Other instruments

← All instruments
mixedmixed
Type
mixed
Layer
mixed
Status
mixed
Last verified
2026-07-16

Other instruments (shorter entries)

These matter to the full picture but need less depth than the core acts. Split any of them into its own file if the website needs a dedicated page.

Electricity Network Code on Cybersecurity — Reg. (EU) 2024/1366

  • Type: Commission delegated regulation (network code). In force: 2024.
  • What: sector-specific cybersecurity rules for cross-border electricity flows — the first EU-wide, energy-specific cyber framework. Establishes recurring risk assessments at Union and national level, common minimum requirements, and information flows among grid operators, regulators and ENISA/ACER.
  • Interplay: implements NIS2’s risk-management logic for the electricity subsector; phased implementation over several years. ⚠️ VERIFY current phase.
  • Source: https://eur-lex.europa.eu/eli/reg/2024/1366/oj

Machinery Regulation — Reg. (EU) 2023/1230

  • Type: regulation. Applies from: 20 Jan 2027 (replacing the Machinery Directive).
  • What: safety of machinery, now including digital/cybersecurity safety aspects — protection against corruption, and ensuring that software/connectivity faults do not create safety hazards. Where machinery is also a product with digital elements, it can interact with the CRA.
  • Source: https://eur-lex.europa.eu/eli/reg/2023/1230/oj

Product Liability Directive (new) — Dir. (EU) 2024/2853

  • Type: directive. Transposition deadline: 9 Dec 2026.
  • What: modernises product-liability law to explicitly cover software and digital products, including cybersecurity vulnerabilities and missing security updates as potential “defects”. Provides a private-law route to compensation — the civil-liability complement to the CRA’s public enforcement.
  • Interplay: pairs with the CRA (a product lacking required security updates could be “defective”); a proposed AI Liability Directive was later withdrawn. ⚠️ VERIFY.
  • Source: https://eur-lex.europa.eu/eli/dir/2024/2853/oj

Directive on attacks against information systems — Dir. 2013/40/EU

  • Type: directive. In force: 2013 (transposed across the EU).
  • What: the EU’s core cybercrime criminal-law instrument — minimum rules on offences (illegal access, illegal system/data interference, illegal interception) and penalties, plus cross-border cooperation. Complements the Council of Europe Budapest Convention.
  • Interplay: the enforcement/criminal backdrop to the preventive obligations of NIS2/ CRA. A recast has been discussed. ⚠️ VERIFY.
  • Source: https://eur-lex.europa.eu/eli/dir/2013/40/oj

ePrivacy Directive — Dir. 2002/58/EC

  • Type: directive. In force: 2002 (amended 2009).
  • What: confidentiality of electronic communications and security duties for electronic-communications providers, incl. breach notification for telecoms. The long-stalled ePrivacy Regulation intended to replace it never passed; the Commission has signalled further reform.
  • Interplay: overlaps with GDPR and NIS2; the Digital Omnibus proposes to repeal its incident-reporting rules in favour of the Single Entry Point. ⚠️ VERIFY.
  • Source: https://eur-lex.europa.eu/eli/dir/2002/58/oj

Data Act — Reg. (EU) 2023/2854

  • Type: regulation. Applies from: 12 Sep 2025.
  • What: rules on access to and sharing of data from connected products, cloud- switching, and safeguards against unlawful third-country government access to non-personal data held in the EU — a data-governance act with security-relevant safeguards. The Digital Omnibus proposes to consolidate several data laws into it.
  • Source: https://eur-lex.europa.eu/eli/reg/2023/2854/oj

Soft-law and sectoral initiatives (no CELEX)

  • EU 5G Cybersecurity Toolbox (2020) — coordinated risk mitigation for 5G; parts to become binding via CSA2.
  • European action plan on the cybersecurity of hospitals and healthcare providers (2025) — sector support, ENISA guidance, an EU cybersecurity support centre for health.
  • EU Cyber Blueprint (Council Recommendation, 2025) — crisis-management coordination for large-scale incidents.
  • Cyber sanctions regime — Council Decision/Reg. (CFSP) 2019/797 & 2019/796: restrictive measures (asset freezes, travel bans) against cyber attackers.
  • National Cybersecurity Strategies — required by NIS2 Art. 7; all 27 states have one (ENISA interactive map).