PofoliaShared via Pofolia

Computer law & security review· 2026Q1

Consistencies and inconsistencies in the implementation of the NIS2 directive by EU Member States

Zsolt Bederna, Csaba Krasznay, Gabriella Biró

Short summary

EU Member States exhibit significant national disparities in transposing the NIS2 Directive, leading to fragmentation and potentially weakening cross-border cybersecurity resilience.

AI-generated from the title and abstract; the full text is not read.

Key points

  • Member States show significant national disparities in transposing the NIS2 Directive.
  • Inconsistencies exist in entity classification, security requirements, and incident reporting timelines.
  • Application of international standards (e.g., ISO/IEC 27001) varies across Member States.
  • Divergences create overlapping obligations with other EU regulations like DORA, CRA, and CER.
  • Fragmentation may weaken cross-border cybersecurity resilience.

AI-generated from the title and abstract; the full text is not read.

Abstract

The NIS2 Directive aims to unify cybersecurity across the EU, yet its transposition reveals significant national disparities. This paper analyzes how Member States implement key provisions regarding entity classification, security requirements, and incident reporting. Based on ECSO findings and comparative legal analysis, the study highlights inconsistencies in scope definitions, sectoral coverage, and reporting timelines. Divergences in applying international standards (e.g., ISO/IEC 27001, NIST SP 800–53) and the burden on multinational companies are examined. Furthermore, the paper maps the NIS2 Directive to related EU regulations, such as DORA, CRA, and CER, identifying overlapping obligations and implementation gaps. The findings demonstrate that despite its harmonization intent, the NIS2 Directive's directive nature allows fragmentation, potentially weakening cross-border cybersecurity resilience. The study calls for enhanced coordination and mutual recognition mechanisms to ensure coherent and effective cybersecurity governance within the EU.

The authors' abstract, as published at the source. Computer law & security review, 2026 · DOI ↗

TakeawaysPremium
Ask the paperFree account

Continue with a free account

Ask the paper: 3 free questions a day about this paper; save it, get its citation, new summaries every day for your field. Takeaways are Premium.

Continue free on the web

Sign in with Google or Apple; no card needed. You come back to this paper.

On your phone:

Field: Law

LawSocial Sciences