Orientation

The EU cybersecurity legal ecosystem

A layered map of horizontal, sectoral, product and adjacent instruments — and how they stack on national law.

The EU cybersecurity legal ecosystem

European cybersecurity law is not one law — it is a layered ecosystem of roughly a dozen EU instruments plus 27 national implementations. The easiest way in is to ask what each layer protects:

LayerQuestion it answersMain instruments
1. Horizontal / infrastructureAre the organisations running critical services secure and resilient?NIS2, CER Directive, Cyber Solidarity Act, Cybersecurity Act
2. Sector-specificDoes this sector need stricter or special rules?DORA (finance), electricity network code (NCCS), health action plan
3. ProductAre the products placed on the EU market secure?Cyber Resilience Act, RED delegated regulation, Machinery Regulation
4. Data & rights adjacentIs the data, identity and AI layer secure?GDPR, eIDAS 2, AI Act, Data Act, ePrivacy
5. Crime & liabilityWhat happens when things go wrong?Directive 2013/40 (cybercrime), Product Liability Directive
6. NationalHow does this apply in my country?27 transposition laws (NIS2/CER), national strategies, national frameworks

Mental model

flowchart TB
    subgraph EU["EU LEVEL"]
        subgraph HOR["Horizontal backbone"]
            NIS2["NIS2 Directive<br/>who must be secure"]
            CER["CER Directive<br/>physical-resilience twin"]
            CSA["Cybersecurity Act<br/>ENISA + certification"]
            CSOA["Cyber Solidarity Act<br/>EU detection & response"]
        end
        subgraph SEC["Sectoral"]
            DORA["DORA — finance"]
            NCCS["Electricity network code"]
        end
        subgraph PROD["Products"]
            CRA["Cyber Resilience Act"]
            RED["RED cybersecurity rules"]
        end
        subgraph ADJ["Adjacent"]
            GDPR["GDPR (Art. 32-34)"]
            EIDAS["eIDAS 2 / EUDI Wallet"]
            AIA["AI Act (Art. 15)"]
        end
    end
    subgraph NAT["27 MEMBER STATES"]
        TL["National transposition laws<br/>+ competent authorities + CSIRTs"]
    end
    NIS2 -->|directive: must be transposed| TL
    CER -->|directive: must be transposed| TL
    DORA -.->|regulation: applies directly| NAT
    CRA -.->|regulation: applies directly| NAT

Directive vs regulation — why the national layer exists

  • A regulation (CRA, DORA, GDPR, Cybersecurity Act, Cyber Solidarity Act, eIDAS 2, AI Act) applies directly and identically in every Member State from one date.
  • A directive (NIS2, CER, ePrivacy, 2013/40, PLD) sets objectives each Member State must transpose — choosing its authority, procedures, penalties within EU minimums, and optionally a wider scope.

That single distinction explains this site’s structure: the country drill-down (30-national/) exists because NIS2 and CER are directives, so who supervises you, where you register and which portal you report to are decided nationally.

The five instruments to learn first

  1. NIS2 — the centre of gravity: cyber obligations for essential/important entities across 18 sectors.
  2. Cyber Resilience Act — security for virtually every hardware/software product sold in the EU.
  3. DORA — the financial sector’s stricter regime (lex specialis to NIS2).
  4. CER Directive — NIS2’s physical twin.
  5. Cybersecurity Act — ENISA’s mandate and the EU certification framework; being revised by CSA2.

What is changing right now (2026)

On 20 January 2026 the Commission proposed a new Cybersecurity Package: a revised Cybersecurity Act (“CSA2”) and targeted NIS2 amendments — alongside the November-2025 Digital Omnibus introducing a Single Entry Point for incident reporting (“report once, share many”). All three are in the pipeline: see 20-proposals/.

Soft law worth knowing (no dedicated file)

  • EU 5G Cybersecurity Toolbox (2020) — coordinated 5G risk mitigation; CSA2 would make parts binding.
  • EU Cyber Blueprint (Council Recommendation, 2025) — large-scale crisis playbook.
  • Cyber Diplomacy Toolbox / cyber sanctions (Decision & Reg. 2019/796–797).
  • National Cybersecurity Strategies — required by NIS2 Art. 7; all 27 have one (ENISA maintains an interactive NCSS map).