The NIS2 Directive, which aims to establish a high common level of cybersecurity across the EU, is being transposed at varying speeds and approaches by EU member states.
Thus far, 15 of the 27 EU countries have adopted national legislation to implement NIS2.

Cullen International’s assessment of 18 member states also reveals differences in how key aspects of the directive are being transposed. For example, some countries (e.g. the Czech Republic and Spain) could expand the scope of sectors covered by NIS2.
In nine of the surveyed countries, the telecoms sector remains under the supervision of the national regulatory authority (NRA).
Additionally, the research identifies national authorities responsible for oversight, cybersecurity incident response, and coordination within the digital sectors.
For more information on the benchmark and Cullen International's complete NIS2 coverage, please click on “Access the full content” - or on “Request Access”, in case you are not subscribed to our European Digital Economy service.
more news
13 July 26
Authorities around the world are addressing emerging regulatory topics in IoT
Our Quarterly Regulatory Update on IoT and M2M Services (Q2 2026) highlights how national regulators are shaping the future of IoT and M2M services in areas such as cross-border connectivity, device regulation, and security.
09 July 26
Global trends in AI regulation
Our latest Global Trends benchmark compared if and how artificial intelligence (AI) is being regulated across 14 jurisdictions around the world.
08 July 26
Recent policy developments in LATAM telecoms markets include spectrum decisions in four countries
Our latest LATAM Telecoms Update highlights policy developments over the past three months affecting the regulation of radio spectrum, wholesale networks and consumer protection in six markets in the region: Argentina, Brazil, Chile, Colombia, Mexico and Peru.