NIS2 Grace Period: No EU-Wide Delay — But Bulgaria, Poland, and Italy Each Got a Different One
Search “NIS2 grace period” and you’ll find two contradictory claims: some sites say the grace period “ended June 2026,” others say there was never one to begin with. Both are half right. The NIS2 Directive itself contains no grace period — Member States were required to have their own transposing measures in force EU-wide by 18 October 2024, with Article 21’s security obligations flowing from those national laws [1]. But three member states built genuinely different national leniency mechanisms into their own transposing laws, and confusing “my country hasn’t finished transposing yet” with “I have more time” is the mistake that gets organisations caught flat-footed. Here’s what Article 41 actually says, what the European Commission did on 8 July 2026 to the four laggard states, and — country by country — which “grace period” claim is real where you operate.
Is There an EU-Wide NIS2 Grace Period? What Article 41 Actually Says
No. Article 41 of Directive (EU) 2022/2555 states plainly: “By 17 October 2024, Member States shall adopt and publish the measures necessary to comply with this Directive,” and that those measures “shall apply… from 18 October 2024” [1]. There is no transitional clause, no phase-in window, and no reduced-penalty period written into the Directive itself. The obligation was binding on Member States — not directly on companies — from that date, regardless of whether any individual country had finished writing its own implementing law.
That distinction is where the confusion starts. NIS2 is a directive, not a regulation — it doesn’t apply directly to your organisation the way GDPR does. It applies to you once your national government transposes it into domestic law, and your actual compliance deadlines are set by that national law, not by Article 41. So “is there a grace period” really breaks into two separate questions: has my country transposed NIS2 at all, and if so, did its transposing law build in any leniency of its own? As of this writing, most member states have transposed and are actively supervising; a handful still haven’t, and the EU’s patience for that second group ran out this month. One thing doesn’t move regardless of any national timeline: the Directive’s own fine ceilings. Article 34 requires that penalties be “effective, proportionate and dissuasive,” with a floor set at up to €10 million or 2% of global turnover for essential entities and €7 million or 1.4% for important entities [2] — every national leniency mechanism described below operates underneath that ceiling, never above it.
No EU Patience for Delay: The July 2026 CJEU Referral
On 8 July 2026, the European Commission referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the EU for failing to notify complete transposition of NIS2 — requesting the Court impose both a lump-sum fine and daily penalty payments on the countries involved until each one does [3]. The timeline behind that referral is itself instructive: letters of formal notice went out 28 November 2024, barely six weeks after the October 2024 deadline passed; reasoned opinions followed on 7 May 2025; the CJEU referral came fourteen months after that [3]. Notably, the Dutch Senate had passed the Cyberbeveiligingswet just one day earlier, on 7 July 2026 [9] — so the Netherlands’ inclusion reflects its transposition-notification status at the moment the case was filed, not necessarily its status today. Its law now enters force 15 August 2026 [9].
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
This is the clearest evidence available that there’s no informal EU-level grace period either. The Commission isn’t waiting patiently for slow transposers; it’s actively litigating against them, seeking financial penalties against the states themselves. If you’re operating in Ireland, Spain, or France, that CJEU referral doesn’t touch your organisation directly — but it should end any assumption that your country’s incomplete transposition is a compliance holiday. For the complete legislative status of all 27 member states, our transposition status tracker tracks entry-into-force dates and competent authorities as they update.
The Country-by-Country Grace Period Status Matrix
The table below isn’t a full transposition tracker — it’s a targeted read on the specific question this article answers: is enforcement genuinely active, and does that country’s law contain any real leniency mechanism, or is “grace period” just wishful thinking?
| Country | Law in Force | Enforcement Status | Real “Grace” Mechanism |
|---|---|---|---|
| Belgium | 18 Oct 2024 | Active since day one | None — full penalties applied from entry into force [10] |
| Italy | 16 Oct 2024 (decree); 14 Apr 2025 (real clock start) | Phased — active | 9/18-month runway from notification, not from the decree date [4] |
| Bulgaria | 13 Feb 2026 | Active, full rate since 1 Jun 2026 | Temporary 50% fine discount, expired 1 Jun 2026 [5][6] |
| Germany | 6 Dec 2025 | Active, registration lagging | Discretionary registration extension to 31 Jul 2026 — not a fine amnesty [7] |
| Poland | Apr 2026 | Law active, penalties not yet biting | Multi-year phase-in — audits/fines not until 2027-2028 [8] |
| Netherlands | 15 Aug 2026 | Not yet active | None once live — obligations apply immediately (3-yr exception for higher education only) [9] |
| Ireland, Spain, France | Not yet transposed | No national NIS2 law yet | None — and the states themselves face CJEU lump-sum and daily penalties [3] |
Bulgaria’s 50% Fine Discount: A Real but Temporary Grace Period
Bulgaria is the closest thing to a textbook “grace period” on this list — and it’s already over. The law amending Bulgaria’s Cybersecurity Act entered force on 13 February 2026 [6], and it built in a genuine transitional mechanism: violations committed before 1 June 2026 were subject to a 50% reduction on the standard fine [5]. From 1 June 2026 onward, the full penalty structure applies — up to €10 million or 2% of global turnover for essential entities (€25,000 floor), up to €7 million or 1.4% for important entities (€12,500 floor) [6], and €500–€5,000 in personal fines for management body members [5]. If your organisation operates in Bulgaria, that window has closed; any violation from June onward is assessed at the full rate, no discount attached. For the full penalty structure and SEGA’s enforcement powers, see our Bulgaria enforcement guide.
Italy’s Grace Period Confusion: Law Date vs Compliance-Clock Date
Italy causes more confusion than any other country on this list, and the mechanism explains why. Legislative Decree No. 138/2024 entered into force on 16 October 2024 — right before the EU deadline, which is why Italy gets cited as an “early transposer” [4]. But that date doesn’t start your compliance clock. Italy’s National Cybersecurity Agency (ACN) didn’t issue its first classification notices — the letters that actually tell an entity it’s in scope as essential or important — until 14 April 2025 [4]. Everything downstream runs from that notification date, not the decree date: basic incident-notification requirements began nine months later, in January 2026, and full implementation of the basic security measures ACN requires is due eighteen months out, by October 2026 [4].
That six-month gap between “the law exists” (October 2024) and “your obligations actually started counting down” (April 2025) is what generates most of the “Italy has a grace period” claims you’ll see online. It isn’t a grace period in any formal sense — it’s simply that Italy’s compliance timeline is anchored to individual notification, not to the law’s publication date. Organisations that assumed their clock started in October 2024 have, if anything, been over-cautious; the ones who assumed it hadn’t started at all by mid-2025 were wrong. Our Italy penalties and enforcement breakdown covers ACN’s minimum fine floors and audit powers in full.
Poland and Germany: Two Different Kinds of Leniency
Poland and Germany both look lenient on the surface, but the mechanisms behind that leniency aren’t remotely alike — treating them as interchangeable is where a lot of readers get tripped up.
Poland’s amended National Cybersecurity System Act entered force in April 2026 and expanded scope roughly a hundredfold, from around 400 regulated entities under the previous framework to an estimated 42,000 [11]. Rather than demanding immediate compliance from that much larger population, Poland built a genuine multi-year runway: registration isn’t due until 3 October 2026, full compliance with the law’s Chapter 3 obligations isn’t required until 3 April 2027, and the first mandatory audits — the point where penalties realistically start biting for entities that were in scope at entry into force — don’t happen until 3 April 2028 [8]. That’s a structural phase-in, not a temporary discount; the fine ceiling (€10 million or 2% of turnover for essential entities) is unchanged, it just isn’t being tested against most entities yet.
Germany took the opposite approach. Its NIS2UmsuCG entered force on 6 December 2025 with a hard registration deadline of 6 March 2026 — no statutory phase-in at all. When only around 11,500 of an estimated 29,500 affected companies had registered by that deadline, the Federal Office for Information Security (BSI) granted a discretionary “goodwill” extension to 31 July 2026 [7]. That’s meaningfully different from Bulgaria’s or Poland’s mechanisms: it’s not written into the law, it’s an enforcement-discretion decision the BSI could revoke, and missing the original March deadline technically remains a fineable administrative offense even during the extension window [7]. Treat it as borrowed time, not a right. Country-specific detail for each is in our Germany and Poland enforcement guides.
Does This Apply to Me? Quick Decision Tree
Use this before assuming any “grace period” claim applies to your organisation:
- Is your sector and entity size within NIS2’s scope (Annex I/II equivalents in your national law)? If unsure, start with the applicability check in our compliance checklist above before worrying about timelines at all.
- Has your country of establishment transposed NIS2 into national law? If not — as with Ireland, Spain, or France at the time of writing — you have no domestic NIS2 obligations yet, but that status can change with the law’s publication, sometimes with immediate effect and no notice period, as the Netherlands’ 15 August 2026 entry into force shows [9].
- If your country has transposed, does its law include a named leniency mechanism (a fine discount, a phase-in period, a registration extension)? Check the matrix above — most countries, including Belgium, do not.
- If a mechanism exists, what specifically does it delay — the fine amount (Bulgaria), the audit date (Poland), or just the registration paperwork (Germany)? None of these delay your Article 21 security obligations themselves.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
FAQ
Is there an official EU-wide NIS2 grace period?
No. Article 41 sets a binding transposition deadline of 17 October 2024 with obligations applying from 18 October 2024, and contains no transitional or reduced-penalty provision [1]. Any leniency comes from individual member states’ own transposing laws, not from the Directive.
My country hasn’t finished transposing NIS2 yet — does that mean I’m off the hook?
For domestic enforcement, yes, until your country’s law takes effect — but that status can end abruptly, as the Netherlands’ single-day gap between law passage and the EC’s CJEU referral shows [3][9]. And your organisation may still face NIS2-equivalent obligations if you operate in, or provide services into, a country that has already transposed.
Does missing a national registration deadline mean an automatic fine?
Not necessarily, but don’t assume otherwise. Germany’s BSI chose discretionary leniency over immediate fines for late registrants, but explicitly kept the underlying offense classification in place [7] — the extension is a supervisory choice, not a legal right.
Will the CJEU referral against Ireland, Spain, France, and the Netherlands affect companies directly?
Not directly — the requested lump sum and daily penalties would be imposed on the Member States, not on individual organisations [3]. The Netherlands’ own law has since entered its final legislative stage and takes effect 15 August 2026 [9]. For the other three, the practical effect on companies is indirect: it signals these countries’ transposing laws, and your compliance deadlines under them, are coming, and the EU has stopped tolerating delay at the state level.
If my country’s law has a phase-in period like Poland’s, can I wait until the audit deadline to start?
That would be a mistake. A multi-year runway to the first audit isn’t the same as a multi-year runway to build a compliance programme from scratch — most organisations under-estimate how long governance, risk assessment, and supply-chain documentation actually take to implement properly.
Sources
- “Article 41, Transposition,” NIS2 Directive (EU) 2022/2555 — nis-2-directive.com
- “Article 34, General conditions for imposing administrative fines,” NIS2 Directive (EU) 2022/2555 — nis2resources.eu
- “Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose the rules on cybersecurity,” European Commission, 8 July 2026 — digital-strategy.ec.europa.eu
- “La normativa,” Agenzia per la Cybersicurezza Nazionale (ACN) — acn.gov.it
- “Bulgaria’s long road to NIS2 is over,” Kinstellar — kinstellar.com
- “Bulgaria implements NIS 2 Directive: key changes to the Cybersecurity Act,” Schoenherr — schoenherr.eu
- “NIS2-Registrierung: BSI-Nachfrist für Unternehmen bis 31. Juli 2026,” LocateRisk — locaterisk.com
- “NIS2 Directive finally implemented in Poland: what businesses need to know,” Addleshaw Goddard — addleshawgoddard.com
- “Dutch Cybersecurity Act enters into force 15 August,” Houthoff — houthoff.com
- “Belgium’s NIS2 Transposition: Key Dates and Authority,” nis-2-directive.com — nis-2-directive.com
- “Poland’s KSC Act Is Now in Force: Why NIS2 Compliance Starts with Infrastructure Automation,” Puppet — puppet.com
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
