Why national implementation matters
NIS2 establishes a common European framework, but the obligations are given effect through national law. Member States were required to transpose the directive by 17 October 2024. National implementation therefore determines important aspects of how the regime operates in practice. Member States can also adopt or maintain provisions that provide a higher level of cybersecurity, and NIS2 itself leaves a number of matters to national determination.
Where national differences matter
Three areas require particular attention when moving from the directive to national law.
- Scope
- NIS2 establishes essential and important entities and uses sector, activity and size as important elements of scope. But the directive contains exceptions to the general size rule and gives Member States discretion in certain areas of scope. National law therefore matters when determining whether a particular legal entity is in scope and how it is classified.
- Competent authority
- The competent authority responsible for oversight varies by Member State and, in some jurisdictions, by sector. NIS2 contains jurisdiction rules that determine which Member State is responsible for supervising an entity, including specific rules for certain cross border services. A multinational group may therefore deal with different competent authorities across its legal entities, each operating within its national supervisory framework.
- Supervision and enforcement
- NIS2 establishes common cybersecurity risk management obligations, including the measures set out in Article 21, but those obligations sit within national supervisory and enforcement regimes. Organisations therefore need to understand what controls they have implemented, what evidence may be expected by the relevant authority, and how deficiencies can be investigated and enforced in each jurisdiction.
What multinational organisations should do
For a multinational board, the key governance question is whether management has mapped the group's relevant legal entities against the applicable national regimes and identified where those regimes diverge. A general assurance that the group is NIS2 compliant does not answer that question.
The resulting analysis should distinguish differences that are merely administrative from those that affect scope, governance, incident reporting, supervision or enforcement. A group programme can still provide a common compliance baseline, but it needs to accommodate material national differences, since compliance in the headquarters jurisdiction does not establish compliance across the group.