NIS2 compliance in the EU: 2026 guide
What the NIS2 directive requires, where member states really stand in July 2026 and how to measure your readiness today with our free 25-question self-assessment.
What is NIS2?
Directive (EU) 2022/2555, known as NIS2, is the EU cybersecurity law replacing the 2016 NIS directive. It dramatically widens the sectors in scope, tightens risk-management duties, imposes strict incident-reporting deadlines (24-hour early warning, 72-hour notification) and makes company management directly accountable. Member states had until 17 October 2024 to transpose it into national law.
Transposition status across the EU (July 2026)
Implementation is uneven. Roughly 20 member states have national NIS2 laws adopted or in force — including Italy (Legislative Decree 138/2024, in force since October 2024), Germany (NIS2UmsuCG, in force since 6 December 2025) and Romania (Government Emergency Ordinance 155/2024). Others are late: in its July 2026 infringement package, the European Commission referred Ireland, Spain, France and the Netherlands to the EU Court of Justice, asking for financial penalties. Wherever you operate, the directive sets the common baseline — national laws mainly decide who supervises you and how registration works.
Who is in scope?
Essential and important entities across 18 sectors: energy, transport, banking, health, water, digital infrastructure, managed ICT services, public administration, space, postal services, waste, chemicals, food, manufacturing, digital providers and research, among others. General size rule: 50 or more employees or over €10 million annual turnover, plus special cases regardless of size. Non-EU companies offering in-scope services inside the EU can also be caught.
Penalties
The directive sets minimum maximums for fines: up to €10 million or 2 % of worldwide annual turnover for essential entities, and up to €7 million or 1.4 % for important ones, together with personal liability for management bodies.
Where to look: ENISA and your national authority
At EU level,
ENISA (the EU Agency for Cybersecurity) publishes implementation guidance and sector maturity assessments (NIS360). Day-to-day supervision sits with the national authority each member state designates — for example INCIBE/CCN in Spain, BSI in Germany, ANSSI in France, ACN in Italy and DNSC in Romania. Country-specific guides are available through the language selector of this page.
Frequently asked questions
Is NIS2 already enforceable?
It depends on the member state. Around 20 countries have national laws adopted or in force (Italy, Germany and Romania among them), while Ireland, Spain, France and the Netherlands were referred to the EU Court of Justice in July 2026 for failing to transpose. Check the implementing act of the country where you operate.
Does NIS2 apply to non-EU companies?
It can. Entities established outside the EU that offer in-scope services within the EU may fall under the directive and typically must designate an EU representative.
Where should we start?
Measure your current maturity, then close the highest-impact gaps: asset inventory, MFA, tested backups, an incident response plan and supplier control. Our free 25-question self-assessment gives you a 0-100 score and prioritised recommendations in minutes.
Official sources
Updated: July 2026 · Informational content; not legal advice.
Monitor your compliance continuously
Sign up free at OCIRIA Security and track your NIS2 maturity over time with risk alerts.