"When does NIS2 apply to us?" sounds like a question with one answer. If your company — or your customers, or your suppliers — sit across Slovakia, Czechia, Germany, and Austria, it has four. NIS2 is a directive: it binds member states to legislate, and what you actually comply with is the national law each one passed. Four countries, four acts, four regulators, four calendars.
This post is the buyer's version of that map — what is in force where, which authority supervises it, and which dates are still ahead. Facts verified against the national authorities' own publications as of early August 2026.
Why "is NIS2 in force?" is the wrong question
The directive itself — Directive (EU) 2022/2555 — entered into force in January 2023, and member states were obliged to transpose it into national law by 17 October 2024. Most missed that deadline, some by more than a year. So the honest picture in mid-2026 is uneven: some countries have had their national act live for eighteen months, one large neighbour switched overnight with no transition period, and one is still counting down. The right question is country-specific: which national act applies to this entity, since when, and what has it been asked to do by which date?
Slovakia — in force since 1 January 2025
Slovakia transposed early, and quietly: Act No. 366/2024 Coll. amends the existing Cybersecurity Act (Act No. 69/2018) rather than replacing it, so organisations already regulated under the NIS1-era framework kept their footing. The competent authority is the NBÚ — the National Security Authority — with SK-CERT as the national CSIRT. Entities in scope on day one had to register with the NBÚ by 1 March 2025; compliance obligations phase in through 2026. If you are Slovak and in scope, the registration window is long gone — the live question is whether your risk-management measures, supplier obligations included, would hold up to an NBÚ inquiry. The details are on our Slovakia page.
Czechia — in force since 1 November 2025, on a staircase
Czechia passed a new act rather than an amendment: Act No. 264/2025 Coll., the new Cybersecurity Act, supervised by NÚKIB. Two things make the Czech transposition distinctive. First, the calendar is a staircase: an entity has 60 days from falling into scope to self-register with NÚKIB, then 12 months from registration to implement the full set of security measures. If you registered in late 2025, your measures deadline lands in late 2026 — closer than it feels. Second, the act gives the government the power to restrict or ban specific suppliers or products for entities of strategic importance — a power that goes beyond what the directive itself requires, and one that moves supplier decisions from "best practice" territory into something the state can override. More on our Czechia page.
Germany — in force since 6 December 2025, with no transition period
Germany's transposition rewrote the BSI Act (BSIG) and took effect the day after promulgation — 6 December 2025, no transition period. The BSI supervises a three-tier model: KRITIS operators, besonders wichtige Einrichtungen (the directive's "essential"), and wichtige Einrichtungen ("important") — roughly 29,500 entities in scope, up from about 4,500 under the old KRITIS-only regime. The registration deadline passed on 6 March 2026 with only around a third of the expected entities registered, which tells you two things at once: a large share of the German mid-market is behind, and the BSI has a very long list to work through. German law also makes management accountability explicit — Section 38 of the revised BSI Act introduces personal liability for management bodies. Details on our Germany page.
Austria — counting down to 1 October 2026
Austria is the one still ahead of its main date, and the one where vendor copy gets it wrong most often. NIS2 is not yet the operative regime there: the first transposition attempt failed in parliament in 2024, and the successor — NISG 2026, promulgated in the Federal Law Gazette on 23 December 2025 — enters into force on 1 October 2026. Until then, the old NISG 2018 applies, covering only around a hundred designated operators. On 1 October that population expands to roughly 4,000 entities, each of which must register with the authority within three months — by 31 December 2026 at the latest. For an Austrian mid-market company that has never been regulated before, the practical runway between "the law applies to us" and "we are registered and expected to have measures under way" is one quarter. That is not much time to build a supplier inventory from nothing. See our Austria page for the specifics.
The rest of the EU, honestly
Beyond these four: NIS2 is transposed unevenly across the EU, with real national variation in scope, registration timelines, and supervisory powers. Hungary and Poland — both covered on our NIS2 hub — have their acts in force. Several member states are still legislating. We deliberately don't publish a "X of 27 transposed" figure, because it changes month to month and stale numbers are worse than none. For any country not named here, work from the directive and verify the national status the week you need it.
What stays the same in every country
Here is the useful part. The dates, regulators, and registration portals differ; the supply-chain obligation does not. Article 21(2)(d) — supply chain security, covering the relationships between each entity and its direct suppliers or service providers — survives transposition intact in every national act above. So does the operational work it implies: a maintained supplier inventory, a documented risk classification, per-supplier assessment evidence, a decision trail, and a reaction plan for material change. We've written up the five artefacts that answer most supply-chain inquiries separately — and none of them is country-specific.
That has a practical consequence for cross-border operators: build the supplier assurance layer once, to the obligation, not to a single country's act. A Czech staircase deadline, a German inquiry, and an Austrian registration wave all land on the same underlying records. If those records exist, the country calendar is an administrative detail. If they don't, every one of those dates is a separate emergency.
Where to start
If you want to know where you stand today, the NIS2 readiness check is self-serve and takes about five minutes. If your exposure spans more than one of the countries above, start with the country page for wherever your regulator sits — and remember that your suppliers' countries matter less than yours: the obligation follows the buyer.