An uneven map
By May 2026, 23 of 27 member states had transposed NIS2 into national law. The remaining group includes Spain with partial transposition, alongside Bulgaria, Poland and Slovenia. The European Commission has referred seven member states to the Court of Justice for failure to transpose.
For an organisation operating in one country, this is trivia. For one operating in six, it is a planning problem with no clean answer, because the obligation landscape is genuinely different depending on where you look and it is changing on a timeline nobody controls.
The three positions you can take, and what each costs
Multinational entities are broadly choosing one of three approaches, and each has a distinct failure mode.
Wait for local law. Defensible and increasingly uncomfortable. The directive's obligations do not appear from nothing when a national law passes - they arrive with implementation deadlines attached, and organisations that started at transposition have consistently found the runway shorter than expected. It also leaves you with nothing to show if an incident happens in the interim in a jurisdiction where the directive's substance is politically live even if the statute is not yet in force.
Comply to the directive baseline everywhere. Operationally simplest and slightly over-inclusive. You implement to the directive's requirements union-wide and accept that some jurisdictions will eventually ask for a little more or a little less. Most large organisations we see are here.
Comply to the strictest national standard everywhere. Safest and most expensive. Sensible for a small number of highly regulated entities and hard to justify otherwise, because the strictest transposition on any given point is not the same country for every point.
Where transpositions actually differ
The directive harmonises more than it is given credit for, and the divergences cluster in a predictable set of places. If you are building a multi-jurisdiction programme, these are the fields to track per country rather than assuming a single answer.
Entity identification and registration mechanics differ substantially - who registers, on what platform, within what window, and whether the supervisor identifies entities or the entity self-identifies. Incident reporting channels and thresholds vary around a common cadence. Supervisory structures differ, with some states concentrating supervision in a national cybersecurity authority and others distributing it to sector regulators. Sanction procedures and the practical implementation of management liability vary meaningfully. And several states have extended scope beyond the directive's minimum, bringing in sectors or size thresholds the directive did not require.
The good news is that the underlying control expectations are broadly consistent. The variation is in the interface with the supervisor, not the substance of what you must do.
Why one evidence base survives the variation
The practical conclusion follows from that last point. If the controls are broadly consistent and the interfaces differ, then the expensive thing to build per jurisdiction is the interface, and the expensive thing to build once is the evidence.
That means resisting the natural organisational pull toward country-level compliance silos. A Polish subsidiary building its own evidence store because Polish law is not yet in force, and a Portuguese subsidiary building another because CNCS has started auditing, produces two incomplete pictures and a group function that cannot answer a question about either.
A single evidence base that records what happened, when, and under whose authority - queryable per entity, per jurisdiction, per supervisor - answers Portugal today and Poland whenever Poland arrives. We made the structurally identical argument about overlapping regimes rather than overlapping jurisdictions in building one evidence layer for dual-regulated financial entities.
- Maintain a per-jurisdiction status sheet covering transposition state, supervisor, registration mechanics, and reporting channel, and review it monthly rather than annually
- Build controls to the directive baseline and treat national variations as configuration on top, not as separate programmes
- Keep evidence centrally with jurisdiction as an attribute, so a supervisor's request can be answered without a data-gathering exercise
- Identify which of your entities would be first to face supervision and use that jurisdiction to pressure-test the group model
- Watch the infringement proceedings, since a referral to the Court of Justice tends to precede rapid national action
- Portugal is currently the most instructive jurisdiction to watch, since registration and supervisory activity are both live - see our Portugal coverage
- Germany's enforcement posture gives the clearest signal on what a mature supervisory relationship looks like - see inside Germany's NIS2 enforcement wave
- The union-level enforcement picture, including the first fines, is tracked in the NIS2 enforcement tracker
If your group evidence currently lives in as many places as you have subsidiaries, consolidating it is less work than it sounds. You can start with one entity and one jurisdiction, or see how multi-entity deployments are structured on the ROOTKey enterprise page.
Recebe insights de ciber-resiliência no teu email
Orientação prática e pronta para auditoria sobre integridade de dados, conformidade e continuidade - à medida que publicamos.





