There is no single NIS2 compliance deadline any more. The transposition deadline passed in October 2024, and if your organisation is waiting for one date to work towards, the date that now applies depends on where you operate.

Member states had until 17 October 2024 to transpose NIS2 into national law. Most did not. In July 2026 the European Commission referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the European Union for failing to notify their transposing measures — closing on two years past the deadline.

The result is a compliance landscape with no common clock. Germany’s BSIG entered into force in December 2025 with no transition period, and the BSI registration portal opened on 6 January 2026. Other member states are running their own registration, audit, and reporting timetables across 2026 and 2027. An organisation operating in five EU markets does not have one NIS2 deadline. It has five, and they are not aligned.

What varies, and what does not

What varies by member state

The timetable and the administrative detail: when registration opens and closes, which national authority supervises, what the audit cadence looks like, and how quickly penalties become enforceable.

What is fixed by the directive

The substance does not vary, because it comes from the directive rather than the transposing law. Article 21 requires cybersecurity risk-management measures. Article 23 sets the reporting clock: an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month. Article 20 makes management bodies responsible for approving and overseeing those measures, and requires them to undertake training. Article 34 caps administrative fines at €10 million or two percent of total worldwide annual turnover for essential entities, and €7 million or 1.4 percent for important entities.

An organisation that builds to the directive is ready for whichever national deadline arrives first. An organisation that builds to one country’s checklist is ready for one country.

The obligation that is hardest to retrofit

Registration is administrative. Documentation is a project with a due date. The Article 23 reporting clock is neither, because it is the only obligation that has to work under pressure, on the day, with whoever happens to be available.

Twenty-four hours sounds generous until the first hours of an incident go on establishing what is actually happening. The early warning has to leave while the picture is still forming. The fuller notification at 72 hours has to be consistent with it. Both have to hold up afterwards, in front of a supervisory authority that will ask how each conclusion was reached. That is a capability, not a document — and it is the part organisations most often find they do not have at the moment they need it.

What this means in practice

RAYVN closes that gap by making the record a by-product of the response rather than a task after it. When mobilisation, escalation, and every decision are logged as they happen, the notification is drawn from a live, time-stamped record instead of reconstructed from memory against a running clock — and the same record answers the supervisory questions that follow.

This article summarises NIS2 for general information and reflects our reading of the directive and the national transposing laws as they stand. It is not legal advice and should not be relied on as such. For a definitive view on how these rules apply to your organisation, consult a qualified legal adviser.

Common questions about the NIS2 compliance deadline

When is the NIS2 deadline?

There is no single NIS2 compliance deadline. The EU-wide deadline for member states to transpose the directive into national law was 17 October 2024. Most member states missed it, and several had still not notified their measures by July 2026. The deadline that applies to any given organisation is now set by the national law of each member state it operates in, and those dates differ.

Who does NIS2 apply to?

NIS2 applies to medium and large entities operating in the sectors listed in the directive’s annexes, which cover energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, space, postal services, waste management, chemicals, food, certain manufacturing, digital providers, and research. Entities are classified as either essential or important, which determines the supervisory regime and the maximum penalty.

What are the NIS2 incident reporting timeframes?

Article 23 sets three. An early warning is due within 24 hours of becoming aware of a significant incident. A fuller incident notification is due within 72 hours. A final report is due within one month. These come from the directive and apply regardless of which member state’s transposing law governs the entity.

What happens if an organisation misses its national NIS2 deadline?

Supervisory authorities can impose administrative fines of up to €10 million or two percent of total worldwide annual turnover for essential entities, and up to €7 million or 1.4 percent for important entities. Article 20 also makes members of management bodies accountable for approving and overseeing risk-management measures, so consequences are not limited to the organisation.

  1. Directive (EU) 2022/2555 (NIS2). Articles 20, 21, 23, and 34. https://eur-lex.europa.eu/eli/dir/2022/2555/oj
  2. European Commission. NIS2 Directive policy page, including the July 2026 referral of Ireland, Spain, France, and the Netherlands to the Court of Justice of the European Union. https://digital-strategy.ec.europa.eu/en/policies/nis2-directive
  3. Germany, BSIG (NIS2UmsuCG). In force December 2025; BSI registration portal opened 6 January 2026.

Related articles

Talk to a RAYVN Expert

Don't just test a tool—optimize your strategy. Sit down with a RAYVN expert to verify our features meet your compliance needs and see how easy it is to manage complex incidents in real-time.

Get Started
RAYVN Overview Laptop