EU cybersecurity is entering an implementation test
EU cybersecurity in 2026 is no longer mainly about tracking new rules. It is becoming an implementation test for governments, critical infrastructure operators, product manufacturers and digital service providers. NIS2 has widened cybersecurity governance across 18 critical sectors, but national transposition remains uneven. The Cyber Resilience Act is moving product security toward mandatory lifecycle obligations, with reporting rules due to start on 11 September 2026 and the main requirements applying from 11 December 2027. At the same time, ENISA’s latest threat reporting explains why the policy shift matters: availability attacks, ransomware, phishing and vulnerability exploitation continue to shape Europe’s risk picture.
For more coverage of digital risk, policy and critical infrastructure security, follow the Cybersecurity section on RoadsNews.

The policy stack is bigger than NIS2
NIS2 remains the most visible part of the EU cybersecurity framework because it applies to a wide range of essential and important entities. Member States had until 17 October 2024 to transpose the directive into national law, and the earlier NIS framework was repealed from 18 October 2024. In practice, regulated organisations still need to work from the national law, regulator guidance and sector-specific supervisory approach in each Member State where they operate.
The European Commission’s communications show that the rollout has not been uniform. On 7 May 2025, the Commission sent reasoned opinions to 19 Member States for failing to notify full transposition. On 8 July 2026, it announced a decision to refer Ireland, Spain, France and the Netherlands to the Court of Justice of the European Union for failing to notify NIS2 transposition measures. That does not make NIS2 irrelevant in those markets. It means compliance planning must allow for legal uncertainty, local timing and possible rapid changes in national implementation.
Beyond NIS2, three other EU-level developments now matter for cybersecurity planning:
| EU measure | Status by September 2026 | Practical significance |
|---|---|---|
| NIS2 Directive | Transposition deadline passed on 17 October 2024, with uneven national implementation | Sets cybersecurity risk management, reporting, supervision and governance expectations for essential and important entities |
| Cyber Resilience Act | Entered into force on 10 December 2024; reporting obligations apply from 11 September 2026; main obligations apply from 11 December 2027 | Moves cybersecurity requirements into the design, development, maintenance and vulnerability handling of products with digital elements |
| Cyber Solidarity Act | Entered into force on 4 February 2025 | Creates EU-level mechanisms for detection, preparedness and response, including cyber hubs and an EU Cybersecurity Reserve |
| Cybersecurity Act revision package | Proposed by the Commission on 20 January 2026 | Would revise certification, ICT supply-chain security and ENISA’s support role; it remains a proposal, not a final adopted law |
Threat data explains the shift from paperwork to resilience
The regulatory push is clearer when viewed alongside ENISA’s 2025 Threat Landscape. Published on 1 October 2025 and later updated for link corrections in January 2026, the report analysed 4,875 incidents from 1 July 2024 to 30 June 2025. The findings show that the EU’s exposure is not concentrated in one incident type or one sector.
DDoS attacks dominated the incident count, representing 77% of reported incidents in ENISA’s summary. Hacktivism accounted for almost 80% of the total number of incidents, largely through low-impact DDoS campaigns against public-facing websites. Even so, incident volume is not the same as business impact. ENISA identified ransomware as the most impactful threat in the EU, so organisations should not judge risk by frequency alone.
The sector data also matters. Public administration was the most targeted sector in the period, at 38.2% of incidents, followed by transport at 7.5%, digital infrastructure and services at 4.8%, finance at 4.5% and manufacturing at 2.9%. ENISA also reported that 53.7% of the total number of incidents concerned essential entities as defined by NIS2. For transport operators, logistics providers, public authorities and their suppliers, the message is direct: cybersecurity risk is now part of service continuity, not a separate IT issue.
Initial access patterns reinforce the same point. ENISA identified phishing and vulnerability exploitation as leading intrusion access points. That aligns closely with the controls regulators continue to emphasise: patch management, identity protection, incident reporting, supplier risk management and tested continuity plans.
Investment is rising, but execution gaps remain
Higher cybersecurity spending does not automatically translate into resilience. ENISA’s 2025 NIS Investments work, based on a survey of 1,080 public and private organisations across all EU Member States, found that cybersecurity investment remained at about 9% of IT budgets, with a median of €1.5 million. Compliance was the main investment driver at 70%, although organisations also reported improvements in risk management, detection and response.
The more difficult findings are in the execution gaps. ENISA reported that patching, business continuity and supply-chain risk management were among the main implementation challenges. It also found that almost one in three surveyed organisations had not conducted a cybersecurity assessment in the previous 12 months, while 28% took more than three months to patch critical vulnerabilities. In a policy environment built around faster reporting, stronger supervision and better preparedness, those gaps are material.
Skills remain another constraint. ENISA reported persistent difficulty attracting and retaining cybersecurity professionals, with the problem more acute where organisations rely on legacy systems, fragmented supplier chains or small internal security teams. This matters for NIS2 and the Cyber Resilience Act because both frameworks assume that organisations can identify risk, document decisions, handle incidents and maintain security over time. A formal policy will not help if the organisation cannot execute it during an attack.
Product security is becoming a lifecycle obligation
The Cyber Resilience Act changes the logic for software and hardware products with digital elements. Rather than treating cybersecurity as a feature added late in development, the law pushes manufacturers to address security during planning, design, development, production and maintenance. It also requires vulnerability handling during the expected product lifetime. See also: AI.
The next milestone is close. Reporting obligations for actively exploited vulnerabilities and severe incidents are scheduled to apply from 11 September 2026. The main obligations apply from 11 December 2027. That gap gives manufacturers, importers, distributors and software producers time to build processes, but it should not be treated as a pause. Companies need to know which products are in scope, who owns vulnerability intake, how updates are distributed, how third-party components are tracked and how evidence will be retained for market surveillance.
This will also affect buyers. Procurement teams may increasingly ask suppliers for secure development practices, vulnerability disclosure procedures, update commitments, component visibility and documentation. In sectors already covered by NIS2, supplier assurance and product assurance will become linked. A critical infrastructure operator cannot manage cyber risk effectively if a key product supplier cannot explain how vulnerabilities are found, prioritised and fixed.
What organisations should prioritise now
The most practical response is to build one integrated cybersecurity control map rather than separate compliance projects for every EU rule. The details differ by sector and Member State, but five priorities are broadly relevant.
- Confirm scope by country and sector. NIS2 obligations depend on national implementation, entity classification and sector definitions. Organisations operating in multiple Member States should maintain a country-by-country applicability view.
- Upgrade incident reporting readiness. Reporting deadlines are only meaningful if teams can detect, classify, escalate and document an incident quickly. Legal, security, communications and operational teams should test this together.
- Make patching measurable. Track critical vulnerability exposure, compensating controls, patch exceptions and time to remediation. Regulators and customers will expect evidence, not just policies.
- Map critical suppliers and dependencies. Cloud, managed services, software components, operational technology and outsourced security services can all become concentration risks.
- Connect cyber risk to continuity. DDoS, ransomware and supplier compromise can interrupt public services, transport systems and customer operations. Recovery plans should be tested against realistic scenarios, not only documented.
Boards and senior management should also treat EU cybersecurity as a governance issue. NIS2 places more emphasis on management responsibility, while the broader EU framework increasingly expects evidence that risk decisions are understood, resourced and reviewed. Stronger organisations will not only ask whether a control exists. They will ask whether it works under pressure.
What to watch next
Three developments will shape the next phase. First, NIS2 enforcement will become more concrete as national authorities finalise supervision models and as delayed Member States complete or amend their laws. Second, the Cyber Resilience Act will move from preparation to early operational reporting on 11 September 2026, creating a practical test for vulnerability handling. Third, the proposed revision of the Cybersecurity Act could reshape certification and ICT supply-chain expectations if adopted, but organisations should treat it as a legislative proposal until the EU process is complete.
The broader direction is already visible. EU cybersecurity policy is moving from minimum compliance toward resilience across services, products and supply chains. For regulated entities, suppliers and public bodies, the central question is no longer whether Europe is serious about cybersecurity. It is whether operational processes, budgets, contracts and incident playbooks can keep pace with both the rules and the threat environment.
Frequently asked questions
What is the main EU cybersecurity law in 2026?
NIS2 is the main horizontal cybersecurity directive for essential and important entities across critical sectors. However, it now sits alongside the Cyber Resilience Act for products with digital elements, the Cyber Solidarity Act for EU-level preparedness and response, and certification rules under the Cybersecurity Act framework.
When do Cyber Resilience Act obligations begin?
The Cyber Resilience Act entered into force on 10 December 2024. Reporting obligations for actively exploited vulnerabilities and severe incidents are due to apply from 11 September 2026, while the main obligations apply from 11 December 2027.
Does NIS2 apply the same way in every EU country?
No. NIS2 is an EU directive, so Member States must transpose it into national law. The core framework is European, but practical obligations, competent authorities, enforcement details and local procedures depend on national implementation.
Why is ransomware still central if DDoS dominates incident volume?
DDoS attacks may be more numerous in ENISA’s incident data, especially because of hacktivist campaigns, but ransomware can cause deeper operational, financial and recovery impacts. Frequency and severity therefore need to be assessed separately.
