EU Cybersecurity and Critical Infrastructure Resilience
Map the EU rules for cyber risk management, secure digital products, critical entities, certification and collective response—and track the important application dates.
Cybersecurity and Critical Infrastructure
EU cyber resilience uses complementary layers. NIS2 governs risk management and incident reporting by essential and important entities. The Cyber Resilience Act governs products with digital elements across their life cycle. The Critical Entities Resilience Directive covers non-cyber resilience of identified critical entities. The Cyber Solidarity Act builds shared detection, preparedness and emergency-support capacity. ENISA provides expertise and coordination, while national authorities remain central to supervision and response. A January 2026 Cybersecurity Act revision was still a proposal on 17 August 2026.
- Policy status
- Current
- Exam relevance
- High
- Depth
- Core
A shared resilience system
Cybersecurity crosses internal-market, security and national-security boundaries. Much EU legislation uses Article 114 TFEU because divergent national requirements can fragment the internal market. Article 16 supports data-protection rules, Article 196 supports civil-protection cooperation and Article 222 contains the solidarity clause for disasters and terrorist attacks. National security remains the sole responsibility of each Member State under Article 4(2) TEU. EU cyber law therefore raises common civilian resilience without creating an EU intelligence service or transferring all incident command to Brussels.
The working model has four stages: reduce risk before an incident, detect and share relevant information, coordinate response when impacts cross borders, and restore services. Member States designate competent authorities, single points of contact and computer security incident response teams. The Commission oversees EU law and may adopt specified implementing acts. ENISA—the European Union Agency for Cybersecurity—supports expertise, exercises, vulnerability coordination and cooperation. EU-CyCLONe links national crisis-management authorities for large-scale incidents; the CSIRTs Network supports technical operational cooperation.
NIS2: organisations and essential services
Directive (EU) 2022/2555, known as NIS2, seeks a high common level of cybersecurity across the Union. It expands covered sectors and divides covered organisations into essential and important entities. The classification affects the supervisory regime, not the basic need to manage risk. Sectors include energy, transport, health, digital infrastructure, public administration, drinking water, wastewater, postal services, manufacturing of certain critical products and digital providers. Size thresholds and specific inclusions or exclusions matter; not every small organisation is automatically covered.
Entities must use proportionate technical, operational and organisational measures. The directive lists incident handling, business continuity, supply-chain security, vulnerability handling, encryption where appropriate, access control, asset management and staff awareness. Management bodies approve and oversee measures and can be held accountable under national transposition. Significant incidents follow a staged notification model: an early warning within 24 hours of awareness, an incident notification within 72 hours and a final report normally within one month. Candidates should not collapse these into one deadline.
NIS2 is a directive. Member States had to transpose it by 17 October 2024 and apply national measures from 18 October 2024. Rights and duties are enforced principally through national law. Incomplete transposition does not turn the directive into a regulation; it creates an implementation problem subject to EU-law remedies and possible infringement action.
Cyber Resilience Act: products and life-cycle security
Regulation (EU) 2024/2847—the Cyber Resilience Act or CRA—takes a product-market approach. It covers hardware and software products with digital elements placed on the EU market, subject to defined exclusions and interactions with sectoral law. Manufacturers must design and produce secure products, assess cyber risks, manage vulnerabilities and provide security updates for the support period. Importers and distributors have verification duties. Conformity assessment and CE marking connect cyber requirements to normal Single Market product enforcement.
Entry into force is not the same as full application. The CRA entered into force on 10 December 2024. Rules on notifying conformity-assessment bodies applied from 11 June 2026. Article 14 reporting duties for actively exploited vulnerabilities and severe incidents apply from 11 September 2026. Most obligations apply from 11 December 2027. On this briefing’s update date, the September reporting duties were imminent but not yet applicable.
Critical entities: cyber and physical risks
Directive (EU) 2022/2557, the Critical Entities Resilience or CER Directive, addresses the ability of identified entities to prevent, protect against, respond to, resist, mitigate, absorb, accommodate and recover from incidents. Its all-hazards scope includes natural hazards, accidents, public-health emergencies, sabotage and terrorism. Member States conduct risk assessments, adopt strategies and identify critical entities in listed sectors. Identified entities then assess risks, take proportionate measures and notify disruptive incidents.
CER and NIS2 were designed to work together. CER focuses mainly on non-cyber resilience; NIS2 focuses on network and information systems. National authorities must cooperate and exchange relevant information. The directives do not mean that every entity in a listed sector has identical obligations. Identification, size rules, sectoral provisions and national transposition determine coverage.
Collective detection and crisis support
Regulation (EU) 2025/38, the Cyber Solidarity Act, has applied since 4 February 2025. It establishes a European Cybersecurity Alert System, preparedness measures and an EU Cybersecurity Reserve of trusted incident-response providers. It also supports review of significant or large-scale incidents. The reserve supplements, rather than replaces, national capabilities. Requests, eligibility, contracting and confidentiality follow the regulation and its implementation arrangements.
Crisis language must be precise. A significant incident under NIS2 concerns serious disruption, loss or damage for an entity or others. A large-scale incident exceeds one Member State’s capacity or significantly affects at least two Member States. Political coordination may also use the Council’s Integrated Political Crisis Response arrangements. The EU’s 2019 cyber-diplomacy toolbox can support external-relations responses, including restrictive measures, but attribution and sanctions are political and legal decisions, not ENISA technical findings.
What changed in 2026
On 20 January 2026 the Commission proposed a revision of the 2019 Cybersecurity Act. The proposal aims to streamline EU certification, address security risks in information and communication technology supply chains and reinforce ENISA. It was still subject to Parliament and Council examination on 17 August 2026. Existing Regulation (EU) 2019/881 remained the applicable Cybersecurity Act unless and until amended.
On 7 July 2026 the Commission presented an action plan on advanced artificial intelligence and cybersecurity. It covers model evaluation, structured access to advanced models for defenders, secure testing with ENISA and the Joint Research Centre, faster vulnerability remediation and stronger European AI capability. The action plan builds on existing law; it is not itself a new regulation. Separately, implementation work continued for the CRA reporting platform, the Cybersecurity Reserve and national NIS2 frameworks.
Exam method: identify object, actor and stage
Ask what is being protected. For a covered service provider, start with NIS2. For connected hardware or software placed on the market, start with the CRA. For physical and all-hazards resilience of an identified critical entity, start with CER. For cross-border detection and emergency support, consider the Cyber Solidarity Act. Then identify whether the responsible actor is a manufacturer, regulated entity, Member State authority, CSIRT, ENISA, Commission or co-legislator. Finish by checking whether the rule was proposed, in force or already applicable on the relevant date.
Legal anchors
National security responsibility
National security remains the sole responsibility of each Member State.
Internal market
Legal base for much harmonised EU cyber legislation addressing market fragmentation.
NIS2 Directive
Common cyber risk-management, reporting, cooperation and supervisory framework for covered entities.
Cyber Resilience Act
Horizontal product cybersecurity requirements for products with digital elements.
Critical Entities Resilience Directive
All-hazards resilience rules for critical entities identified by Member States.
Key figures
First staged notification after awareness of a significant incident.
More developed notification after awareness, following the early warning.
Article 14 duties on actively exploited vulnerabilities and severe incidents begin to apply.
Most Cyber Resilience Act obligations apply from this date.
Policy timeline
-
2023-01-16
NIS2 and CER entered into force
Paired directives strengthened cyber and all-hazards resilience.
in_force -
2024-10-17
NIS2 transposition deadline
Member States were required to adopt and publish national measures.
transposition_deadline -
2024-12-10
Cyber Resilience Act entered into force
Application is phased through 2026 and 2027.
in_force -
2025-02-04
Cyber Solidarity Act applied
Shared detection, preparedness and reserve framework became applicable.
applicable -
2026-01-20
Revised Cybersecurity Act proposed
Commission proposal opened the ordinary legislative process.
proposal -
2026-07-07
AI and cybersecurity action plan presented
Non-legislative plan addresses defensive and offensive implications of advanced AI.
action_plan -
2026-09-11
CRA reporting duties apply
Future date from the perspective of this update.
scheduled
Common exam traps
In force does not always mean fully applicable
The CRA uses several dates; most duties wait until December 2027.
Cyber and physical resilience overlap but differ
NIS2 and CER coordinate, yet govern different risk dimensions.
Incident deadlines are staged
NIS2 uses 24-hour, 72-hour and final-report stages, subject to the directive and national rules.
National security remains national
EU resilience rules do not create general EU competence over Member-State national security.
Essential glossary
- CSIRT
- Computer security incident response team providing technical incident functions.
- EU-CyCLONe
- Network supporting coordinated management of large-scale cybersecurity incidents and crises.
- Cybersecurity certification
- EU framework for schemes that attest defined security properties of ICT products, services or processes.
- Product with digital elements
- CRA concept covering software or hardware and specified remote data-processing solutions with direct or indirect data connection.
- Cybersecurity Reserve
- EU-level pool of trusted response providers supporting eligible users during serious incidents.
Check your recall
Which law primarily regulates covered essential and important entities?
Which law primarily regulates connected hardware and software products?
When do CRA Article 14 reporting duties apply?
Does ENISA replace national CSIRTs?
What does the CER Directive add to NIS2?
Was the revised Cybersecurity Act adopted by 17 August 2026?
Official sources
Primary EU sources. Accessed on the date shown.
- 01Directive (EU) 2022/2555 — NIS2EUR-Lex · Accessed 2026-08-17
- 02Regulation (EU) 2024/2847 — Cyber Resilience ActEUR-Lex · Accessed 2026-08-17
- 03Directive (EU) 2022/2557 — Critical Entities Resilience DirectiveEUR-Lex · Accessed 2026-08-17
- 04Regulation (EU) 2025/38 — Cyber Solidarity ActEUR-Lex · Accessed 2026-08-17
- 05Regulation (EU) 2019/881 — Cybersecurity ActEUR-Lex · Accessed 2026-08-17
- 06New measures to strengthen cybersecurity resilience and capabilitiesEuropean Commission · Accessed 2026-08-17
- 07New EU plan for advanced AI and cybersecurityEuropean Commission · Accessed 2026-08-17