NIS2 is a directive, and your client is in a country
The reporting clocks in NIS2 are broadly the same wherever you look: a warning within a day, a notification within three, a final report within a month. The divergence that costs a client money is elsewhere — in who they register with, by when, and from which event the clock starts.
These pages take every country-level fact from national profiles we keep as data, each with the source that confirms it and the date it was checked. Where something is not confirmed, they say so instead of filling it in.
Guides
Long-form, written for a practitioner.
- NIS2: national transposition differences that matter
Where member states diverge on scope, registration and incident reporting, and how to advise a client operating in several of them.
- Answering vendor security questionnaires at scale
A method for answering questionnaires from a client's documented facts, marking what needs checking and building a reusable answer library.
Notes
Shorter pieces on one thing that changed.
- The German NIS2 clocks a consultant has to track
BSIG 2025 registration, change and incident deadlines with their section numbers, and the order to put them in place for a German client.
- What to tell a client with an Irish entity about NIS2
Ireland has not transposed NIS2, so there are no national duties yet — what is live instead, what to do meanwhile, and what not to put in a memo.
- The Dutch Cyberbeveiligingswet is in force: what to check now
The Netherlands' NIS2 law applies from 15 August 2026 — who is essential by law, how group size counts, and how registration and reporting actually run.
- NIS2 registration deadlines differ by country. The clocks do not.
A country-by-country table of NIS2 status, registration duties and the three reporting clocks, and what a multi-country client should do about the gaps.
Doing this work
What the product does with it.
- Vendor changes
Vendor pages are checked daily and every change is read by a person before it reaches you, with the clients affected and the documents to regenerate.
- Records of processing
Build an Article 30 record of processing for each client from facts you confirmed once: purposes, categories, recipients, transfers and retention, with the vendor rows filled from a verified registry.
Reference
The pages the facts come from.
See what changed since your clients' policies were written
Enter up to ten client websites. Free, no sign-up, the first report in about a minute.