The baseline obligations that decide whether your security programme is adequate in law. For most organisations in Europe this domain arrives as NIS2, through whichever national statute their member state used to implement it.

What we track

NIS2 and its transpositions

EU. Risk management measures, governance duties and management liability for essential and important entities, as enacted in each member state.

UK Cyber Security and Resilience Bill

UK. The successor regime to the NIS Regulations, including which entities are brought newly into scope and on what timetable.

EU Cyber Solidarity Act

EU. Detection, preparedness and the mechanics of coordinated response across member states.

Cybersecurity Act and certification

EU. The certification framework and its revision, and what a scheme will require of you once your sector adopts one.

Singapore Cybersecurity Act

Singapore. Critical information infrastructure duties, and the amendments extending them to providers and to systems outside the original definition.

ENISA implementation guidance

EU. The technical detail that regulators use when they examine you, which the directive itself does not provide.

Who is in scope

NIS2 sorts organisations into essential and important entities, by sector and by size. Annex I covers the highly critical sectors, among them energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space. Annex II adds postal services, waste management, chemicals, food, manufacturing, digital providers and research.

Size thresholds bring in medium and large enterprises. Several member states have gone wider than the directive. Some capture organisations below the threshold, where they are the sole provider of a service or where a disruption would have significant effects. Your national statute is what decides, and reading the directive alone will give you the wrong answer.

Where the deadlines fall

The directive’s own transposition deadline has passed. What matters to you now is your member state’s commencement date, its registration window, and whether it granted a transition period at all. Germany’s implementation entered force with none. The Dutch Cyberbeveiligingswet took effect on 15 August 2026 with no grace period.

After commencement the recurring dates are registration, incident reporting clocks, and whatever supervisory cycle your sector regulator sets. Our analysts keep those dates in the Radar’s regulatory timeline, per jurisdiction, so your team is not maintaining a spreadsheet of them.

Where organisations get caught

Transposition divergence is the first problem and the largest. A group operating in six member states has six commencement dates, six registration mechanisms and six working definitions of what counts as important. The Commission has issued reasoned opinions to nineteen states over transposition and referred four to the Court of Justice, so the divergence is not settling quickly.

The second is registration. Several regimes require you to identify yourself to the competent authority within a fixed window. The obligation is yours, and the regulator is not required to come looking. Organisations that assume they will be told they are in scope are usually already late.

The third is management liability. NIS2 puts approval of risk management measures on the management body and makes training a duty. That turns a security programme into something a board has to be able to evidence it understood, which is a different artefact from a control matrix.

Questions worth asking now

  • Which member states are we in scope in, and under which national statute in each?
  • Are we an essential or an important entity in each of them, and who decided?
  • Have we registered where registration is required, and can we show when?
  • Which body approved our risk management measures, and is that recorded?
  • What training have the directors had, and when?
  • If a supervisor asked for evidence tomorrow, which document would we hand over first?

Related domains

Incident reporting covers the notification clocks inside this regime. Third-party and supply chain risk covers the supplier duties NIS2 imposes. Cyber-kinetic and OT security covers what happens when those duties reach the plant floor.

All sixteen domains and how the Radar works.