Five member states have not yet transposed the NIS2 directive, which aims to establish a high common level of cybersecurity across the EU.
The deadline for member states to adopt national legislation transposing the directive was 17 October 2024.

Of the five EU countries, four (France, Ireland, Luxembourg and Netherlands) have already submitted legislation to parliament. Spain is the only country which has not yet submitted a draft transposition law to parliament.
Scope
Region: Europe
Countries covered: 27 EU member states
Policy area: Cybersecurity, digital economy
Last updated: March 2026
For more information on the benchmark and Cullen International's complete NIS2 coverage, please click on “Access the full content” - or on “Request Access”, in case you are not subscribed to our European Digital Economy service.
more news
04 August 26
Cross-border IoT data transfer rules across seven APAC markets
This new Cullen International benchmark analyses whether global IoT and M2M operating models can centralise data and platform functions outside the country where connected devices operate. It covers Australia, China, India, Japan, New Zealand, Singapore and South Korea, assessing how data protection, telecommunications, cybersecurity and sector-specific regulation affect the feasibility of offshore operating models.
27 July 26
Spectrum policy adapts to support new network models in the Americas
Cullen International's latest Americas Spectrum Benchmarks compare regulatory approaches across the Americas for a range of topics, including 5G deployment, spectrum assignments, spectrum refarming and private networks.
27 July 26
Most European countries require 10 Mbps for adequate fixed broadband
Cullen International's latest European benchmark on universal service obligation investigates the minimum download speed required in 33 countries.