Author: Ingolf Rauh

FAQ: NIS2 Implementation in the EU

 

Postponed is not canceled, and despite all delays in some European countries, national NIS2 laws will come into effect sooner or later—likely in most cases during 2025. Therefore, companies in regulated sectors should take swift action if they are not yet prepared.

 

What is NIS2?

The NIS2 Directive (Network and Information Security 2) is the EU's updated cybersecurity legislation, replacing the original NIS Directive. "Directive" means that each EU member state is responsible for transferring the EU legislation to national law to come into effect. Therefore, actual implementation may differ between European countries. NIS2, in general, expands the scope of cybersecurity requirements for businesses and organizations in critical sectors, ensuring a higher level of resilience against cyber threats across the EU. In parallel with the NIS2 Directive, the EU Commission has issued the NIS2 implementing regulation, which overrules the national law and applies to all target entities. It defines in special the security requirements. 

 

Why is NIS2 important for businesses?
NIS2 introduces stricter security measures, incident reporting requirements, and penalties for non-compliance. It applies to more industries than before, and companies should check with official government resources in their jurisdiction to see if they fall under the new requirements. If they do so, businesses must invest in cybersecurity to avoid fines, reputational damage, and operational risks. 

 

What is the current status of NIS2 implementation across the EU?
NIS2 should be transposed into national law by all EU member states by October 17, 2024. However, the implementation of NIS2 still varies by country. Some nations, such as Belgium, Croatia, and Italy, have already enacted their laws promptly, while others, including Germany, France, and Spain, are still finalizing their legislation. Some countries, like Estonia and Portugal, have put implementation on hold. Therefore, most EU member states have missed the deadline for NIS2 implementation. Trust Services must follow the NIS2 directive as far as possible since the directive was already included in the eIDAS regulation. Despite the national law-making process, the NIS2 implementing regulation concerning security requirements has been in force for any target entity since October 2024. 
What are the expected timelines for pending implementation in major EU countries?

9 countries— Belgium, Croatia, Greece, Hungary, Italy, Lithuania, Romania, Slovakia, and Latvia— have adopted national laws transposing the NIS2 directive.

Several other countries are in the process of finalizing their NIS2 implementation:

  • Germany: Expected by mid-to-late 2025.
  • Denmark: Expected by Mid 2025
  • Portugal: to be expected by May 2025
  • France: Likely to be enacted by the second half of 2025.
  • Spain: The timeline remains unclear but is anticipated in 2025.
  • Finland: the draft law is expected to be passed and come into force in Q2 2025
  • Austria: the first draft of the law was sent to Parliament in 2024 but is being revised. Due to the government building process, the current timeline is not entirely clear.

Other countries are still in the early stages of the transposition process. Despite the transposition process, the EU Commission Implementing Regulation on NIS2 is already valid and in force since October 2024.

How does NIS2 affect businesses operating in multiple EU countries?

Businesses must comply with each country's specific implementation of NIS2 and all EU implementing acts, which may lead to variations in requirements deriving from national laws. Companies should monitor national developments to ensure compliance across multiple jurisdictions.

What penalties are expected for non-compliance with NIS2?

Penalties vary by country but are expected to include significant fines and potential operational restrictions for non-compliant businesses. Authorities may impose penalties of up to €10 million or 2% of global turnover, whichever is higher. Additionally, executives can face personal liability for cybersecurity failures.  

How does NIS2 interact with existing cybersecurity regulations?
NIS2 builds upon the original NIS Directive, strengthening cybersecurity measures and expanding the scope of affected entities. Companies subject to NIS regulations will likely face stricter security and reporting obligations.mollit anim id est laborum.
What is the role of national cybersecurity authorities under NIS2?

Under NIS2, national cybersecurity authorities are crucial in monitoring, enforcing, and supporting cybersecurity regulations. Their key responsibilities include:

  1. Supervision & Compliance – Ensuring that essential entities comply with cybersecurity requirements.
  2. Incident Reporting & Response – Receiving, analyzing, and coordinating responses to cyber incidents.
  3. Regulatory Enforcement – Imposing fines, sanctions, and corrective measures for non-compliance.
  4. Threat Intelligence & Risk Analysis – Assessing cybersecurity risks and sharing intelligence.
  5. Collaboration & Coordination – Working with EU institutions, national agencies, and industry stakeholders to enhance cybersecurity resilience. 
How can Swisscom Trust Services help businesses become compliant?

Swisscom Trust Services offers a NIS2-compliant trust service, which will be audited according to NIS2 in the repetition audit. As part of the supply chain, a NIS2-compliant trust service streamlines any customer's compliance while improving operational resilience and business potential.

As a trust service provider, we are uniquely positioned to support businesses complying with NIS2 and other regulatory requirements. We undergo rigorous audits according to ETSI standards, which, while not mandatory in many European countries, have been firmly established in Switzerland for years. This gives us a significant advantage over providers who do not adhere to the same high standards. Our trust services assure you that your digital processes are robust, compliant, and future-proof. 

 

 

Do you have any questions? Contact us!