EU Cyber Law
The layered map of Europe's cybersecurity rules.
From NIS2 and the Cyber Resilience Act to national transposition — one place to see how the instruments fit together.
Start here
Three ways in
Start with the overview, drill into an EU instrument, or check what's coming.
Core rulebook · 10 in force · 3 proposals
Instruments that shape the map
The centre of gravity of this area's current EU rulebook.
- NIS2 NIS2 Directive Cybersecurity obligations for essential/important entities across 18 sectors.
- CRA Cyber Resilience Act Security by design for every product with digital elements; CE marking.
- DORA DORA ICT-risk regime for the financial sector; lex specialis to NIS2.
- CER CER Directive All-hazards physical resilience of critical entities; NIS2's physical twin.
Situation desk
Situation desk
Interactive triage for this area’s instruments — find likely regimes, track deadlines, and explore overlaps.
27 Member States · data 2026-07-16
Across the Union
Transposition is uneven — status counts from the national knowledge base.
19
Transposed, in force
2
Transposed, entry pending
1
Transposed, commencement pending
5
In legislative procedure