Belgium is currently the clearest example of operational NIS2 implementation, having moved essential entities into a formal compliance assurance process ahead of most other Member States. Croatia, Hungary and Italy have each built distinctive elements of the wider framework, while Ireland, Spain, France and the Netherlands are still finalising their own transposition.

That picture is more complicated than it looks.

Comparing national progress on NIS2 sounds straightforward. Count the countries that have passed legislation, identify those that missed the deadline and produce a league table. Unfortunately, that only tells part of the story.

There are at least three different stages to consider:

  1. Has the directive been transposed into national law?
  2. Have registration, guidance, supervision and reporting processes become operational?
  3. Are utilities actually implementing, testing and evidencing the required controls?

A country can pass legislation early but still have organisations at the beginning of their implementation journey. Equally, a country with a mature cybersecurity environment may transpose the directive late.

NIS2 transposition: the formal position in July 2026

EU Member States were required to complete NIS2 transposition by 17 October 2024.

By July 2026, most had done so. However, on 8 July 2026, the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify full transposition.

The Commission also requested financial sanctions, including lump sum and daily penalties until full transposition is notified.

This means the legislative picture is much further advanced than it was during 2024 and 2025, but it is still not completely uniform.

NIS2 Europe

Belgium: probably the clearest operational leader

Belgium transposed NIS2 through its law of 26 April 2024.

More importantly, it created a practical implementation route through the Centre for Cybersecurity Belgium, including an entity registration portal, incident reporting, guidance and its CyberFundamentals framework.

Belgian essential entities were required by 18 April 2026 to demonstrate that cybersecurity risk management measures were being implemented and that they were following a recognised compliance assurance route.

The authorities also requested supporting evidence as part of supervision conducted in advance. That is a significant milestone.

It moves NIS2 beyond self-declaration and into evidence, assurance and supervisory verification. For that reason, Belgium is one of the strongest examples of operational implementation rather than legislative transposition alone.

Croatia: early legislation and a national crisis framework

Croatia adopted its Cybersecurity Act in February 2024, making it one of the earlier member states to transpose NIS2. The law established processes for identifying key and important entities, cybersecurity requirements, supervision, national incident arrangements and crisis management.

Croatia subsequently adopted an implementing regulation and, in January 2025, approved a national cyber crisis management programme establishing responsibilities, coordination mechanisms, preparedness measures and procedures for incidents on a large scale.

This combination of legislation, implementation rules and crisis arrangements places Croatia among the more structured adopters.

Hungary: implementation through audit and formal responsibility

Hungary has established a detailed framework around cybersecurity responsibility, regulatory registration, audits, supervision and recognised cybersecurity roles. The supporting regulations cover areas including authorised auditors, cybersecurity audit procedures, supervisory fees, inspections and vulnerability assessment providers.

This illustrates a more prescriptive approach in which organisations must not only introduce controls but prepare for formal assessment. For utilities and their suppliers, that increases the importance of retaining reliable technical and procedural evidence.

Italy: a staged route into operational obligations

Italy transposed NIS2 through Legislative Decree No. 138 of 4 September 2024 and centralised national NIS responsibility under the National Cybersecurity Agency, supported by sector authorities.

Its implementation has followed a staged timetable covering entity registration and identification, appointment of responsible representatives, incident notification and the later application of governance and security measures.

Incident notification obligations began in 2026, with broader security and management requirements being phased in later that year.

Italy is therefore a useful example of a country that has created a structured transition rather than expecting every requirement to become operational on the same day.

But legislation is not the same as utility maturity

It would be misleading to conclude that every Belgian utility is ahead of every Finnish or German utility simply because Belgium passed and operationalised its law earlier.

Large electricity groups have often been subject to cybersecurity requirements for years. They may already operate mature security management systems, specialist response teams, threat intelligence functions and IT and OT security programmes.

E.ON, for example, describes cybe

These examples do not prove complete NIS2 compliance, but they demonstrate that operational maturity can predate national transposition.

But legislation is not the same as utility maturity

Rather than asking which country has “won” the NIS2 race, utilities and their suppliers should ask:

  • Has the organisation confirmed its scope and competent authority?
  • Has it registered where required?
  • Are management responsibilities clear?
  • Have technical and organisational gaps been assessed?
  • Can the controls be tested?
  • Can the organisation produce evidence?
  • Can it meet the incident reporting timeline?
  • Are suppliers and connectivity partners included?

That is the point at which NIS2 becomes real. Europe is getting closer to a common legislative baseline.

Operationally, however, it remains a market of different deadlines, different supervisory approaches and widely different levels of utility maturity.

Frequently Asked Questions (FAQs)

Belgium, Croatia, Hungary and Italy were among the earliest to transpose NIS2 into national law and to build practical implementation routes such as registration portals and compliance assurance processes. Belgium has gone furthest, moving essential entities into a formal compliance assurance process.

No. As of July 2026, most member states had transposed the directive, but the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice on 8 July 2026 for failing to notify full transposition, with financial sanctions requested.

Not necessarily. A country can pass legislation early while its organisations are still at the beginning of implementation, and a country with a mature cybersecurity environment may transpose the directive late. Large utility groups such as E.ON and Enel already run mature security programmes that predate their country’s national deadline.