< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

3 clusters · 8 sources · 29 days · First seen · Last updated

EU NIS2 cybersecurity implementation

Overview

In late July 2026, Greece formally incorporated the EU’s NIS2 Directive into national law (Law 5160/2024), creating a broad framework that obliges entities in critical sectors—such as energy, transport, finance, health and public administration—to register with the National Cybersecurity Authority, adopt mandatory risk-management measures and integrate cybersecurity into overall business resilience.

A few days later, the European Union Agency for Cybersecurity (ENISA) released sector-specific procurement guidelines for hospitals, stressing the need to embed security requirements throughout the acquisition process. The guidance cited rising ransomware threats to healthcare, noting low levels of dedicated defence programs and staff awareness. In parallel, Italy’s National Cybersecurity Agency (ACN) updated its FAQ on NIS2, adding clarifications that board members of essential and important entities must approve and oversee cybersecurity measures, reflecting the directive’s governance requirements.

By late August 2026, Italy’s ACN expanded its enforcement strategy to focus on systemic ecosystem resilience and supply chain risks. Under Determination n. 127437/2026, organizations within the NIS2 perimeter must now provide a structured list of their ‘relevant NIS suppliers’ to help the ACN map interdependencies and identify critical nodes in the national supply chain. Furthermore, updated ACN guidance on monitoring, supervision, and enforcement (MVE) has shifted the regulatory focus toward the practical demonstration of compliance during oversight, rather than the mere formal adoption of security measures.

Entities

NIS2 Directive · Italian Government · European Union · Law 5160/2024 · Agenzia per la Cybersicurezza Nazionale (ACN)

Claims

What the coverage asserts, and how many sources carry each claim.

Timeline

  1. 22 days ago

    [TECHNOLOGY] 3 sources
    Italy's ACN implements new NIS2 cybersecurity compliance measures

    Italy's National Cybersecurity Agency is implementing NIS2 Directive measures, focusing on supply chain risk mapping and new guidelines for monitoring, supervision, and enforcement compliance.

  2. about 2 months ago

    [TECHNOLOGY] 4 sources
    EU ENISA Issues New Hospital Cybersecurity Procurement Guidelines Under NIS2

    ENISA rolled out new hospital procurement cybersecurity guidelines, noting healthcare's 8 % share of ransomware hits, while Italy’s ACN updated NIS2 FAQ clarifying board‑level security duties.

  3. about 2 months ago

    [TECHNOLOGY] 2 sources
    Greece Adopts NIS2 Cybersecurity Directive, Raising Business Resilience Standards

    Greece has enacted the EU NIS2 Directive via Law 5160/2024, broadening cyber‑security obligations for many sectors and mandating registration with the National Cybersecurity Authority.

Sources

banks.com.gr · campaniadih.it · cybersecitalia.it · dalealbo.cl · diritto.it · mononews.gr · protezionedatipersonali.it · vianova.it

This summary has been updated 2 times: see revision history