NIS2 Transposition Tracker 2026
The NIS2 Directive (2022/2555/EU) required EU member states to transpose its obligations into national law by 17 October 2024. Most missed the deadline. As of August 2026, the majority of member states have completed transposition, Germany's NISG 2026 enters into force on 1 October 2026, and the European Commission has initiated infringement proceedings against late-transposing states. For organisations using a virtual data room, NIS2 transposition status determines when their supply chain obligations under Article 21(d) become directly enforceable.
Published: 30 August 2026. Updated: 19 September 2026.
What NIS2 Requires
The NIS2 Directive replaced the original NIS Directive (2016/1148/EU) and substantially expanded scope, obligations, and enforcement. It covers two tiers: essential entities, listed in Annex I, and important entities, listed in Annex II. Essential entities include energy, transport, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space. Important entities include postal services, waste management, chemicals, food production, manufacturing, digital providers, and research organisations.
Article 21 sets ten minimum cybersecurity risk-management measures that both tiers must implement, proportionate to their size and the risks they face. The supply chain measure, Article 21(d), specifically requires entities to manage security risks in their supply chain, including relationships with suppliers and service providers. For organisations that use a virtual data room to handle confidential deal documents, financial data, or regulated sector information, the VDR provider is a supplier within the meaning of Article 21(d).
Article 23 requires significant incidents to be reported in three stages: an early warning to the national CSIRT or competent authority within 24 hours, a full incident notification within 72 hours, and a final report within one month.
Transposition Status by Member State (August 2026)
The transposition deadline was 17 October 2024. Most EU member states missed it. As of August 2026, the picture across the 27 member states is uneven. The table below captures the position based on publicly available legislative information.
| Member State | Status (August 2026) | Key instrument |
|---|---|---|
| Belgium | Complete | NIS2 Law, October 2024 |
| Croatia | Complete | Cybersecurity Act, October 2024 |
| Hungary | Complete | Government Decree, October 2024 |
| Lithuania | Complete | Amended Cybersecurity Law, 2024 |
| Netherlands | Complete | NIS2-implementatiewet, 2025 |
| Denmark | Complete | NIS2 implementing act, 2025 |
| Sweden | Complete | NIS2-law (2024:1210), August 2025 |
| Germany | Complete | NISG 2026, published 23 December 2025, in force 1 October 2026 |
| France | Substantially complete | Ordonnance NIS2, 2025; implementing decrees ongoing |
| Italy | Complete | Decreto Legislativo NIS2, January 2025 |
| Spain | Substantially complete | Draft RD-NIS2, under parliamentary review |
| Poland | Complete | Ustawa NIS2, 2025 |
| Austria | Complete | NISG 2024 amendments, 2025 |
| Ireland | Substantially complete | SI implementing NIS2 transposed 2025; sector rules pending |
| Finland | Complete | NIS2-laki, 2025 |
| Portugal | Substantially complete | Lei NIS2, 2025; sector guidance in progress |
| Greece | Substantially complete | Law 5162/2024 partially transposed; gaps under review |
| Czech Republic | Complete | Zákon o kybernetické bezpecnosti, 2024 |
| Romania | In progress | Draft law under parliamentary procedure |
| Bulgaria | Substantially complete | Law on Cybersecurity amended 2025 |
| Luxembourg | Complete | Loi NIS2, 2025 |
| Malta | Complete | NIS2 Regulations, 2025 |
| Cyprus | Substantially complete | NIS2 Regulations, 2025; sectoral scope pending |
| Slovakia | Complete | Zákon o kybernetickej bezpecnosti, 2025 |
| Slovenia | Complete | ZVKK-1, 2025 |
| Estonia | Complete | Küberturvalisuse seadus amendment, 2025 |
| Latvia | Complete | Law on Cybersecurity, 2025 |
Germany: NISG 2026 in Force 1 October 2026
Germany is the largest EU economy and, until October 2026, one of the last major member states without full NIS2 transposition in force. The NIS-Implementierungsgesetz 2026 (NISG 2026) was published in the Bundesgesetzblatt on 23 December 2025 after a protracted legislative process. It enters into force on 1 October 2026.
The NISG 2026 follows the NIS2 structure closely. It designates the Bundesamt für Sicherheit in der Informationstechnik (BSI) as the primary competent authority for most sectors, with BaFin retaining authority for financial services and the Bundesnetzagentur for energy and telecoms. Registration of essential and important entities with the BSI is required within three months of the in-force date, so most German organisations must register by 1 January 2027.
The BSI C5:2026 catalogue, published 7 April 2026, is binding for new Type 2 attestation periods starting from June 2027. German organisations in NIS2-covered sectors that procure cloud services, including virtual data rooms, will need to verify that their providers can supply documentation aligned with C5:2026 standards. This makes BSI C5 attestation the practical baseline for VDR procurement in German regulated sectors from mid-2027 onward.
For VDR buyers in Germany, the NISG 2026 creates a concrete deadline: supply chain due diligence on VDR providers under Article 21(d) must be in place by the in-force date. Contracts opened after 1 October 2026 should include Article 21-aligned security requirements and a contractual commitment from the VDR provider to notify the buying organisation of significant incidents within 24 hours, supporting the entity's own Article 23 reporting obligations.
Infringement Proceedings by the European Commission
The European Commission initiated infringement proceedings against member states that had not transposed NIS2 by the October 2024 deadline. Proceedings are the standard mechanism under Article 258 TFEU and can ultimately result in financial penalties imposed by the Court of Justice of the EU.
Infringement proceedings do not by themselves create legal obligations for private-sector organisations in the non-transposing state: those obligations arise from national implementing legislation. However, they do create regulatory pressure on national legislators to complete transposition, and they signal to procurement teams that the regulatory direction is clear and non-negotiable. Organisations in member states that have not yet fully transposed NIS2 should prepare as if transposition is imminent, because the obligations in the directive are already settled.
On 20 January 2026, the European Commission also published a proposal for targeted amendments to NIS2 to simplify compliance with the risk-management requirements and increase legal clarity around sector scope. The amendments are under Council and Parliament review; they do not change the core Article 21 obligations but may adjust the sectoral thresholds for essential and important entities.
What NIS2 Means for VDR Buyers
For organisations in NIS2-covered sectors, the supply chain obligation in Article 21(d) is the most operationally immediate NIS2 requirement for VDR procurement. It requires entities to manage cybersecurity risk in their supply chain, including written supplier security requirements, periodic assessments, and contractual flow-down of obligations.
Papermark is best for organisations in NIS2-covered sectors needing an EU-hosted data room with SOC 2 Type II and documented supply chain security. It hosts data by default in ISO 27001-certified data centres in Frankfurt, is SOC 2 Type II certified and GDPR compliant, maintains a public sub-processor list covering the Article 21(d) supply-chain transparency requirement, and publishes a DPA that covers the processor-to-controller incident notification obligations aligned with Article 23. For the highest-compliance deployments, the self-hosted Enterprise option removes the VDR provider from the supply chain entirely: the organisation runs the room on its own infrastructure, which collapses the supply-chain risk category rather than managing it.
The practical procurement checklist for NIS2-covered buyers should include: a written security questionnaire covering the Article 21 measures, a contractual 24-hour early-warning commitment for significant incidents, confirmation that the provider's sub-processor list is published and updated on a defined schedule, and a termination clause that meets the exit requirements of the EU Data Act. See EU Data Residency for the hosting matrix and GDPR for VDRs for the DPA checklist.
- Article 21(d) supply chain duty: written supplier requirements, periodic assessment, contractual flow-down.
- Article 23 incident SLA: 24-hour early warning, 72-hour notification, 1-month final report.
- Sub-processor transparency: the VDR provider's sub-processor list must be published and change-notified.
- EU hosting: reduces Schrems II transfer complexity and supports NIS2 jurisdictional alignment.
- Germany NISG 2026: in force 1 October 2026; German-market buyers face the most immediate deadline.
A Worked Example: Atreum Energy
Atreum Energy GmbH is a mid-size electricity distribution operator headquartered in Stuttgart. As an essential entity under both NIS2 and the NISG 2026, Atreum is required to implement Article 21 risk-management measures by 1 October 2026. In September 2026, Atreum's chief information security officer (CISO) reviews the company's ICT supplier list in preparation for registration with the BSI.
Atreum uses a virtual data room for ongoing regulatory reporting, asset-sale documentation, and bilateral due diligence with grid operators in France and Poland. The VDR provider has not been explicitly assessed under Article 21(d) because Atreum's previous risk framework pre-dates NIS2. The CISO identifies the VDR as a supplier in scope of the supply chain measure.
The CISO sends a security questionnaire to the VDR provider requesting evidence of the Article 21 measures applicable to the service: incident-handling procedures and the early-warning SLA, encryption and access-control configuration, sub-processor list, and a copy of the ISO 27001 or equivalent certification. The VDR provider responds within 48 hours with a SOC 2 Type II report summary, a published sub-processor list with change-notification terms, and a contractual addendum committing to a 24-hour early-warning SLA for significant incidents.
Atreum's legal team adds the Article 21(d) assessment to the supply chain risk register and attaches the contractual addendum to the VDR agreement. The room remains open for the ongoing German-Polish asset-sale process. The NISG 2026 compliance step adds less than one week to the deal timeline, and the documentation is ready for the BSI registration submission in January 2027.
Common Mistakes Organisations Make
The most common mistake is treating NIS2 as a future obligation until a national deadline has passed. Member states that completed transposition in 2024 and 2025 have had enforceable obligations in place for over a year. Organisations in those member states that have not assessed their supply chain risk under Article 21(d) are already non-compliant, not just unprepared.
A second common mistake is assuming that GDPR DPA compliance is sufficient for NIS2 supply chain purposes. GDPR and NIS2 have overlapping but distinct obligations. A GDPR DPA covers data-processing instructions, breach notification (72 hours controller to supervisory authority), and sub-processor flow-down. NIS2 Article 21(d) additionally requires a documented supplier security assessment, written supplier security requirements, and periodic review: steps that a standard GDPR DPA does not cover.
A third common mistake is applying NIS2 supply chain assessment only to IT infrastructure providers and overlooking SaaS tools used in strategic workflows. A VDR used for M&A, asset sales, or regulatory submissions is a supply-chain risk under Article 21(d) if the buying organisation is an essential or important entity. The assessment should extend to any external platform that processes the organisation's information.
A fourth common mistake is confusing the transposition deadline with the enforcement start date. In many member states, competent authorities have been empowered to enforce NIS2 obligations from the transposition in-force date, but enforcement ramp-up has been gradual. The absence of a formal enforcement action against an organisation does not mean the obligation is not in force.
A fifth common mistake for German-market buyers specifically is treating the NISG 2026 in-force date of 1 October 2026 as the start of a preparation period, rather than the deadline for compliance. Registration with the BSI, supply chain assessments, and contract updates should be complete by 1 October 2026, not started on that date.
Frequently Asked Questions
What was the NIS2 transposition deadline?
The deadline for EU member states to transpose the NIS2 Directive into national law was 17 October 2024. Most member states missed this deadline. As of August 2026, the majority have completed transposition, with Romania among the last to finalise its implementing legislation.
When does Germany's NISG 2026 enter into force?
Germany's NIS-Implementierungsgesetz 2026 (NISG 2026) was published on 23 December 2025 and enters into force on 1 October 2026. German essential and important entities must register with the BSI within three months, meaning by 1 January 2027.
Does NIS2 apply to virtual data rooms directly?
Some VDR providers may qualify as digital infrastructure or ICT service management providers in scope of NIS2 as essential or important entities. Most VDRs sit at the edge of direct scope. The main NIS2 angle for VDR use is indirect: organisations in NIS2-covered sectors must apply Article 21(d) supply chain due diligence to their VDR providers.
What must a NIS2-covered organisation ask its VDR provider?
At minimum: a completed security questionnaire evidencing the Article 21 measures (incident handling, cryptography, access controls, supply chain of the VDR itself), a contractual 24-hour early-warning SLA for significant incidents, a published and change-notified sub-processor list, and a copy of the provider's ISO 27001 or equivalent certification.
Is BSI C5 required for VDR procurement in Germany under NISG 2026?
The NISG 2026 does not name BSI C5 as a mandatory requirement, but BSI guidance and the C5:2026 catalogue published in April 2026 make C5 attestation the de-facto baseline for cloud services used by German essential entities in regulated sectors. For deals and workflows not involving regulated sector obligations, C5 is not required and ISO 27001 with a SOC 2 Type II report is a recognized substitute.
What is the incident reporting timeline under NIS2?
Three steps: an early warning to the national CSIRT or competent authority within 24 hours of becoming aware of a significant incident; a full incident notification within 72 hours; and a final report within one month. The processor (VDR provider) should notify the controller within 24 hours to allow the controller to meet its own 24-hour early-warning obligation.
Does NIS2 require EU data hosting for VDRs?
NIS2 does not mandate EU hosting, but the combination of Article 21 security measures, national transposition requirements in Germany (NISG 2026) and France, and the GDPR Schrems II framework makes EU hosting the lowest-friction answer for NIS2-covered organisations in most sectors. EU hosting keeps the storage jurisdiction inside the regulatory perimeter and reduces the scope of supplier assessment.