Menu
← Blog

NIS2 registration deadlines differ by country. The clocks do not.

A country-by-country table of NIS2 status, registration duties and the three reporting clocks, and what a multi-country client should do about the gaps.

20 September 2026

Abstract editorial illustration for “NIS2 registration deadlines differ by country. The clocks do not.”

The part that travels, and the part that does not

If you advise clients in several member states, the NIS2 fact everyone can recite — 24 hours, 72 hours, one month — matters least when you cross a border. It is identical in every transposed law we track. The duty with a dated, missable deadline attached, registration, differs in every single one: different cut-offs, different portals, and, most awkwardly, different events that start the clock.

A consultant who memorises the clocks is safe everywhere; one who memorises a single country's registration rule is wrong in the next one, in a way that surfaces as a missed statutory deadline rather than an argument about interpretation.

The table is built from our national NIS2 profiles, checked against primary sources on 17 September 2026. Where a profile records nothing, the table says so: unrecorded means not confirmed, not zero. Guidance and commencement orders move; re-check the source before relying on any date below.

The table

CountryLawStatusRegistration duty and deadlineEarly warningFull notificationFinal report
GermanyNIS2UmsuCG, BSIG 2025In force 6 Dec 2025Yes — 3 months from first qualifying; changes within 2 weeks (§33 BSIG)24 h72 h30 days
NetherlandsCyberbeveiligingswet (Cbw)In force 15 Aug 2026Yes — applies from 15 Aug 2026, the law sets no date; changes within 2 weeks24 h72 h30 days
BelgiumLaw of 26 April 2024 and Royal Decree of 9 June 2024In force 18 Oct 2024Yes — by 18 Mar 2025, or within 5 months of identification (art. 13); digital infrastructure and providers by 18 Dec 2024 (art. 14)24 h72 h30 days
DenmarkNIS 2-loven (Act no. 434 of 6 May 2025)In force 1 Jul 2025Yes — 2 weeks from coming into scope (§10); digital providers 3 months (§9)24 h72 h30 days
SwedenCybersäkerhetslag (SFS 2025:1506)In force 15 Jan 2026Yes — as soon as possible (2 kap. 2 §); changes within 14 days24 h72 h30 days
AustriaNISG 2026 (BGBl. I Nr. 94/2025)Adopted, applies from 1 Oct 2026Yes — 3 months from entry into force, by 1 Jan 2027; later entrants within 3 months (§29(3))24 h72 h30 days
IrelandNational Cyber Security Bill (not enacted)Pending; no in-force dateNot confirmed — no transposing lawNot confirmedNot confirmedNot confirmed

Read the last row carefully. Ireland is not a country with lenient NIS2 deadlines; it is one with no confirmed deadlines, because the Bill is not enacted. Our profile records no early-warning, notification or final-report figure, and no registration duty, deadline or portal: there is no national law to take them from. The NCSC's position: the portals open once the law is in place, and NIS1 still applies to existing operators of essential services. The Commission referred Ireland to the Court of Justice on 8 July 2026. Sources: https://www.ncsc.gov.ie/nis2/ and https://digital-strategy.ec.europa.eu/en/news/commission-refers-ireland-spain-france-and-netherlands-court-justice-failing-transpose-rules.

Four ways a registration clock can start

Ignore the numbers in the registration column; the trigger is the interesting part. Four starting events are in play across six transposed laws.

A fixed calendar date. Belgium set one — 18 March 2025 generally, 18 December 2024 for digital infrastructure and digital providers (arts 13 and 14). Austria's lands on 1 January 2027. Easiest to plan around, hardest to recover from once missed.

The moment the entity comes into scope. Germany gives three months from first qualifying (§33 BSIG); Denmark two weeks (§10), three months for digital providers (§9); Austria gives later entrants three months. These bite a growing client: nothing external announces that a company crossed a size threshold or added a qualifying service, so somebody there has to notice.

Identification by the authority. Belgium also runs a five-month clock from identification (art. 13) — a trigger arriving in the inbox.

Nothing at all. The Netherlands: the duty applies from 15 August 2026 and the law sets no date. Sweden: "as soon as possible" (2 kap. 2 §). Live duties with no countdown — easy to postpone, impossible to defend postponing.

Three of the six also set a clock for updating a registration — two weeks in Germany and the Netherlands, fourteen days in Sweden — and no client tracks it unprompted.

The portals are separate systems with separate enrolment: the BSI portal in Germany, via Mein Unternehmenskonto; MijnNCSC in the Netherlands (https://www.ncsc.nl/cyberbeveiligingswet-nis2/registreren); the Safeonweb at-work portal in Belgium; virk.dk in Denmark, coordinated by the Danish Agency for Societal Security (https://samsik.dk/nis2/); Cyberportalen in Sweden; and the USP portal in Austria. Enrolment in a national business-identity system is usually the slow step, and rarely the compliance team's to control. In Sweden the NCSC at FRA has received registrations and reports since 1 July 2026, previously MCF: a procedure written earlier in 2026 may name the wrong recipient.

Scope diverges too, quietly

Registration is the expensive divergence; the size test produces the confidently wrong answers. Of the six, five record no deviation from the directive's size-cap rule under Recommendation 2003/361/EC. Denmark is the exception: the Act states thresholds itself (§§4–5) — 50 employees with turnover and balance sheet of EUR 10m, 250 employees with turnover of EUR 50m or balance sheet of EUR 43m — without referring to the Recommendation. Whether partner and linked enterprises count is therefore not stated, and our profile does not fill the gap. Denmark also disapplies the Act where the energy preparedness law, the telecom security law or the financial sector rules (FIL §333) apply (§1(2)).

Aggregation differs elsewhere too. Austria does not add partner and linked enterprise data where the entity's systems are independent (§25(4)); Belgium's CCB weighs the same independence (art. 3 §2); Germany lets negligible business activities be disregarded when classifying (§28(3) BSIG); the Netherlands counts partner and linked enterprises with no such qualification recorded. Two facts override size: the Dutch Cbw makes ministries, provinces, municipalities, water boards and critical entities essential by law (art. 8), and Sweden covers all municipalities and regions regardless of size. Trust service providers notify within 24 hours in Belgium (art. 35 §2) and Sweden — the one clock genuinely shorter for a subset of entities.

What to do about it, in order

  1. Build the country list before the control list. Where the client operates decides which statute you are reading.
  2. Pull the group structure next. Aggregation rules differ by country and move the size answer more often than the sector list.
  3. Classify per country, and confirm each one yourself. The class is a legal qualification; a tool should propose it and show the trigger, never assign it.
  4. Deal with registration ahead of documentation. It is dated and binary — the duty a client fails on a specific Tuesday.
  5. Write the trigger into the plan, not just the date. "Three months from first qualifying" needs an owner watching headcount and services; "as soon as possible" needs a date you set.
  6. Diary the update clocks: two weeks in Germany and the Netherlands, fourteen days in Sweden.
  7. Write one incident procedure per country, not per client. The clocks match; the variables are the authority, the portal, the routing, and the 24-hour trust-service-provider rule where it applies.
  8. For Ireland, plan for the Bill and keep NIS1 obligations running. Record the position as unconfirmed rather than inventing dates.
  9. Put a re-check date on every country fact. Ours were checked on 17 September 2026 — itself a fact with a shelf life.

Step 7 is the argument for holding this as per-country data rather than prose in a template: once the authority, portal, registration duty and three clocks live in one record, the procedure a client receives names the right body without anyone retyping it. That is how clausebench holds them — and check the source before the document leaves your office.

Primary sources: https://www.gesetze-im-internet.de/bsig_2025/__28.html, https://www.gesetze-im-internet.de/bsig_2025/__32.html, https://www.gesetze-im-internet.de/bsig_2025/__33.html, https://wetten.overheid.nl/BWBR0052872/2026-08-15/0, https://refli.be/en/lex/2024202344, https://www.retsinformation.dk/eli/lta/2025/434, https://lagen.nu/2025:1506, https://lagen.nu/2025:1507, https://ogd.ris.bka.gv.at/Dokumente/BgblAuth/BGBLA_2025_I_94/BGBLA_2025_I_94.html, https://www.usp.gv.at/aktuelles/newsliste/NIS-2.html, plus the Irish pages above.

See what changed since your clients' policies were written

Enter up to ten client websites. Free, no sign-up, the first report in about a minute.