NIS2

Know which national authority actually enforces NIS2 for you

The European Union flag waving against a cloudy sky

#Technology 📅 Year-round

NIS2 is an EU directive, which means it doesn't enforce itself directly — each member state transposes it into national law and designates its own competent authority (or authorities, split by sector in some countries) to actually register businesses, receive incident reports, and carry out enforcement. Knowing you're in scope isn't the same as knowing who you'd actually be reporting to or dealing with in an audit. This isn't legal advice — the details vary by country and change as implementation matures — but finding your specific national authority (usually via your country's cybersecurity agency) is a concrete, findable fact worth having on hand before you need it.

← All challenges