Orientation
The EU cybersecurity legal ecosystem
A layered map of horizontal, sectoral, product and adjacent instruments — and how they stack on national law.
The EU cybersecurity legal ecosystem
European cybersecurity law is not one law — it is a layered ecosystem of roughly a dozen EU instruments plus 27 national implementations. The easiest way in is to ask what each layer protects:
| Layer | Question it answers | Main instruments |
|---|---|---|
| 1. Horizontal / infrastructure | Are the organisations running critical services secure and resilient? | NIS2, CER Directive, Cyber Solidarity Act, Cybersecurity Act |
| 2. Sector-specific | Does this sector need stricter or special rules? | DORA (finance), electricity network code (NCCS), health action plan |
| 3. Product | Are the products placed on the EU market secure? | Cyber Resilience Act, RED delegated regulation, Machinery Regulation |
| 4. Data & rights adjacent | Is the data, identity and AI layer secure? | GDPR, eIDAS 2, AI Act, Data Act, ePrivacy |
| 5. Crime & liability | What happens when things go wrong? | Directive 2013/40 (cybercrime), Product Liability Directive |
| 6. National | How does this apply in my country? | 27 transposition laws (NIS2/CER), national strategies, national frameworks |
Mental model
flowchart TB
subgraph EU["EU LEVEL"]
subgraph HOR["Horizontal backbone"]
NIS2["NIS2 Directive<br/>who must be secure"]
CER["CER Directive<br/>physical-resilience twin"]
CSA["Cybersecurity Act<br/>ENISA + certification"]
CSOA["Cyber Solidarity Act<br/>EU detection & response"]
end
subgraph SEC["Sectoral"]
DORA["DORA — finance"]
NCCS["Electricity network code"]
end
subgraph PROD["Products"]
CRA["Cyber Resilience Act"]
RED["RED cybersecurity rules"]
end
subgraph ADJ["Adjacent"]
GDPR["GDPR (Art. 32-34)"]
EIDAS["eIDAS 2 / EUDI Wallet"]
AIA["AI Act (Art. 15)"]
end
end
subgraph NAT["27 MEMBER STATES"]
TL["National transposition laws<br/>+ competent authorities + CSIRTs"]
end
NIS2 -->|directive: must be transposed| TL
CER -->|directive: must be transposed| TL
DORA -.->|regulation: applies directly| NAT
CRA -.->|regulation: applies directly| NAT
Directive vs regulation — why the national layer exists
- A regulation (CRA, DORA, GDPR, Cybersecurity Act, Cyber Solidarity Act, eIDAS 2, AI Act) applies directly and identically in every Member State from one date.
- A directive (NIS2, CER, ePrivacy, 2013/40, PLD) sets objectives each Member State must transpose — choosing its authority, procedures, penalties within EU minimums, and optionally a wider scope.
That single distinction explains this site’s structure: the country drill-down
(30-national/) exists because NIS2 and CER are directives, so who supervises you, where
you register and which portal you report to are decided nationally.
The five instruments to learn first
- NIS2 — the centre of gravity: cyber obligations for essential/important entities across 18 sectors.
- Cyber Resilience Act — security for virtually every hardware/software product sold in the EU.
- DORA — the financial sector’s stricter regime (lex specialis to NIS2).
- CER Directive — NIS2’s physical twin.
- Cybersecurity Act — ENISA’s mandate and the EU certification framework; being revised by CSA2.
What is changing right now (2026)
On 20 January 2026 the Commission proposed a new Cybersecurity Package: a revised
Cybersecurity Act (“CSA2”) and targeted NIS2 amendments — alongside the November-2025
Digital Omnibus introducing a Single Entry Point for incident reporting (“report
once, share many”). All three are in the pipeline: see 20-proposals/.
Soft law worth knowing (no dedicated file)
- EU 5G Cybersecurity Toolbox (2020) — coordinated 5G risk mitigation; CSA2 would make parts binding.
- EU Cyber Blueprint (Council Recommendation, 2025) — large-scale crisis playbook.
- Cyber Diplomacy Toolbox / cyber sanctions (Decision & Reg. 2019/796–797).
- National Cybersecurity Strategies — required by NIS2 Art. 7; all 27 have one (ENISA maintains an interactive NCSS map).