A German subsidiary of one of our clients had been in breach of NIS2 for six months. Nobody in the group knew. The programme was running, the steering committee was reporting green, and the board had been briefed twice.
The German registration deadline had passed on 6 March 2026. The entity had not registered, because the group plan had not reached Germany yet, and the group plan had one timeline while Germany had its own.
The question that cannot be answered
They came to us asking whether they were NIS2 compliant. That question has no answer at group level, and this is the part that catches experienced teams.
NIS2 is a directive. It binds nobody. Every entity is bound by the transposition law of the country where it is established, and those laws differ in scope, in dates, in mechanics and in the evidence they want to see. A group in five countries answers the scope question five times.
Here is what that looked like for one ownership chain, as at September 2026.
|
Entity |
Sector |
Position today |
Authority |
The date that binds it |
|
Parent, shared ICT services (IE) |
Annex I, ICT service management |
Undetermined, no law in force |
NCSC Ireland, designated |
Enactment of the National Cyber Security Bill |
|
Food production (BE) |
Annex II, food |
Important entity |
CCB |
Registered since March 2025, CyFun evidence track running |
|
Machinery manufacturing (DE) |
Annex II, manufacturing |
Important entity |
BSI |
Registration expired 6 March 2026 |
|
Courier and warehousing (IT) |
Annex II, postal and courier |
Important entity |
ACN |
Basic security measures, 31 October 2026 |
|
Food distribution (FR) |
Annex II, food |
Undetermined, no law in force |
ANSSI, designated |
Promulgation of the loi resilience |
One group. Five authorities. Five registration mechanics, of which one expired, one runs in an annual window from 1 January to 28 February, one had its deadline pass in March 2025 and two do not exist yet.
Does one registration cover the group?
That was their first question, and it is the right one. Mostly, no.
The default is blunt. You answer in every country where you have a legal entity. A group established in five countries is established five times, and every entity that crosses the threshold in a covered sector gets its own registration, its own regulator and its own dates. Manufacturing, food, courier, energy, transport, health, water, all of it works that way. Four of the five entities here.
There is one exception and it is narrower than people hope. A short list of digital businesses answers in a single country: cloud and data centre providers, content delivery networks, DNS and domain name businesses, managed service and managed security providers, online marketplaces, search engines and social platforms. Those companies are supervised where their main establishment sits, wherever else in the EU they operate. One regulator, one registration, one national law, even if they serve clients in all twenty-seven.
Main establishment is not where the sign is on the building. It is where the decisions about managing cyber risk are actually taken. If that cannot be pinned down, it is where the security operations run, and failing that where most of the EU staff sit. ENISA keeps the register of these companies.
Two things catch groups here. Running IT for yourself is not a managed service, but a service company running IT for legally separate sisters usually is, because the sisters are other parties. And if the parent does that work itself rather than through a subsidiary, the whole parent entity is caught, not just its IT department. A few member states allow an exemption where the service company is sufficiently independent, so the position is worth writing down and confirming locally rather than assuming either way.
One company in the group qualified, the Irish shared IT services company, as a managed service provider. Its one country is Ireland, because that is where the decisions get made. Ireland has no law, no portal and no reporting route. So the only entity in the group entitled to a single point of supervision is the one nobody can supervise yet, while its four regulated sisters push supplier requirements at it every quarter. We wrote the position down, built against the framework Ireland has already pointed at, and set the entity up to register inside the three month window the General Scheme provides once the Bill commences.
The national single point of contact is not the answer either. That is a liaison desk between authorities, not a place where a group files once and is finished.
Where the law is in force, the calendar is not yours
Germany is the case that hurts. The rewritten BSIG entered into force on 6 December 2025 with no transition period at all, taking the population under BSI supervision from roughly 4,500 entities to roughly 29,500. Obligations applied from day one and registration was due within three months. By the deadline, only about 11,500 of those 29,500 entities had registered, which is why the BSI communicated a catch-up window to 31 July 2026. Our client missed both. A group programme sequenced by country size would have reached Germany in Q4.
Italy moves on a different logic again. The clocks do not start with the law. They start when ACN notifies the entity of its inclusion in the national list: incident reporting at nine months, basic security measures at eighteen, with 31 October 2026 as the live deadline. Registration itself is an annual event, and the categorised list of activities and services is filed between 1 May and 30 June each year. Our client had registered in 2025 and closed the file.
Belgium was the entity in the best shape, for a structural reason rather than a cultural one. The law has been in force since 18 October 2024, registration was due by 18 March 2025, and the CCB gave everyone a usable route to evidence in CyFun, with a presumption of conformity attached. When the regulator tells you what good looks like, teams execute.
Where the law is late, the obligation is not
France and Ireland are both waiting, and both were being treated as out of scope internally. Neither is.
In France the loi resilience was presented in October 2024, adopted by the Senat in March 2025, cleared the special committee of the Assemblee nationale in September 2025, and then stopped. It missed the July 2026 extraordinary session, and as this is written no date has been set for the chamber. The Commission referred France to the Court of Justice in July 2026 and asked for financial penalties. ANSSI expects around 15,000 entities in scope against roughly 500 under NIS1. But the content is not unknown. ANSSI put out the Referentiel Cyber France in March 2026, a working version that binds nobody yet, and MonEspaceNIS2 has been running as a preparatory service. The sectors, the thresholds and the shape of the measures are public. What is open is the promulgation date and the final decrees.
Ireland is in the same legislative position, referred to the Court of Justice in July 2026 alongside France and Spain, with no live registration or reporting portal. Its NCSC has nonetheless published board level guidance, and both that guidance and the General Scheme of the Bill point to CyFun, the Belgian framework, as a reference standard. So does the Irish parent's exposure through its sister companies: it supplies ICT services to four regulated entities, and Article 21 pushes supplier requirements down the chain whether or not Ireland has legislated.
Two countries without a law. Two countries where the work can start today, and where waiting buys nothing.
Agility is the pillar
Three of these five positions changed in the twelve months before the engagement. Two will change again. Germany went from no law to full obligations overnight. Italy's clocks depend on a letter. France and Ireland depend on a parliament and a court.
Under a directive, GRC is not a matter of completeness or of certainty. It is a matter of agility. Build on what is already knowable, adjust when each text lands, and keep the structure stable enough that an adjustment costs days rather than another programme.
One framework, local flavours
That is only possible with a single framework across the group, carrying local flavours.
Start at the parent and build the foundation every entity needs regardless of country: management accountability, risk management, asset and supplier inventory, detection and response, continuity, access control, training. That is the common floor, and it is where most of the work lives.
Then extend outward only where a national law adds something real: the registration mechanics, the notification route and the local definition of significant, the evidence format the authority expects, and the local dates. Where two requirements differ in level, take the strictest and apply it everywhere. One standard, executed once, that satisfies every regulator in the perimeter.
The client's own evidence makes the point. Belgium runs on CyFun. Ireland's draft framework points at CyFun. That is two of five countries on the same reference, before a single control is written. The baseline travels. The dates and the paperwork do not.
What changed
Three entities classified as important today, two awaiting a law and already building. One German registration closed with a dated record of when the gap was found. One baseline, four country annexes, one accountable name per entity for registration, notification and local evidence. And a register, one row per legal entity, reviewed every quarter.
Where to start
Most groups we meet are not short of controls. They are short of clarity. They cannot say how many regulated entities they have, which law applies to each, or which clock is already running.
|
If that sounds familiar Our team has done this before and knows exactly what to do. This is not about adding another control to your framework. It is about knowing where you stand, in every country you operate in, before a regulator tells you. |
