# EU NIS2 cybersecurity implementation

> Live situation record from CLSTR: https://clstr.news/situations/eu-nis2-cybersecurity-implementation
> Updated: 2026-08-23T16:37:42.000Z. Sources: 8. Developments: 3.

In late July 2026, Greece formally incorporated the EU’s NIS2 Directive into national law (Law 5160/2024), creating a broad framework that obliges entities in critical sectors—such as energy, transport, finance, health and public administration—to register with the National Cybersecurity Authority, adopt mandatory risk-management measures and integrate cybersecurity into overall business resilience.

A few days later, the European Union Agency for Cybersecurity (ENISA) released sector-specific procurement guidelines for hospitals, stressing the need to embed security requirements throughout the acquisition process. The guidance cited rising ransomware threats to healthcare, noting low levels of dedicated defence programs and staff awareness. In parallel, Italy’s National Cybersecurity Agency (ACN) updated its FAQ on NIS2, adding clarifications that board members of essential and important entities must approve and oversee cybersecurity measures, reflecting the directive’s governance requirements.

By late August 2026, Italy’s ACN expanded its enforcement strategy to focus on systemic ecosystem resilience and supply chain risks. Under Determination n. 127437/2026, organizations within the NIS2 perimeter must now provide a structured list of their ‘relevant NIS suppliers’ to help the ACN map interdependencies and identify critical nodes in the national supply chain. Furthermore, updated ACN guidance on monitoring, supervision, and enforcement (MVE) has shifted the regulatory focus toward the practical demonstration of compliance during oversight, rather than the mere formal adoption of security measures.

## Claims

- ENISA released new guidelines for cybersecurity procurement in hospitals and health service providers. (single source)
- The guidelines emphasize integrating cybersecurity throughout the supply chain and procurement lifecycle. (single source)
- ENISA’s Threat Landscape 2024 reports the healthcare sector accounts for 8 % of ransomware incidents. (single source)
- Only 27 % of healthcare organisations have a dedicated ransomware‑defence programme and 40 % lack staff security‑awareness training. (single source)
- The Italian National Cybersecurity Agency (ACN) updated its FAQ on NIS2 responsibilities on 23 July 2026. (single source)
- The updated FAQ adds three new clarifications (FAQ ODA 10, ODA 11, ODA 12). (single source)
- NIS2 requires board members of essential and important entities to approve, supervise, and train on cybersecurity risk‑management measures. (single source)
- Italy’s implementing decree (d.lgs. 138/2024) incorporates NIS2 governance responsibilities into national law. (single source)

## Timeline

### 2026-08-23: Italy's ACN implements new NIS2 cybersecurity compliance measures

Italy's National Cybersecurity Agency is implementing NIS2 Directive measures, focusing on supply chain risk mapping and new guidelines for monitoring, supervision, and enforcement compliance.

3 sources. https://clstr.news/cluster/italys-acn-implements-new-nis2-cybersecurity-compliance-measures

### 2026-07-28: EU ENISA Issues New Hospital Cybersecurity Procurement Guidelines Under NIS2

ENISA rolled out new hospital procurement cybersecurity guidelines, noting healthcare's 8 % share of ransomware hits, while Italy’s ACN updated NIS2 FAQ clarifying board‑level security duties.

4 sources. https://clstr.news/cluster/eu-cybersecurity-guidelines-revised-for-hospitals-and-corporate-governance

### 2026-07-25: Greece Adopts NIS2 Cybersecurity Directive, Raising Business Resilience Standards

Greece has enacted the EU NIS2 Directive via Law 5160/2024, broadening cyber‑security obligations for many sectors and mandating registration with the National Cybersecurity Authority.

2 sources. https://clstr.news/cluster/greece-adopts-nis2-cybersecurity-directive-raising-business-resilience-standards

---
Cite as: EU NIS2 cybersecurity implementation. CLSTR, https://clstr.news/situations/eu-nis2-cybersecurity-implementation
