Consistencies and inconsistencies in the implementation of the NIS2 directive by EU Member States
The NIS2 Directive aims to unify cybersecurity across the EU, yet its transposition reveals significant national disparities. This paper analyzes how Member States implement key provisions regarding entity classification, security requirements, and incident reporting. Based on ECSO findings and comparative legal analysis, the study highlights inconsistencies in scope definitions, sectoral coverage, and reporting timelines. Divergences in applying international standards (e.g., ISO/IEC 27001, NIST SP 800–53) and the burden on multinational companies are examined. Furthermore, the paper maps the NIS2 Directive to related EU regulations, such as DORA, CRA, and CER, identifying overlapping obligations and implementation gaps. The findings demonstrate that despite its harmonization intent, the NIS2 Directive's directive nature allows fragmentation, potentially weakening cross-border cybersecurity resilience. The study calls for enhanced coordination and mutual recognition mechanisms to ensure coherent and effective cybersecurity governance within the EU.
Authors
- Zsolt Bederna (ORCID: https://orcid.org/0000-0003-0444-7275)
- Csaba Krasznay (ORCID: https://orcid.org/0000-0003-3216-2592)
- Gabriella Biró (ORCID: https://orcid.org/0009-0004-5924-6694)
Institutions
- Obuda University (HU)
- Ludovika University of Public Service (HU)
- Budapest University of Technology and Economics (HU)
Publication Details
- Journal
- Computer law & security review
- Published
- 2026-10-03
- DOI
- https://doi.org/10.1016/j.clsr.2026.106412
- Primary Topic
- Cybersecurity and Cyber Warfare Studies
- Type
- article
- Field-Weighted Citation Impact
- 0.00