Two things are true about NIS2 in mid-2026, and they sit awkwardly together.

The first: the grace period is over. National competent authorities are now actively supervising, and the obligations — risk management measures, incident reporting, and personal accountability for senior management — are live for the entities in scope.

The second: the legal map is still incomplete. As of mid-2026, 22 of 27 Member States have adopted transposing legislation, while five — France, Ireland, Luxembourg, the Netherlands, and Spain — remain in legislative procedure. The European Commission has escalated: after formal notices to 23 Member States in late 2024, it issued reasoned opinions to 19 in 2025 for failing to notify complete transposition, the last step before referral to the Court of Justice.

For a company operating in a single country that has finished the job, this is manageable. For a cross-border scale-up, it is the actual problem — bigger than any single clause in the directive.

Why fragmentation is the real exposure

NIS2 was meant to raise the floor and harmonise cybersecurity obligations across the Union. In practice, transposition has introduced exactly the variation it was designed to remove:

  • Scope diverges. Which entities count as “essential” or “important” — and the size and sector thresholds that pull you in — are being drawn slightly differently across national laws.
  • Registration and reporting differ. Deadlines, formats, and the identity of the competent authority you report to vary by country.
  • Some of your markets have no final law yet. In the five outstanding states, you are planning against a directive and a draft, not a statute.

If you operate in six countries, you do not have one NIS2 obligation. You have six overlapping ones, at least one of which is still being written.

Waiting for the map to settle is not a strategy. By the time every Member State has transposed, the states that moved first will already have run their first enforcement cycles.

How to comply against a moving target

You cannot control the transposition timetable. You can control your posture. The approach that works is to stop treating NIS2 as twenty-seven separate compliance projects and start treating it as one control baseline, applied everywhere, tuned locally.

  1. Build to the strictest common denominator. Design your risk-management measures — governance, supply-chain security, incident handling, business continuity, encryption, access control — to satisfy the most demanding version among the states you operate in. Meeting the toughest bar clears the rest.
  2. Centralise detection and reporting, localise the filing. Run one incident-response process that can produce a notification fast enough for the tightest national deadline (the early-warning obligation is measured in hours, not days), then route the filing to the right authority per country.
  3. Put it on the board, in writing. NIS2 makes senior management personally accountable for cybersecurity risk management, and that duty does not wait for perfect transposition. Management-body approval and oversight of the measures should be documented now.
  4. Map scope per market, and keep the map current. Re-check whether you are “essential” or “important” in each country as national laws finalise — including the five still in procedure — because your obligations, and your reporting authority, follow that classification.

The overlap that pays you back

The good news for anyone already building a security programme: NIS2’s risk-management measures overlap heavily with ISO 27001, and its incident-reporting discipline is the operational muscle you need for GDPR breach notification anyway. Built once, deliberately, a single control set can satisfy NIS2 supervision, carry your ISO certification, and feed your GDPR obligations at the same time.

That is the difference between treating NIS2 as a compliance tax and treating it as infrastructure. The directive is not going to get simpler while the last five states finish transposing. The companies that get ahead are the ones that stop waiting for the map and build to the terrain.

If you operate across several EU markets and are unsure where NIS2 pulls you in — or how to run one incident process across them — that is a first-call conversation.