The NIS2 Directive, which aims to establish a high common level of cybersecurity across the EU, is being transposed at varying speeds and approaches by EU member states.
Thus far, 15 of the 27 EU countries have adopted national legislation to implement NIS2.

Cullen International’s assessment of 18 member states also reveals differences in how key aspects of the directive are being transposed. For example, some countries (e.g. the Czech Republic and Spain) could expand the scope of sectors covered by NIS2.
In nine of the surveyed countries, the telecoms sector remains under the supervision of the national regulatory authority (NRA).
Additionally, the research identifies national authorities responsible for oversight, cybersecurity incident response, and coordination within the digital sectors.
For more information on the benchmark and Cullen International's complete NIS2 coverage, please click on “Access the full content” - or on “Request Access”, in case you are not subscribed to our European Digital Economy service.
more news
14 November 25
Most European NRAs regulate wholesale access to fibre
Our latest pan-European benchmark provides an overview of the market definition of M1/2020 and the remedies imposed on fibre unbundling and VULA over fibre, the wholesale prices for fibre unbundling at the optical distribution frame and for VULA over fibre.
07 November 25
How are EU member states transposing NIS2? - Continued
Cullen International’s latest Benchmark continues its analysis of NIS2 transposition across 18 EU countries, focusing on cybersecurity risk-management, incident reporting, and enforcement.
05 November 25
EU member states set out emissions reduction plans in long-term strategies
Our new benchmark compares EU countries' long-term strategies, outlining their 2030 and 2040 targets, overall and sectoral (transport and power) emissions reductions, energy consumption projections, renewable energy target, potential investments needed, R&D requirements and socio-economic aspects.