< Back to situation

[REVISION HISTORY]

EU NIS2 cybersecurity implementation

Updated 2 times since CLSTR started tracking revisions of this situation.

What changed

2026-07-29 08:47 UTC → 2026-08-24 10:23 UTC · added removed

In late July 2026, Greece formally incorporated the EU’s NIS2 Directive into national law (Law 5160/2024), creating a broad framework that obliges entities in critical sectors—such as energy, transport, finance, health and public administration—to register with the National Cybersecurity Authority, adopt mandatory risk‑management risk-management measures and integrate cybersecurity into overall business resilience. A few days later, the European Union Agency for Cybersecurity (ENISA) released sector‑specific sector-specific procurement guidelines for hospitals, stressing the need to embed security requirements throughout the acquisition process. The guidance cited rising ransomware threats to healthcare, noting low levels of dedicated defence programs and staff awareness. In parallel, Italy’s National Cybersecurity Agency (ACN) updated its FAQ on NIS2, adding clarifications that board members of essential and important entities must approve and oversee cybersecurity measures, reflecting the directive’s governance requirements. Together, these developments show the EU’s move from national legislative transposition By late August 2026, Italy’s ACN expanded its enforcement strategy to focus on systemic ecosystem resilience and supply chain risks. Under Determination n. 127437/2026, organizations within the rollout NIS2 perimeter must now provide a structured list of practical, sector‑focused tools their ‘relevant NIS suppliers’ to help the ACN map interdependencies and clarifications aimed at achieving consistent cyber‑risk management across member states. identify critical nodes in the national supply chain. Furthermore, updated ACN guidance on monitoring, supervision, and enforcement (MVE) has shifted the regulatory focus toward the practical demonstration of compliance during oversight, rather than the mere formal adoption of security measures.

Versions

  1. 2026-08-24 10:23 UTC EU NIS2 cybersecurity implementation
  2. 2026-07-29 08:47 UTC EU NIS2 cybersecurity implementation
  3. 2026-07-29 08:47 UTC EU NIS2 Cybersecurity Implementation

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.