NIS24-minute read·Marcin Pajdzik·January 2026

NIS2 Is Not One Rulebook Across Europe

NIS2 is a European directive, not a regulation. Unlike a regulation, it does not apply identically across all EU Member States. Each Member State must enact its own implementing legislation, and scope, supervision and enforcement can differ materially between jurisdictions.

For senior leaders of multinational organisations, the practical consequence is that NIS2 scope cannot be confirmed by reading the directive alone. It must be assessed against the national laws that apply to each relevant legal entity.

Why national implementation matters

NIS2 establishes a common European framework, but the obligations are given effect through national law. Member States were required to transpose the directive by 17 October 2024. National implementation therefore determines important aspects of how the regime operates in practice. Member States can also adopt or maintain provisions that provide a higher level of cybersecurity, and NIS2 itself leaves a number of matters to national determination.

Where national differences matter

Three areas require particular attention when moving from the directive to national law.

Scope
NIS2 establishes essential and important entities and uses sector, activity and size as important elements of scope. But the directive contains exceptions to the general size rule and gives Member States discretion in certain areas of scope. National law therefore matters when determining whether a particular legal entity is in scope and how it is classified.
Competent authority
The competent authority responsible for oversight varies by Member State and, in some jurisdictions, by sector. NIS2 contains jurisdiction rules that determine which Member State is responsible for supervising an entity, including specific rules for certain cross border services. A multinational group may therefore deal with different competent authorities across its legal entities, each operating within its national supervisory framework.
Supervision and enforcement
NIS2 establishes common cybersecurity risk management obligations, including the measures set out in Article 21, but those obligations sit within national supervisory and enforcement regimes. Organisations therefore need to understand what controls they have implemented, what evidence may be expected by the relevant authority, and how deficiencies can be investigated and enforced in each jurisdiction.

What multinational organisations should do

For a multinational board, the key governance question is whether management has mapped the group's relevant legal entities against the applicable national regimes and identified where those regimes diverge. A general assurance that the group is NIS2 compliant does not answer that question.

The resulting analysis should distinguish differences that are merely administrative from those that affect scope, governance, incident reporting, supervision or enforcement. A group programme can still provide a common compliance baseline, but it needs to accommodate material national differences, since compliance in the headquarters jurisdiction does not establish compliance across the group.

How this affects your organisation

For a multinational board, an assumption of group wide compliance that has not been tested entity by entity is a governance gap. That gap may only become visible when a local entity faces regulatory scrutiny or an incident triggers its national obligations.

The board should be able to ask one straightforward question: Have we assessed every relevant legal entity against the national NIS2 regime that applies to it, and do we know where the requirements materially differ?

Not sure how national NIS2 transposition affects your organisation?

Receive new briefings by email

Published every few weeks. Confirm by email before your first briefing arrives.

NIS2 Frameworks

If this briefing is relevant to your organisation, these frameworks set out how to act on it, with a structured starting point and a programme approach designed to deliver sustained compliance.

NIS2 Diagnostic FrameworkHow to Run a NIS2 Programme