Telecoms security requirements predate the directive on measures for a high common level of cybersecurity across the EU (NIS2), which has regulated the security of electronic communications networks and services since October 2024.
NIS2 sets baseline cybersecurity risk-management and incident reporting obligations for entities operating in EU critical sectors (e.g. telecoms, cloud). The directive applies an all-hazard approach; thus, the risk-management measures should also address physical and environmental security (e.g. natural disasters), as well as resilience (e.g. having a business continuity strategy).
Cullen International published a Benchmark examining whether, in addition to the security requirements in NIS2 transposition laws, European countries established additional resilience requirements, in particular for mobile networks. It specifically addresses power backup and redundancy requirements to ensure service continuity during power outages, natural disasters, and other events impacting the operation of telecoms networks.
Of the surveyed countries, Denmark, Finland, Germany, Poland, Romania, Slovakia, Slovenia and Sweden expressly require telecoms operators to take measures guaranteeing backup power supply for mobile network elements.
In addition, Finland, Poland (proposed), Romania, Slovenia, Spain (proposed) and Sweden set minimum power backup duration requirements for mobile networks. In most of these countries, the minimum power backup duration requirements range depending on aspects such as the number of customers or the network elements affected.
Scope
Region: European Union
Countries covered: 27 EU member states
Policy area: cybersecurity, telecoms
Source type: Benchmark
Published: September 2026
For more information and access to the full benchmark, please click on “Access the full content” - or on “Request Access”, in case you are not subscribed to our European Digital Economy service.
more news
05 October 26
Ireland, the Netherlands and France account for the highest sum of data protection fines against large digital platforms
Our latest benchmark tracks fines imposed on large digital platforms by data protection and other supervisory authorities in 19 European countries since May 2018. It covers GDPR and e-Privacy Directive infringements and identifies whether the GDPR consistency mechanism was used in cross-border cases.
02 October 26
Saudi Arabia concludes a new round of market analysis
Cullen International's latest benchmark provides details on the market analysis regulatory framework in 13 MENA countries.
01 October 26
How are EU member states transposing NIS2?
Our latest benchmark tracks the progress of the Directive on measures for a high common level of cybersecurity across the EU (NIS2) transposition in the 27 EU member states.