Understanding the registration and reporting requirements of the EU NIS2 Directive
December 09, 2024
Understanding the registration and reporting requirements of the EU NIS2 DirectiveDecember 09, 2024 The NIS2 Directive (Network and Information Security Directive 2) is one of the European Union’s most ambitious initiatives to harmonise and strengthen cybersecurity across the bloc. Since 16 January 2023, the directive has been in force with the goal of improving the resilience of organisations operating in critical sectors. Member States were required to transpose the directive into their national legislation by 17 October 2024. However, as of 28 November 2024, the European Commission identified that 23 Member States, including the Netherlands, had failed to meet this deadline. This raises important questions: what are the consequences for organisations in these countries? Are registration and incident reporting obligations enforceable? This blog explores the legal implications of delayed implementation of the NIS2 Directive. The status of implementation: which countries are delayedOn 28 November 2024, the European Commission announced infringement proceedings against 23 Member States for failing to transpose the NIS2 Directive into their national laws on time. These Member States include:
These delays have resulted in significant legal uncertainty. Belgium and Croatia are among the few Member States that managed to complete their transposition within the stipulated timeframe. Registration and reporting obligations under NIS2The NIS2 Directive imposes several obligations on organisations in critical sectors. Two key obligations include:
These obligations become enforceable only after a Member State has transposed the directive into its national legislation. The legal reality in countries without implementationUntil a Member State implements the NIS2 Directive, there is no legal basis to compel organisations to register or report incidents. This means that organisations based in these countries are formally not required to register with a supervisory authority or to report significant incidents. This is rooted in the legal principle that EU directives are only binding on individuals and organisations once they are transposed into national law. The European Commission confirms this principle, stating that “directives […] must be transposed into national legislation by EU countries before they can be enforced.” Consequently, in the absence of national implementation, organisations in these countries have no direct obligations under the NIS2 Directive. The absence of national implementation of the NIS2 Directive does not entirely negate its impact. While organisations are not directly obligated to comply with registration or reporting requirements, positive obligations on Member States to act in certain circumstances may still hold weight under EU law. This can occur through the principles of the effet utile doctrine, which ensures the effective application of EU law, even if it has not been fully transposed. The NIS2 Directive places an emphasis on Member States' responsibilities to coordinate, assist, and respond to significant cybersecurity incidents. For example:
Proactive steps organisations can takeWhile organisations in Member States without implementation laws currently face no enforceable obligations, this period of legal “breathing space” is not an excuse to remain unprepared. The implementation of the directive is inevitable. Organisations should take the following steps to enhance their cybersecurity posture and prepare for compliance:
ConclusionIn Member States that have yet to implement the NIS2 Directive, registration and reporting obligations are not currently enforceable. However, organisations should not mistake this delay for a lack of accountability. By proactively strengthening cybersecurity measures and establishing compliance frameworks, organisations can safeguard their operations, protect their reputations, and ensure readiness for the regulatory landscape ahead. Further readingLatest Insights
Latest News
Latest Events
legal updates May 29, 2026 Consumer Lens - Session 1 | The Rise of European Class Actions podcasts and webcasts May 29, 2026 Tax NOLs in Cross-Border Structures Webinar legal updates May 28, 2026 EU Pay Transparency Directive legal updates May 27, 2026 Trade secrets and the Digital Omnibus: key risks and safeguards client news June 02, 2026 Next stop, public ownership: Eversheds Sutherland advises DfT on GTR transi... firm news June 01, 2026 Eversheds Sutherland strengthens restructuring offering with senior partner... firm news June 01, 2026 Eversheds Sutherland strengthens Commercial Advisory practice with technolo... client news May 28, 2026 Eversheds Sutherland advises Schroders Greencoat on acquisition of Dutch bi... virtual UK employment law training June 09, 2026 1pm - 4pm (BST) Virtual virtual Nordic (Denmark, Finland, Norway and Sweden) employment law training June 16, 2026 12.45pm - 4pm (BST) Virtual virtual Introduction to Swiss employment law June 23, 2026 2pm - 5pm (GMT) Virtual virtual UAE - Employment law in the Dubai International Financial Centre September 10, 2026 9.30am - 1.30pm (GMT) Virtual |