< Back to situation

[REVISION HISTORY]

EU NIS2 cybersecurity implementation

Updated 1 time since CLSTR started tracking revisions of this situation.

What changed

2026-07-29 08:47 UTC → 2026-07-29 08:47 UTC · added removed

EU NIS2 Cybersecurity Implementation cybersecurity implementation

The European Union’s NIS2 Directive is being operationalized across member states and key sectors. In late July 2026, Greece formally incorporated the directive EU’s NIS2 Directive into national law, establishing law (Law 5160/2024), creating a registration regime for broad framework that obliges entities exceeding 50 employees or €10 million in turnover and assigning oversight to its National Cybersecurity Authority. The measure broadens mandatory cyber‑risk management to sectors such critical sectors—such as energy, transport, finance, health, water, digital infrastructure health and public administration. Soon after, administration—to register with the EU’s ENISA agency National Cybersecurity Authority, adopt mandatory risk‑management measures and integrate cybersecurity into overall business resilience. A few days later, the European Union Agency for Cybersecurity (ENISA) released updated sector‑specific procurement guidelines targeting hospitals and health‑service providers, emphasizing for hospitals, stressing the integration of cybersecurity need to embed security requirements throughout supply‑chain lifecycles. Concurrently, the acquisition process. The guidance cited rising ransomware threats to healthcare, noting low levels of dedicated defence programs and staff awareness. In parallel, Italy’s National Cybersecurity Agency clarified (ACN) updated its FAQ on NIS2, adding clarifications that board members of essential and senior‑management responsibilities under NIS2, reinforcing corporate‑governance important entities must approve and oversee cybersecurity measures, reflecting the directive’s governance requirements. These steps aim Together, these developments show the EU’s move from national legislative transposition to embed cyber‑resilience in both sector‑specific practices the rollout of practical, sector‑focused tools and overall governance clarifications aimed at achieving consistent cyber‑risk management across the Union. member states.

Versions

  1. 2026-07-29 08:47 UTC EU NIS2 cybersecurity implementation
  2. 2026-07-29 08:47 UTC EU NIS2 Cybersecurity Implementation

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.