Compliance & Regulation
Navigating NIS2, DORA, GDPR, and the evolving regulatory landscape for cyber risk and insurance.
The NIS2 + AI Coverage Gap: When Your Cyber Policy Won't Cover the Incident NIS2 Requires You to Report
NIS2 mandates AI incident reporting for hundreds of thousands of EU entities. But most cyber insurance policies contain silent AI exclusions, sublimits, or ambiguity that leave insureds paying for AI incident response out of pocket — even though NIS2 required them to report the incident in the first place.
Resiliently Team
9 min read
NIS2 Austria Egov Compliance Guide 2026
Austrias journey to NIS2 compliance has been one of the most dramatic in the EU. The initial NISG 2024 was **rejected by Parliament in July 2024** over constitutional federal-stat
NIS2 Belgium Ccb Compliance Guide 2026
Belgium made history as the **first EU Member State to fully transpose the NIS2 Directive** into national law, passing the Law of 26 April 2024 well ahead of the 17 October 2024 EU
NIS2 Bulgaria Cybersecurity Act Compliance Guide 2026
Bulgaria transposed the EU NIS2 Directive into national law by **amending its existing Cybersecurity Act** (Закон за киберсигурността), with the amendments entering into force on *
NIS2 Compliance Checklist 2026: Complete Guide for the 2026 Deadline
Complete NIS2 compliance checklist with 70+ action items covering risk management, incident reporting, supply chain security, and governance. Essential preparation for EU enforcement.
NIS2 Compliance Checklist 2026: Complete Guide for Insurance Professionals
Complete NIS2 compliance checklist with requirements, deadlines, and implementation steps. Get your organization compliant with our expert guide.
What is NIS2 Compliance? A Complete Guide for 2026
Master NIS2 compliance in 2026. Understand the EU cybersecurity directive, who it affects, key requirements, penalties, and how to prepare before enforcement.
NIS2 Compliance Requirements: 10 Mandatory Security Controls Before the 2026 Deadline
Master NIS2 compliance with our guide to the 10 mandatory security requirements. Learn what to implement, when deadlines hit, and how to avoid penalties up to €10 million or 2% of global turnover.
NIS2 Croatia Cybersecurity Act Compliance Guide 2026
Croatia was one of the **first EU Member States** to transpose the NIS2 Directive into national law, passing the **Cybersecurity Act** (*Zakon o kibernetičkoj sigurnosti*, Official
NIS2 Cyprus Ocecpr Compliance Guide 2026
Cyprus transposition of NIS2 has been one of the most distinctive in the EU — not for its speed (it missed the October 2024 deadline by six months), but for its **strictest-in-clas
NIS2 Czech Republic Nukib Compliance Guide 2026
The Czech Republic went further than almost any EU member state in transposing NIS2. **Act No. 264/2025 Coll.** doesnt merely implement the directive — it creates an entirely new
NIS2 Denmark Cfcs Compliance Guide 2026
Denmark transposed the NIS2 Directive through the **NIS-2-loven** (Law on Measures to Ensure a High Level of Cybersecurity, Bill L 141) — but unlike most EU member states, Denmark
NIS2 Directive Compliance Guide 2026
The NIS2 Directive entered into force on October 17, 2024, fundamentally reshaping the cybersecurity landscape for organizations across the European Union. If your company operates
NIS2 Penalties Explained: Essential vs Important Entities for 2026
Understand the critical difference between NIS2 essential and important entities. Classification criteria, compliance requirements, penalty differences, and what it means for your cyber insurance.
NIS2 Estonia Ria Compliance Guide 2026
Estonia has transposed the EU NIS2 Directive into national law by **amending its existing Cybersecurity Act (Küberturvalisuse seadus)**, which entered into force on **1 January 202
NIS2 Finland Traficom Compliance Guide 2026
Finland is among the earliest and most prepared NIS2 transposers in the EU. The **Kyberturvallisuuslaki** (Cybersecurity Act, Act 124/2025) entered into force on **8 April 2025** —
NIS2 France Anssi Compliance Guide 2026
Frances Agence Nationale de la Sécurité des Systèmes dInformation (ANSSI) has emerged as one of the most active national cybersecurity supervisors in the EUs NIS2 enforcement la
NIS2 Greece Ensi Compliance Guide 2026
Greece occupies a unique position in the EUs NIS2 compliance landscape. It controls the **worlds largest merchant fleet** by tonnage, operates critical energy infrastructure acro
NIS2 Hungary Nbi Nkh Compliance Guide 2026
Hungarys NIS2 transposition through **Act LXIX of 2024 on the Cybersecurity of Hungary** created much more than a single-regulator compliance regime. While **SZTFH (Supervisory Au
NIS2 Hungary Sztfh Nki Compliance Guide 2026
Hungary transposed the EU NIS2 Directive into national law through **Act LXIX of 2024 on the Cybersecurity of Hungary** (a.k.a. the Cybersecurity Act), which entered into force on
NIS2 Incident Reporting: 24-Hour, 72-Hour, and 1-Month Requirements Explained
Complete guide to NIS2 incident reporting timelines, requirements, and procedures. Learn what must be reported, when, and to whom under the EU cybersecurity directive.
NIS2 Italy Acn Compliance Guide 2026
Italy has emerged as one of the EUs most aggressive NIS2 enforcers. The Agenzia per la Cybersicurezza Nazionale (ACN), established in 2021, has built a compliance architecture tha
NIS2 Latvia Ncsc Cert Cybersecurity Act Compliance Guide 2026
Latvia transposed the EU NIS2 Directive through a brand-new central statute — the **Nacionālās kiberdrošības likums** (National Cybersecurity Law) — adopted by the Saeima on 20 Jun
NIS2 Malta Mita Compliance Guide 2026
Malta was the last EU Member State to transpose the NIS2 Directive into national law, completing the process through the **NIS2 Implementing Regulations, 2025** under the Malta Dig
NIS2 Netherlands Ncsc Compliance Guide 2026
The Netherlands has long been a leader in cybersecurity policy within the EU. With the introduction of the **Uitvoeringswet cybersecurityrichtlijn** (Implementation Act for the Cyb
NIS2 Penalties & Fines Explained: What Organizations Actually Face in 2026
NIS2 fines can reach €10 million or 2% of global annual turnover—whichever is higher. This breakdown explains exactly which penalties apply to essential vs important entities, what triggers enforcement, and how underwriters should factor penalty exposure into cyber risk assessment.
NIS2 Poland Ncsa Compliance Guide 2026
Poland is among the EU Member States actively transposing NIS2 into national law through amendments to its existing **Ustawa o krajowym systemie cyberbezpieczeństwa** (Act on the N
NIS2 Portugal Cncs Compliance Guide 2026
Portugal transposed NIS2 through **Decree-Law No. 125/2025** on 4 December 2025, creating the **Regime Jurídico da Cibersegurança** (Legal Framework for Cybersecurity). But Portuga
NIS2 Ransomware Reporting Requirements: What Incident Response Teams Must Know
Under NIS2, ransomware incidents trigger mandatory reporting obligations with tight deadlines and personal liability for management. Here is the compliance playbook incident response teams need.
NIS2 Romania Ansi Compliance Guide 2026
Romania is among the EU Member States working to transpose NIS2 into national law through amendments to its existing **Legea nr. 361/2018 privind măsurile pentru asigurarea unui ni
NIS2 Slovakia Nbu Compliance Guide 2026
Slovakia transposed the EU NIS2 Directive through an **amendment to the Act on Cybersecurity** (*Zákon o kybernetickej bezpečnosti*), which was adopted in **2024** and entered into
NIS2 Slovenia Si Cert Compliance Guide 2026
Slovenia transposed the EU NIS2 Directive through the **Cybersecurity Act** (*Zakon o kibernetski varnosti*, **ZKV-1**), which was adopted in **late 2024** and entered into force o
NIS2 Spain Incibe Compliance Guide 2026
Spains Instituto Nacional de Ciberseguridad (INCIBE), working alongside the Centro Criptológico Nacional (CCN), has established one of the EUs most structured NIS2 enforcement fr
NIS2 Sweden Msb Compliance Guide 2026
Swedens **Cybersäkerhetslagen** (Cybersecurity Act, SFS 2025:1506) entered into force on **15 January 2026** — more than a year after the EUs October 2024 transposition deadline.
blog.featured
AI Tooling RCE: The Sublimit Layer Underwriters Rarely Underwrite
9 min read
SolarWinds SAML Bypass: The IT Ticketing Supply-Chain Path
9 min read
AM Best and S&P Flag Cyber Pricing Risks: What Underwriters Should Do at Renewal
7 min read
One Salesforce Integration Breach Just Hit 200 Cyber Insureds
8 min read
Premium Report
2026 Cyber Risk Landscape Report
24 pages of threat analysis, claims data, and underwriting implications for European cyber insurance.
View Reports →