Other instruments
← All instruments
Other instruments (shorter entries)
These matter to the full picture but need less depth than the core acts. Split any of them into its own file if the website needs a dedicated page.
Electricity Network Code on Cybersecurity — Reg. (EU) 2024/1366
- Type: Commission delegated regulation (network code). In force: 2024.
- What: sector-specific cybersecurity rules for cross-border electricity flows — the first EU-wide, energy-specific cyber framework. Establishes recurring risk assessments at Union and national level, common minimum requirements, and information flows among grid operators, regulators and ENISA/ACER.
- Interplay: implements NIS2’s risk-management logic for the electricity subsector; phased implementation over several years. ⚠️ VERIFY current phase.
- Source: https://eur-lex.europa.eu/eli/reg/2024/1366/oj
Machinery Regulation — Reg. (EU) 2023/1230
- Type: regulation. Applies from: 20 Jan 2027 (replacing the Machinery Directive).
- What: safety of machinery, now including digital/cybersecurity safety aspects — protection against corruption, and ensuring that software/connectivity faults do not create safety hazards. Where machinery is also a product with digital elements, it can interact with the CRA.
- Source: https://eur-lex.europa.eu/eli/reg/2023/1230/oj
Product Liability Directive (new) — Dir. (EU) 2024/2853
- Type: directive. Transposition deadline: 9 Dec 2026.
- What: modernises product-liability law to explicitly cover software and digital products, including cybersecurity vulnerabilities and missing security updates as potential “defects”. Provides a private-law route to compensation — the civil-liability complement to the CRA’s public enforcement.
- Interplay: pairs with the CRA (a product lacking required security updates could be “defective”); a proposed AI Liability Directive was later withdrawn. ⚠️ VERIFY.
- Source: https://eur-lex.europa.eu/eli/dir/2024/2853/oj
Directive on attacks against information systems — Dir. 2013/40/EU
- Type: directive. In force: 2013 (transposed across the EU).
- What: the EU’s core cybercrime criminal-law instrument — minimum rules on offences (illegal access, illegal system/data interference, illegal interception) and penalties, plus cross-border cooperation. Complements the Council of Europe Budapest Convention.
- Interplay: the enforcement/criminal backdrop to the preventive obligations of NIS2/ CRA. A recast has been discussed. ⚠️ VERIFY.
- Source: https://eur-lex.europa.eu/eli/dir/2013/40/oj
ePrivacy Directive — Dir. 2002/58/EC
- Type: directive. In force: 2002 (amended 2009).
- What: confidentiality of electronic communications and security duties for electronic-communications providers, incl. breach notification for telecoms. The long-stalled ePrivacy Regulation intended to replace it never passed; the Commission has signalled further reform.
- Interplay: overlaps with GDPR and NIS2; the Digital Omnibus proposes to repeal its incident-reporting rules in favour of the Single Entry Point. ⚠️ VERIFY.
- Source: https://eur-lex.europa.eu/eli/dir/2002/58/oj
Data Act — Reg. (EU) 2023/2854
- Type: regulation. Applies from: 12 Sep 2025.
- What: rules on access to and sharing of data from connected products, cloud- switching, and safeguards against unlawful third-country government access to non-personal data held in the EU — a data-governance act with security-relevant safeguards. The Digital Omnibus proposes to consolidate several data laws into it.
- Source: https://eur-lex.europa.eu/eli/reg/2023/2854/oj
Soft-law and sectoral initiatives (no CELEX)
- EU 5G Cybersecurity Toolbox (2020) — coordinated risk mitigation for 5G; parts to become binding via CSA2.
- European action plan on the cybersecurity of hospitals and healthcare providers (2025) — sector support, ENISA guidance, an EU cybersecurity support centre for health.
- EU Cyber Blueprint (Council Recommendation, 2025) — crisis-management coordination for large-scale incidents.
- Cyber sanctions regime — Council Decision/Reg. (CFSP) 2019/797 & 2019/796: restrictive measures (asset freezes, travel bans) against cyber attackers.
- National Cybersecurity Strategies — required by NIS2 Art. 7; all 27 states have one (ENISA interactive map).