau vancyberbeveiliging in de Unie, tot wijziging vanVerordening (EU) nr. 910/2014 en Richtlijn (EU)2018/1972 en tot intrekking van Richtlijn (EU)2016/1148 (PbEU 2022, L 333)(Cyberbeveiligingswet) 10 July 2026 15 August 2026 3
Poland Ustawa z dnia 23 stycznia 2026 roku o zmianie ustawy o krajowym systemie cyberbezpieczeństwa oraz niektórych innych ustaw 2 March 2026 3 April 2026 7
Portugal Decreto-Lei n.º 125/2025, de 4 de dezembro, Diário da República n.º 234/2025, Série I de 2025-12-04, Transpõe a Diretiva (UE) 2022/2555, relativa a medidas destinadas a garantir um elevado nível comum de cibersegurança na União 4 December 2025 2
Romania Ordonanță de urgență privind instituirea unui cadru pentru securitatea cibernetică a rețelelor și sistemelor informatice din spațiul cibernetic național civil 31 December 2024 31 December 2024 16
Slovakia Zákon č. 69/2018 Z. z. o kybernetickej bezpečnosti a o zmene a doplnení niektorých zákonov v znení neskorších predpisov a ktorým sa menia a dopĺňajú niektoré zákony (consolidated version as amended by zákon č. 366/2024 Z. z., ktorým sa mení a dopĺňa zákon č. 69/2018 Z. z. o kybernetickej bezpečnosti a o zmene a doplnení niektorých zákonov v znení neskorších predpisov a ktorým sa menia a dopĺňajú niektoré zákony) 9 March 2018 1 January 2025 9
Slovenia Zakon o informacijski varnosti (ZInfV-1) 4 June 2025 19 June 2025 1
Spain nothing communicated 0
Sweden Cybersäkerhetslag (2025:1506) 17 December 2025 15 January 2026 13

The full list behind each line, with types, dates, journals and national links, is on the transposition page, and the same records are in the datasets StandardOS publishes from primary sources.

What a software company does with it

Which of these laws reaches you is decided by Article 26, not by where your customers are. An essential or important entity is under the jurisdiction of the member state where it is established. For the digital providers of Article 26(1)(b), among them cloud computing services, data centres, managed service and managed security service providers, online marketplaces, search engines and social networks, jurisdiction goes to the member state of the main establishment in the Union, defined in Article 26(2) as the state "where the decisions related to the cybersecurity risk-management measures are predominantly taken". One state's law, one supervisor, one registration, whatever the spread of your users. The same providers had to submit their name, sector, addresses, contact details, member states served and IP ranges to the competent authority by 17 January 2025 under Article 27(2), for ENISA's registry. Whether the Directive reaches your company, as essential or important, and under which state's law, is answered in writing here.

The parts that differ by state are the parts a national act sets: who supervises, where and when you register, how the fines are set within the Directive's ceilings, and the form and channel of the incident notification. The parts that are the same everywhere are the Directive's own: the Article 21 measures, section by section against ISO 27001; the Article 23 clocks, which run beside the CRA's for a company that ships a product as well as a service; and, for cloud and other digital providers, the incident thresholds of Implementing Regulation (EU) 2024/2690, which applies directly and needs no transposition at all. A company in one of the two states with nothing on the register is not outside the Directive: the Regulation applies to it today, and the question of whether NIS2 or the CRA is its law has the same answer as everywhere else.

Sources

  • Directive (EU) 2022/2555 (NIS2), Article 26(1) and (2), Article 27(1) and (2), Article 41(1).
  • The national implementing measures linked to CELEX 32022L2555 in CELLAR, the Publications Office's store behind EUR-Lex, read over SPARQL on 12 September 2026; titles, types and dates as communicated.
  • Commission Implementing Regulation (EU) 2024/2690, Article 1.

This is not legal advice. The register records what the member states have communicated; whether a state has transposed the Directive correctly or completely is a question for the Commission and, in the end, the Court, and this article does not answer it.