< Back to situations

We’ll email you as it develops, and you can follow the whole thread from day one.

[SITUATION] · [ACTIVE]

2 clusters · 6 sources · 3 days · First seen · Last updated

Categories: TECHNOLOGY

EU NIS2 cybersecurity implementation

Entities: NIS2 Directive · Italian Government · European Union · Law 5160/2024 · Agenzia per la Cybersicurezza Nazionale (ACN)

Overview

In late July 2026, Greece formally incorporated the EU’s NIS2 Directive into national law (Law 5160/2024), creating a broad framework that obliges entities in critical sectors—such as energy, transport, finance, health and public administration—to register with the National Cybersecurity Authority, adopt mandatory risk‑management measures and integrate cybersecurity into overall business resilience.

A few days later, the European Union Agency for Cybersecurity (ENISA) released sector‑specific procurement guidelines for hospitals, stressing the need to embed security requirements throughout the acquisition process. The guidance cited rising ransomware threats to healthcare, noting low levels of dedicated defence programs and staff awareness. In parallel, Italy’s National Cybersecurity Agency (ACN) updated its FAQ on NIS2, adding clarifications that board members of essential and important entities must approve and oversee cybersecurity measures, reflecting the directive’s governance requirements.

Together, these developments show the EU’s move from national legislative transposition to the rollout of practical, sector‑focused tools and clarifications aimed at achieving consistent cyber‑risk management across member states.

Claims

What the coverage asserts, and how well corroborated each claim is across sources.

Timeline

  1. 3 days ago

    [TECHNOLOGY] 4 sources
    EU ENISA Issues New Hospital Cybersecurity Procurement Guidelines Under NIS2

    ENISA rolled out new hospital procurement cybersecurity guidelines, noting healthcare's 8 % share of ransomware hits, while Italy’s ACN updated NIS2 FAQ clarifying board‑level security duties.

  2. 6 days ago

    [TECHNOLOGY] 2 sources
    Greece Adopts NIS2 Cybersecurity Directive, Raising Business Resilience Standards

    Greece has enacted the EU NIS2 Directive via Law 5160/2024, broadening cyber‑security obligations for many sectors and mandating registration with the National Cybersecurity Authority.

Sources

banks.com.gr · campaniadih.it · cybersecitalia.it · dalealbo.cl · diritto.it · mononews.gr

This summary has been updated 1 time: see revision history