NIS2 in Europe: One Directive, Many National Routes to Proof

An IDC InfoBrief sponsored by Microsoft, covering 2,000 European organizations in more than 20 markets [1], reports a finding that is easy to miss: organizations operating in several member states struggle to keep up with the specific requirements of each country. The security measures themselves are not the main issue. The question is how to demonstrate them to each country.
The requirements come from the same directive. The route to proof is national.
A directive only creates obligations once it becomes national law
NIS2 sets a common framework: risk management, incident handling, access control, supply chain security [2]. It does not bind companies directly. National transposition is what determines which authority is responsible, how entities register, and what that authority will look at as evidence. Those national laws arrived at very different times, and in some member states they are still arriving.
There is also a layer in between. For certain digital providers, such as cloud services, data centers and managed service providers, the European Commission published Implementing Regulation (EU) 2024/2690 [3], which addresses technical and methodological requirements for those categories at EU level. The landscape is therefore not simply NIS2 plus 27 national laws.
Four countries stand at four different points
Public trackers and national sources put them at very different stages.
Greece. The RISI transposition tracker records Greece as transposing NIS2 through Law 5160/2024, in force from 2024-11-28, around six weeks after the European deadline, with the National Cybersecurity Authority acting at once as competent authority, single point of contact, CSIRT and crisis management authority [4]. That is an unusually centralized arrangement compared with most member states.
Germany. The same tracker puts the German NIS2UmsuCG in December 2025 [5].
Austria. The NISG 2026 was published in the Federal Law Gazette in 2025 [6]. ISPA's guide to the law sets out the sequence it expects: the regime applies from 2026-10-01, registration by the end of 2026, the self-declaration by 2027-10-01, and from 2028-10-01 the authority can ask essential entities to demonstrate that their measures are implemented, with an audit report from an independent body possible from 2030 at the earliest [7].
Spain. Transposition is still in progress. The European Commission announced on 2026-07-08 that it had referred Spain, together with Ireland, France and the Netherlands, to the Court of Justice of the EU over incomplete transposition, and asked for financial penalties [8]. Spain also shows how fluid a route to proof can be: the National Cryptologic Centre published guideline CCN-STIC 892 in 2024, including a mapping between NIS2 and the national security framework ENS [9], then withdrew that version in March 2025, saying a new one is intended to reflect Implementing Regulation (EU) 2024/2690 as well [10].
Each of these is a snapshot of a moving picture, and the dates are the ones the cited sources gave at the time of writing. Anyone acting on them should confirm the current position with the competent authority.
Each country decides which proof counts
Belgium and Ireland show how differently the same framework can land.
The Centre for Cybersecurity Belgium's FAQ describes a presumption of conformity that can arise through certain assessments under the CyberFundamentals Framework (CyFun), or through ISO/IEC 27001, where the conditions are met and in particular where the scope is appropriate [11].
Ireland's National Cyber Security Centre presents CyFun as a structured way to organize and evidence security measures, and states plainly that it is not a statutory presumption of conformity. Whether NIS2 is met is decided by the competent national authority [12].
Same framework, two different standings. Which standards, certifications or mappings an authority actually recognizes is a question to put to that authority, and not one to settle from a European overview.
Much of the evidence emerges regardless of country
Across these regimes, organizations are generally asked to show that access is controlled, that changes are made in a traceable way, and that incidents are handled in an orderly manner. That calls for concrete evidence: traceable changes to systems and configurations, the granting of permissions, the course of an incident. This data is already created in day-to-day operations.
In many organizations, part of this happens in Jira. MetaFrazo continuously records these events from the moment of installation and makes visible what the data shows. This has three effects:
-
A shared evidence base for several routes to proof. Where the same events are relevant to different requirements, they do not have to be collected again for each country. Mapping and assessment may differ.
-
Description and actual execution side by side. A documented process describes what should happen. An event trail can additionally show what actually happened.
-
Answers from data instead of memory. The question of who approved a change and when can be answered from the history.

A traceable change history shows who made which change and when. Depending on the national model, such evidence can form part of the proof.
MetaFrazo does not replace an ISMS, a mapping to national requirements or an assessment by auditors. Whether a control is effective is judged by the audit, not by the recording. MetaFrazo works exclusively with Jira Cloud, and recording begins at installation. What happened before is not available. Events are stored and processed outside Atlassian in the EU, without the customer having to set up an export process.
What organizations should clarify now
-
Clarify scope. Which national NIS2 regime applies in which member states, and to which companies, services and locations?
-
Clarify routes to proof. Which standards, certifications, mappings or audit procedures does each competent authority recognize?
-
Secure evidence early. Which evidence is created in operations anyway, and how can it be secured continuously and traceably?
Introducing a control and being able to show later that it worked are two different pieces of work. The second one depends on what was recorded at the time.
If you want that record running before the question arrives: MetaFrazo on the Atlassian Marketplace
Sources
[1] IDC InfoBrief, sponsored by Microsoft, "Preparing for NIS2 and Beyond: The Next Phase of Cyber Resilience in EMEA", January 2026, Executive Summary https://info.microsoft.com/rs/157-GQE-382/images/EN-CNTNT-Whitepaper-NIS2andBeyond-SRGCM15862.pdf
[2] European Commission, NIS2 Directive https://digital-strategy.ec.europa.eu/en/policies/nis2-directive
[3] Commission Implementing Regulation (EU) 2024/2690, EUR Lex https://eur-lex.europa.eu/eli/reg_impl/2024/2690/oj
[4] RISI NIS2 transposition tracker, Greece https://www.risidata.com/regulations/nis2/countries/gr
[5] RISI NIS2 transposition tracker, country overview https://www.risidata.com/regulations/nis2/countries
[6] NISG 2026, Federal Law Gazette I No. 94/2025, RIS https://www.ris.bka.gv.at/Dokumente/BgblAuth/BGBLA_2025_I_94/BGBLA_2025_I_94.html
[7] ISPA, NISG 2026 guide for internet service providers, key deadlines (German) https://hxs.at/assets/Uploads/news/ISPA-Leitfaden-NISG_2026.pdf
[8] European Commission, press release IP/26/1499, 8 July 2026 https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1499
[9] CCN-CERT, publication of CCN-STIC 892, April 2024 (Spanish) https://www.ccn-cert.cni.es/es/seguridad-al-dia/novedades-ccn-cert/12945-el-ccn-publica-un-nuevo-perfil-de-cumplimiento-especifico-para-organizaciones-en-el-ambito-de-aplicacion-de-la-directiva-nis2.html
[10] CCN-CERT, status of guideline CCN-STIC 892, March 2025 (Spanish) https://www.ccn-cert.cni.es/es/seguridad-al-dia/novedades-ccn-cert/13062-informacion-sobre-el-estado-de-la-guia-ccn-stic-892-perfil-de-cumplimiento-especifico-para-entidades-en-el-ambito-de-aplicacion-del-reglamento-de-ejecucion-ue-2024-2690.html
[11] Centre for Cybersecurity Belgium, FAQ NIS2 in Belgium, version 2.1, January 2026 https://ccb.belgium.be/open-media/780/download
[12] NCSC Ireland, Cyber Fundamentals https://ncsc.gov.ie/CyFun/
Rate this post
Related articles

5 Questions in the Atlassian Universe with Martin Runge
Martin Runge, Head of Atlassian Practice at XALT, on how long Jira actually remembers who changed what, why backup is more the customer's job than most Cloud teams realize, and what separates a logged change from an authorized one.
2026-09-10

Traceability is not a Jira problem
Four security dimensions in Spain's ENS can be bought and configured. Traceability cannot. Why audit evidence has to be created while the work happens, and what that means for Jira.
2026-09-29

Jira Audit Log Retention: How Long Jira Cloud Actually Keeps Your History
The site audit log holds up to six months, the organization log 180 days, automation logs 90. Audits ask about periods that are longer than all three. Why evidence has to exist before anyone asks for it, and what continuous history changes.
2026-09-14

