Skip to content
EU AI Stack

NIS2 without transposition: five member states, one supply chain

Fryderyk Pryjma6 min read
Minimal navy infographic with five thin gold markers of different height labelled DE, FR, NL, PL and IE, showing uneven NIS2 transposition

NIS2 had to be transposed into national law by 17 October 2024, and it was not. The Commission opened infringement proceedings against most member states during 2025, and by late summer 2026 the picture is still uneven: some states have a finished regime with named supervisors and registration duties, others operate on draft bills or partial acts. For an AI vendor selling into several markets, the directive is not the compliance surface. Five national acts are. The workable answer is one evidence pack built to the strictest regime you sell into, plus a short per-country annex for registration, incident channel and supervisor.

Why is a directive not enough to answer a questionnaire?

NIS2 is a directive, so it binds member states rather than companies. What binds your customer is the national act that implements it, and what binds you is the clause that customer puts in the contract. When the national act arrives late, the customer still has an audit programme and a board that wants assurance, so the questionnaire goes out anyway, drafted from the directive text or from whatever consultancy template was closest to hand.

That is the practical problem in 2026. Vendors receive questionnaires that cite Article 21 measures in language nobody has yet turned into national detail, while other buyers in the same quarter cite a finished act with concrete registration and reporting duties. Answering each one from scratch is how a small compliance function loses two weeks a month.

Where do the five markets actually differ?

The substance of Article 21 travels well. Risk analysis, incident handling, business continuity, supply chain security, vulnerability handling and cryptography appear in every national version because the directive sets the floor. The differences that cost you time are procedural: who supervises, whether registration is self-service or notified, how incident reports are filed, and how aggressively the state extended scope beyond the directive minimum.

MarketRegime status in mid-2026What it changes for a vendor
GermanyNIS2 implementation act in force, BSI as supervisor with registration dutiesExpect the most detailed questionnaires and requests for named contacts and evidence dates
FranceTransposition law adopted, ANSSI supervising with sector decrees phased inSector decrees decide the detail, so ask which decree the buyer sits under before answering
NetherlandsCyberbeveiligingswet in force, sector supervisors split by domainTwo buyers in one country may report to different supervisors with different formats
PolandAmended national cybersecurity act, later than most, supervision by sector CSIRTContract clauses often reference the directive directly, so pin the clause to a dated act
IrelandNational act in place with NCSC as competent authority, wide scope in digital servicesGroup-level buyers frequently apply the strictest of their group regimes to you
What changes per market when you sell the same AI service into five member states.

Read that table as a routing guide, not a legal opinion. Before answering any NIS2 questionnaire, confirm three things with the buyer: the national act they are regulated under, whether they are essential or important, and which supervisor receives their incident reports. Those three answers determine which of your evidence goes into the reply and which stays out.

The parts that never differ

  • Incident reporting rhythm: early warning within 24 hours, notification within 72 hours, final report within one month. Your contract has to support the buyer meeting those, which means your notification duty to them is measured in hours, not business days.
  • Management accountability: every regime makes senior management answerable, which is why buyers ask who signed your security policy and when it was last reviewed.
  • Supply chain security: the buyer must assess you, so their audit right, your subprocessor list and your own supplier controls appear in every version.
  • Vulnerability handling and disclosure: a named channel, a triage commitment and a patch timeline. From 11 September 2026 the Cyber Resilience Act adds its own reporting duty for actively exploited vulnerabilities.

How do you answer five regimes with one pack?

Build to the strictest market you sell into, usually Germany or an Irish group buyer, then annex the local procedure. A pack that holds up across all five is short: architecture and data residency diagram, access model with joiner mover leaver evidence, retention and deletion table, subprocessor register with locations, incident process with the 24 and 72 hour path drawn, vulnerability disclosure policy, business continuity test result with a date, and the security policy with its approval signature.

  1. Write the core pack once, in English, with every artefact dated and owned by a named person.
  2. Add a one page annex per market naming the act, the supervisor, the registration status of your customer type and the incident channel.
  3. Map each questionnaire question to a pack artefact instead of writing prose, so the second audit costs a tenth of the first.
  4. Re-date the pack quarterly. An undated artefact reads as an aspiration, and auditors treat it that way.
  5. Track transposition changes per market and update only the annex, never the core pack.
Fragmented transposition is not a reason to wait. It is a reason to answer once, in a form that survives whichever national act arrives next.

The upside of doing this properly is that the same artefacts serve more than NIS2. The residency diagram and retention table answer GDPR questions, the vulnerability policy feeds the Cyber Resilience Act duty, and the logging and human oversight evidence carries into AI Act work when the high-risk regime lands on 2 December 2027 for Annex III systems. One pack, several audits.

Frequently asked questions

Does NIS2 apply to us if our member state has not finished transposing it?
Not directly, and usually not at all as an AI vendor. Your obligations arrive through contracts with regulated buyers, and those buyers are bound by their own national act. A delayed act delays supervision, not the questionnaires, because the buyer's audit programme runs regardless.
Which national regime should we build our evidence pack against?
The strictest one you sell into. In practice that is the German implementation act or an Irish group buyer applying group-wide standards. Building to the floor of the directive means reworking the pack for every stricter buyer you win.
What do we do when a contract clause cites the directive rather than a national act?
Ask which act the buyer is regulated under and pin the clause to it in writing. Directive citations create ambiguity about scope and reporting timelines, and ambiguity in a supplier clause is always resolved against the supplier during an incident.
How fast must we notify a customer of an incident?
Fast enough for them to send an early warning within 24 hours and a notification within 72 hours to their supervisor. That realistically means a contractual notification duty measured in hours with a named channel, not a best efforts clause.
Does the pack need translating into each language?
Usually not for the technical artefacts, which buyers accept in English. Translate the annex when a supervisor or a public sector buyer requires filings in the national language, and keep the translation dated alongside the original.
ShareLinkedInXEmail

Related articles

Next step

Bring us the questionnaire you cannot answer yet

Send the audit request or RFP section that is blocking a deal, and we reply with the gaps we see.

Request a review