started · updated
NIS2 Directive implementation drives cybersecurity changes across Europe
The implementation of the European Union’s NIS2 Directive is significantly altering cybersecurity requirements for organizations across Europe. In Poland, new regulations effective April 2026 are expected to impact approximately 38,000 entities, including 27,000 public institutions, requiring them to implement information security management systems and report major incidents to CSIRT teams.
In Austria, the NISG 2026 law, set to take effect on October 1, 2026, mandates minimum cybersecurity standards for medium and large companies in 18 sectors, such as energy and water. While municipalities are generally exempt from the “public administration” sector, they may still fall under regulation if they operate critical services like water supply or digital infrastructure.
Germany is facing challenges with compliance; recent data indicates that out of an estimated 30,000 affected institutions, approximately 12,000 missed the implementation deadline. This has led to increased pressure from authorities to demonstrate operational resilience, specifically regarding asset visibility, change tracking, and the ability to rapidly restore production systems following an attack.
Entities
European Union · Federal Office for Information Security · Ministry of Digital Affairs · NIS2 Directive