The baseline obligations that decide whether your security programme is adequate in law. For most organisations in Europe this domain arrives as NIS2, through whichever national statute their member state used to implement it.
What we track
NIS2 and its transpositions
EU. Risk management measures, governance duties and management liability for essential and important entities, as enacted in each member state.
UK Cyber Security and Resilience Bill
UK. The successor regime to the NIS Regulations, including which entities are brought newly into scope and on what timetable.
EU Cyber Solidarity Act
EU. Detection, preparedness and the mechanics of coordinated response across member states.
Cybersecurity Act and certification
EU. The certification framework and its revision, and what a scheme will require of you once your sector adopts one.
Singapore Cybersecurity Act
Singapore. Critical information infrastructure duties, and the amendments extending them to providers and to systems outside the original definition.
ENISA implementation guidance
EU. The technical detail that regulators use when they examine you, which the directive itself does not provide.
Who is in scope
NIS2 sorts organisations into essential and important entities, by sector and by size. Annex I covers the highly critical sectors, among them energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space. Annex II adds postal services, waste management, chemicals, food, manufacturing, digital providers and research.
Size thresholds bring in medium and large enterprises. Several member states have gone wider than the directive. Some capture organisations below the threshold, where they are the sole provider of a service or where a disruption would have significant effects. Your national statute is what decides, and reading the directive alone will give you the wrong answer.
Where the deadlines fall
The directive’s own transposition deadline has passed. What matters to you now is your member state’s commencement date, its registration window, and whether it granted a transition period at all. Germany’s implementation entered force with none. The Dutch Cyberbeveiligingswet took effect on 15 August 2026 with no grace period.
After commencement the recurring dates are registration, incident reporting clocks, and whatever supervisory cycle your sector regulator sets. Our analysts keep those dates in the Radar’s regulatory timeline, per jurisdiction, so your team is not maintaining a spreadsheet of them.
Where organisations get caught
Transposition divergence is the first problem and the largest. A group operating in six member states has six commencement dates, six registration mechanisms and six working definitions of what counts as important. The Commission has issued reasoned opinions to nineteen states over transposition and referred four to the Court of Justice, so the divergence is not settling quickly.
The second is registration. Several regimes require you to identify yourself to the competent authority within a fixed window. The obligation is yours, and the regulator is not required to come looking. Organisations that assume they will be told they are in scope are usually already late.
The third is management liability. NIS2 puts approval of risk management measures on the management body and makes training a duty. That turns a security programme into something a board has to be able to evidence it understood, which is a different artefact from a control matrix.
Questions worth asking now
- Which member states are we in scope in, and under which national statute in each?
- Are we an essential or an important entity in each of them, and who decided?
- Have we registered where registration is required, and can we show when?
- Which body approved our risk management measures, and is that recorded?
- What training have the directors had, and when?
- If a supervisor asked for evidence tomorrow, which document would we hand over first?
Related domains
Incident reporting covers the notification clocks inside this regime. Third-party and supply chain risk covers the supplier duties NIS2 imposes. Cyber-kinetic and OT security covers what happens when those duties reach the plant floor.