INTERACTIVE MAP

EU Anti-Corruption Directive: Implementation Status by Country

Follow national implementation across all 27 EU Member States, updated as laws are adopted

About This Tracker

Directive (EU) 2026/1021 is the EU’s first comprehensive anti-corruption law, harmonising criminal standards across all 27 member states for the first time. This tracker follows national implementation country by country, updated as legislation is adopted.

Please note: This tracker provides factual legislative information only and does not constitute legal advice. Contact Liberius for jurisdiction-specific guidance.

Denmark: Not bound by this directive. Framework Decision 2003/568/JHA continues to apply to Denmark.

AT A GLANCE
Published:

11 May 2026
In Force:
31 May 2026
Transposition Deadline:
1 June 2028 (core obligations)
1 June 2029 (national anti-corruption strategies)
Scope:
All public and private sector organizations operating in the EU, including non-EU multinationals. No minimum size threshold.

EU Member State Implementation Map

Click any country to view its current ACD implementation status, key legislative details, and relevant regulatory information.

 

No implementation yet
Legislative process underway
Implementing law adopted
Not bound by this directive

What Is the EU Anti-Corruption Directive?

For the first time, the EU has established harmonised criminal anti-corruption standards across all 27 member states.

Directive (EU) 2026/1021 covers bribery in the public and private sectors, trading in influence, misappropriation, obstruction of justice, and enrichment from corruption offences. This applies to public institutions and private organisations alike, with no minimum size threshold, and extends to non-EU multinationals with operations or a nexus in the EU.

Transposition will not be uniform, either in timing or in substance. Since the directive sets minimum requirements only, Member States may choose to impose higher standards when implementing the directive into national law. For organizations operating across multiple EU jurisdictions, that divergence has direct implications for how compliance programs are designed and evidenced.

Definitions, enforcement structures, penalty levels, and the treatment of mitigating factors will vary by country.

Mitratech and Liberius, a Brussels-based law firm specializing in anti-bribery and anti-corruption, are jointly tracking the legislative process in every EU member state. This page is updated as national implementing legislation is published and adopted.

What Compliance Teams Need to Know

Broad scope

The directive applies to all organizations operating in the EU, across both the public and private sectors, regardless of size or nationality. Non-EU multinationals with EU operations are in scope.

GRC coverage

Criminal and personal liability

Comprehensive offense definitions

Significant financial exposure

Compliance programs as a statutory mitigating factor

Personal Liability. Global Fines. One Platform Built for Both.

See how Mitratech connects EU Anti-Corruption Directive obligation.

How Mitratech Supports EU Anti-Corruption Compliance

  • Syntrio icon

    Ethics Hotline and Whistleblowing

    Article 25 of the directive explicitly requires Member States to ensure the EU Whistleblowing Directive (2019/1937) applies to corruption reporting. Organizations need a secure, anonymous channel for employees and third parties to raise concerns, and the ability to evidence that channel to regulators. The Mitratech Hotline is designed for exactly that purpose.

    Explore the Mitratech Hotline
  • Build a Culture of Accountability

    Ethics and Anti-Corruption Compliance Training

    Article 16 allows effective internal controls, ethics awareness and compliance programs to be treated as a mitigating circumstance. Mitratech Compliance Training provides trackable, attestable ABAC training content, giving compliance teams the documented evidence that supports that position.

    Explore Mitratech Compliance Training
  • Automate Policy Management icon

    Policy Management

    Anti-corruption policies are most effective when employees can locate them, read them, and confirm their understanding. Mitratech Policy Management supports the full policy lifecycle, from drafting and distribution through to attestation and audit trail.

    Explore Mitratech Policy Management
  • Prevalent icon

    Third-Party Risk Management

    The directive extends liability to conduct by third parties acting on an organization’s behalf. Mitratech Third-Party Risk Management provides AI-supported vendor risk assessment and continuous monitoring, with documented due diligence at every stage of the third-party lifecycle.

    Explore Mitratech Third-Party Risk Management
  • A four-point floral node icon representing the integration of risk management data into a holistic enterprise view.

    Risk Assessment and Regulatory Intelligence

    Article 20(5) requires Member States to assess corruption risk by sector and occupation. Recital 5 separately encourages Member States to promote robust compliance mechanisms within private companies. Mitratech Enterprise Risk Management provides a regulatory content library covering the directive’s requirements and control testing, giving compliance teams a framework to assess and evidence program effectiveness.

    Explore Mitratech Enterprise Risk Management
  • Risk management icon

    Global GRC Platform

    The EU Anti-Corruption Directive creates obligations that span ethics, risk, policy, and third-party programs simultaneously. The Mitratech Global GRC Platform connects those programs through intelligence, giving compliance teams a single point of access to see how risks relate, act on what matters, and evidence their position to regulators.

    Explore Mitratech Global GRC Platform

EU Anti-Corruption Directive: Frequently Asked Questions

When does the EU Anti-Corruption Directive take effect?

Directive (EU) 2026/1021 was published in the Official Journal of the European Union on 11 May 2026 and entered into force on 31 May 2026. Member States have until 1 June 2028 to transpose core obligations into national law, with a longer deadline of 1 June 2029 for national anti-corruption strategies and risk assessment obligations.

Which organisations does the EU Anti-Corruption Directive impact?

The directive applies to both the public and private sectors, covering conduct involving EU institutions, member state authorities, and private economic activity. There is no minimum company size threshold. Non-EU multinationals with operations or a meaningful commercial nexus in the EU are also in scope. Organisations should assess their exposure regardless of where they are headquartered. Denmark is not bound by this directive.

What offenses does the directive cover?

The directive requires Member States to criminalize seven categories of conduct: bribery in the public sector, bribery in the private sector, trading in influence, misappropriation, unlawful exercise of public functions, obstruction of justice, and enrichment from corruption offenses. Member States must also criminalize concealment of property derived from these offenses. The offenses apply whether or not they involve cross-border elements.

What are the EU Anti-Corruption Directive penalties for organisations?

The directive establishes two tiers of fines for legal persons. For the most serious offenses, including bribery in the public and private sectors and misappropriation, fines may reach 5% of total worldwide annual turnover, or €40 million, whichever is higher. For trading in influence, obstruction of justice, and enrichment from corruption offenses, the maximum is 3% of total worldwide annual turnover, or €24 million. Member States may set higher penalties when transposing the directive into national law

Can individuals face criminal liability under the directive?

Yes, the directive requires Member States to provide for prison sentences for individuals convicted of corruption offenses, ranging from three years for less serious offenses to five years for the most serious. Member States may impose higher penalties. Personal liability may extend to employees, managers, and senior executives where inadequate supervision contributed to an offense.

Does the directive apply to companies headquartered outside the EU?

Yes. The directive applies regardless of where an organization is headquartered, provided conduct affects EU institutions, member state authorities, or entities operating in the EU. Companies with EU operations, EU-based subsidiaries, or significant EU customer and supplier relationships should treat the directive as applicable to them.

Will every member state implement the EU Anti-Corruption Directive in the same way?

No. The directive sets minimum standards, and Member States are free to go further in a number of areas. Definitions, enforcement structures, penalty levels, and the treatment of mitigating factors will vary by country.

Does the EU Anti-Corruption Directive require compliance training?

The directive does not impose a formal training obligation on private sector organizations. However, Article 13(2) establishes corporate liability where a lack of supervision made possible the commission of an offense by a subordinate, and Article 16(c) recognizes effective compliance programs and ethics awareness as a mitigating circumstance that directly reduces penalties. Training is a primary means of evidencing both. Organizations that invest in structured, evidence-based compliance programs are in a materially stronger legal position.

How does the directive interact with existing anti-corruption laws?

The directive replaces two earlier EU instruments: Council Framework Decision 2003/568/JHA on corruption in the private sector, and the 1997 Convention on corruption involving EU officials. It also reinforces the EU Whistleblowing Directive (2019/1937), which Article 25 explicitly incorporates. Organizations with existing anti-bribery programs built around the UK Bribery Act, US FCPA, or existing national anti-corruption legislation in their home Member States should assess how the EU directive affects their obligations across Member States.

What should compliance teams do now about the EU Anti-Corruption Directive?

Start with a structured gap assessment of your current anti-bribery and anti-corruption program against the directive’s seven offense categories, third-party risk procedures, and internal reporting channels. Documenting your compliance program is worthwhile at this stage, given that Article 16 creates a direct incentive to do so. Monitoring national transpositions in the Member States where your organization has the greatest exposure will be important as the map tracker is updated.

How does the EU Anti-Corruption Directive affect third-party risk management?

The directive’s liability framework extends to conduct carried out by third parties acting on an organization’s behalf. Where a business partner, agent, or supplier commits a corruption offence in connection with your organization’s interests, your organization may face liability. Documented third-party due diligence, covering assessment, monitoring, and evidence of both, is a direct compliance requirement under this framework.

Where can I get legal advice on how the EU Anti-Corruption Directive affects my organization?

The map tracker provides factual legislative information and does not constitute legal advice. Liberius is a Brussels-based law firm specializing in anti-bribery and anti-corruption, with deep expertise in EU regulatory frameworks. Their specialists advise organizations across the EU on how to prepare for and respond to the directive across multiple jurisdictions.