Where transposition actually stands
NIS2's original transposition deadline - October 17, 2024 - passed with most member states missing it. As of mid-2026, 22 of 27 member states have adopted their transposing legislation; five (France, Ireland, Luxembourg, the Netherlands, and Spain) are still finishing theirs, under Commission infringement pressure after reasoned opinions issued in May 2025. Separately, the deadline for in-scope entities to complete their first compliance-verifying audit moved from December 31, 2025 to June 30, 2026 - the date most organizations should actually be planning against.
The formal scope question, answered plainly
NIS2 uses the EU's standard SME definition as its baseline: entities are generally in scope if they have 50 or more employees or annual turnover above €10 million, and operate in one of the directive's named "essential" or "important" sectors (energy, transport, health, digital infrastructure, financial services, manufacturing, and more). By that reading, most small companies are technically out of scope.
That formal reading misses two things that matter more in practice:
National expansion clauses
Article 2(2) lets member states expand scope to smaller entities providing critical services - several transposing laws do exactly that for specific sectors, regardless of headcount or turnover.
Contractual pull-through
In-scope entities are required to manage supply-chain cybersecurity risk - which means they push NIS2-aligned security requirements down into vendor and supplier contracts, whether or not the supplier is formally in scope.
Not sure whether a customer's NIS2 obligations are already flowing into your contracts? Get a free NIS2 exposure review - most vendors find out from a procurement questionnaire, not a legal team.
What actually shows up in a NIS2 audit
For entities that are in scope - directly or contractually - the substantive requirements center on risk-management measures (incident handling, business continuity, supply-chain security, access control, encryption), governance accountability at the management level, and incident-reporting obligations with tight early-warning windows similar in spirit to the Cyber Resilience Act's. The June 2026 audit deadline is where "we have a security policy document" gets tested against "we can demonstrate the controls actually operate."
| Status area | Where it stands (Sep 2026) |
|---|---|
| Member state transposition | 22 of 27 complete; 5 under Commission infringement pressure |
| First compliance audit deadline | June 30, 2026 (moved from Dec 31, 2025) |
| Framework amendments | Streamlining proposal published Jan 20, 2026, still in process |
| Formal SME scope | 50+ employees or €10M+ turnover, named critical sectors, subject to national expansion |
Key takeaways
- Most member states have now transposed NIS2, with five still finalizing legislation under Commission pressure.
- The practical deadline to plan against is June 30, 2026 - the first compliance-verifying audit date for in-scope entities.
- Formal scope targets medium and larger entities in specific sectors, but national expansion clauses and supply-chain contract pressure regularly pull smaller companies in anyway.
- If your customers are in scope, expect NIS2-aligned security requirements in your next contract renewal, regardless of your own headcount.
Zetrixweb