Compliance

Resiliently
NIS 2 · · 12 min read

NIS2 Austria Egov Compliance Guide 2026

Austrias journey to NIS2 compliance has been one of the most dramatic in the EU. The initial NISG 2024 was **rejected by Parliament in July 2024** over constitutional federal-stat

Resiliently
NIS 2 · · 12 min read

NIS2 Belgium Ccb Compliance Guide 2026

Belgium made history as the **first EU Member State to fully transpose the NIS2 Directive** into national law, passing the Law of 26 April 2024 well ahead of the 17 October 2024 EU

Resiliently
NIS 2 · · 14 min read

NIS2 Bulgaria Cybersecurity Act Compliance Guide 2026

Bulgaria transposed the EU NIS2 Directive into national law by **amending its existing Cybersecurity Act** (Закон за киберсигурността), with the amendments entering into force on *

Resiliently
NIS 2 · · 16 min read

NIS2 Croatia Cybersecurity Act Compliance Guide 2026

Croatia was one of the **first EU Member States** to transpose the NIS2 Directive into national law, passing the **Cybersecurity Act** (*Zakon o kibernetičkoj sigurnosti*, Official

Resiliently
NIS 2 · · 17 min read

NIS2 Cyprus Ocecpr Compliance Guide 2026

Cyprus transposition of NIS2 has been one of the most distinctive in the EU — not for its speed (it missed the October 2024 deadline by six months), but for its **strictest-in-clas

Resiliently
NIS 2 · · 9 min read

NIS2 Czech Republic Nukib Compliance Guide 2026

The Czech Republic went further than almost any EU member state in transposing NIS2. **Act No. 264/2025 Coll.** doesnt merely implement the directive — it creates an entirely new

Resiliently
NIS 2 · · 9 min read

NIS2 Denmark Cfcs Compliance Guide 2026

Denmark transposed the NIS2 Directive through the **NIS-2-loven** (Law on Measures to Ensure a High Level of Cybersecurity, Bill L 141) — but unlike most EU member states, Denmark

Resiliently
NIS 2 · · 10 min read

NIS2 Directive Compliance Guide 2026

The NIS2 Directive entered into force on October 17, 2024, fundamentally reshaping the cybersecurity landscape for organizations across the European Union. If your company operates

Resiliently
NIS 2 · · 14 min read

NIS2 Estonia Ria Compliance Guide 2026

Estonia has transposed the EU NIS2 Directive into national law by **amending its existing Cybersecurity Act (Küberturvalisuse seadus)**, which entered into force on **1 January 202

Resiliently
NIS 2 · · 10 min read

NIS2 Finland Traficom Compliance Guide 2026

Finland is among the earliest and most prepared NIS2 transposers in the EU. The **Kyberturvallisuuslaki** (Cybersecurity Act, Act 124/2025) entered into force on **8 April 2025** —

Resiliently
NIS 2 · · 12 min read

NIS2 France Anssi Compliance Guide 2026

Frances Agence Nationale de la Sécurité des Systèmes dInformation (ANSSI) has emerged as one of the most active national cybersecurity supervisors in the EUs NIS2 enforcement la

Resiliently
NIS 2 · · 14 min read

NIS2 Greece Ensi Compliance Guide 2026

Greece occupies a unique position in the EUs NIS2 compliance landscape. It controls the **worlds largest merchant fleet** by tonnage, operates critical energy infrastructure acro

Resiliently
NIS 2 · · 19 min read

NIS2 Hungary Nbi Nkh Compliance Guide 2026

Hungarys NIS2 transposition through **Act LXIX of 2024 on the Cybersecurity of Hungary** created much more than a single-regulator compliance regime. While **SZTFH (Supervisory Au

Resiliently
NIS 2 · · 16 min read

NIS2 Hungary Sztfh Nki Compliance Guide 2026

Hungary transposed the EU NIS2 Directive into national law through **Act LXIX of 2024 on the Cybersecurity of Hungary** (a.k.a. the Cybersecurity Act), which entered into force on

Resiliently
NIS 2 · · 13 min read

NIS2 Italy Acn Compliance Guide 2026

Italy has emerged as one of the EUs most aggressive NIS2 enforcers. The Agenzia per la Cybersicurezza Nazionale (ACN), established in 2021, has built a compliance architecture tha

Resiliently
NIS 2 · · 23 min read

NIS2 Latvia Ncsc Cert Cybersecurity Act Compliance Guide 2026

Latvia transposed the EU NIS2 Directive through a brand-new central statute — the **Nacionālās kiberdrošības likums** (National Cybersecurity Law) — adopted by the Saeima on 20 Jun

Resiliently
NIS 2 · · 19 min read

NIS2 Malta Mita Compliance Guide 2026

Malta was the last EU Member State to transpose the NIS2 Directive into national law, completing the process through the **NIS2 Implementing Regulations, 2025** under the Malta Dig

Resiliently
NIS 2 · · 11 min read

NIS2 Netherlands Ncsc Compliance Guide 2026

The Netherlands has long been a leader in cybersecurity policy within the EU. With the introduction of the **Uitvoeringswet cybersecurityrichtlijn** (Implementation Act for the Cyb

Resiliently
NIS 2 · · 13 min read

NIS2 Poland Ncsa Compliance Guide 2026

Poland is among the EU Member States actively transposing NIS2 into national law through amendments to its existing **Ustawa o krajowym systemie cyberbezpieczeństwa** (Act on the N

Resiliently
NIS 2 · · 9 min read

NIS2 Portugal Cncs Compliance Guide 2026

Portugal transposed NIS2 through **Decree-Law No. 125/2025** on 4 December 2025, creating the **Regime Jurídico da Cibersegurança** (Legal Framework for Cybersecurity). But Portuga

Resiliently
NIS 2 · · 12 min read

NIS2 Romania Ansi Compliance Guide 2026

Romania is among the EU Member States working to transpose NIS2 into national law through amendments to its existing **Legea nr. 361/2018 privind măsurile pentru asigurarea unui ni

Resiliently
NIS 2 · · 21 min read

NIS2 Slovakia Nbu Compliance Guide 2026

Slovakia transposed the EU NIS2 Directive through an **amendment to the Act on Cybersecurity** (*Zákon o kybernetickej bezpečnosti*), which was adopted in **2024** and entered into

Resiliently
NIS 2 · · 19 min read

NIS2 Slovenia Si Cert Compliance Guide 2026

Slovenia transposed the EU NIS2 Directive through the **Cybersecurity Act** (*Zakon o kibernetski varnosti*, **ZKV-1**), which was adopted in **late 2024** and entered into force o

Resiliently
NIS 2 · · 14 min read

NIS2 Spain Incibe Compliance Guide 2026

Spains Instituto Nacional de Ciberseguridad (INCIBE), working alongside the Centro Criptológico Nacional (CCN), has established one of the EUs most structured NIS2 enforcement fr

Resiliently
NIS 2 · · 12 min read

NIS2 Sweden Msb Compliance Guide 2026

Swedens **Cybersäkerhetslagen** (Cybersecurity Act, SFS 2025:1506) entered into force on **15 January 2026** — more than a year after the EUs October 2024 transposition deadline.

The Resilience Stack™: A 5-Layer Framework for Cyber Insurance Risk Assessment
Resilience Stack · · 21 min read

The Resilience Stack™: A 5-Layer Framework for Cyber Insurance Risk Assessment

Introducing the Resilience Stack™ — RESILIENTLY's proprietary framework for evaluating cyber risk across five layers: threat landscape, exposure surface, regulatory posture, financial impact, and insurance readiness.

NIS2 Compliance Is Now an Underwriting Requirement — Every Broker's Duty of Care
NIS 2 · · 4 min read

NIS2 Compliance Is Now an Underwriting Requirement — Every Broker's Duty of Care

The NIS2 transposition deadline has passed. With fewer than 10% of critical entities fully compliant, carriers are starting to exclude non-compliant organizations from coverage. For insurance brokers, failing to verify client NIS2 status is now a professional liability risk. Here's what you need to know.

Why Your Cyber Risk Register Is Lying to You — And What to Do About It
Risk Register · · 9 min read

Why Your Cyber Risk Register Is Lying to You — And What to Do About It

Most cyber risk registers are compliance checklists with no connection to real threat data, real incidents, or real financial exposure. Here is how to build one that actually works for underwriting decisions.

NIS2 Ransomware Reporting Requirements: What Incident Response Teams Must Know
Ransomware · · 7 min read

NIS2 Ransomware Reporting Requirements: What Incident Response Teams Must Know

Under NIS2, ransomware incidents trigger mandatory reporting obligations with tight deadlines and personal liability for management. Here is the compliance playbook incident response teams need.

How to Prepare for a NIS2 Audit: Documentation, Evidence, and Compliance Verification Guide (2026)
NIS 2 · · 12 min read

How to Prepare for a NIS2 Audit: Documentation, Evidence, and Compliance Verification Guide (2026)

Complete guide to NIS2 audit preparation. Covers documentation requirements by Article, evidence collection, common failures, management liability, and a 30-day pre-audit checklist for in-scope EU entities.

How to Conduct a NIS2 Gap Analysis: Step-by-Step Readiness Assessment for 2026
NIS 2 · · 12 min read

How to Conduct a NIS2 Gap Analysis: Step-by-Step Readiness Assessment for 2026

Complete NIS2 gap analysis methodology with step-by-step instructions, free checklist template, and readiness scoring framework. Identify compliance gaps across all 10 Article 21 measures, incident reporting, governance, and supply chain security before your national authority does.

NIS2 Ireland Preparation Guide: National Cyber Security Bill, NCSC Ireland and CyFun Framework for 2026
NIS 2 · · 8 min read

NIS2 Ireland Preparation Guide: National Cyber Security Bill, NCSC Ireland and CyFun Framework for 2026

Complete guide to NIS2 preparation in Ireland. Covers the pending National Cyber Security Bill, NCSC Ireland authority, CyFun compliance framework adopted from Belgium, 15 Risk Management Measures, entity classification expectations, and what organizations should do now despite legislation not yet enacted.

NIS2 Supply Chain Security Requirements: Third-Party Risk Management Guide for 2026
NIS 2 · · 10 min read

NIS2 Supply Chain Security Requirements: Third-Party Risk Management Guide for 2026

NIS2 Article 21 mandates supply chain security for all essential and important entities. Complete guide to third-party risk assessments, vendor security clauses, supply chain vulnerability monitoring, and compliance evidence — with free checklist and implementation templates.

Cyber Resilience Act vs NIS2 vs DORA: Which Regulation Applies to My Insured?
Cyber Resilience Act · · 12 min read

Cyber Resilience Act vs NIS2 vs DORA: Which Regulation Applies to My Insured?

A practical comparison of the three major EU cybersecurity regulations — CRA, NIS2, and DORA — explaining scope, timelines, requirements, and what cyber insurance underwriters need to ask clients in 2026.

NIS2 Article 21 Technical Measures: The Complete Security Requirements Breakdown for 2026
NIS 2 · · 11 min read

NIS2 Article 21 Technical Measures: The Complete Security Requirements Breakdown for 2026

NIS2 Article 21 defines 10 mandatory security measures every essential and important entity must implement. Complete breakdown of each requirement with implementation guidance, audit evidence expectations, and compliance timeline.

NIS2 Board Liability: Personal Fines, Bans, and What Management Must Know in 2026
NIS 2 · · 8 min read

NIS2 Board Liability: Personal Fines, Bans, and What Management Must Know in 2026

NIS2 Article 20 holds management bodies personally liable for cybersecurity failures. This guide explains personal fines, temporary bans, and the 7 steps boards must take to protect themselves in 2026.

NIS2 Compliance for IT Managers: The Action Plan That Actually Works in 2026
NIS 2 · · 9 min read

NIS2 Compliance for IT Managers: The Action Plan That Actually Works in 2026

Step-by-step NIS2 compliance action plan for IT managers and CISOs. Practical implementation guide covering risk management, incident reporting, security governance, supply chain security, and business continuity — with free tools and templates.

BSI Opens NIS2 Enforcement: What German Entities Must Do Before the Audit
NIS 2 · · 5 min read

BSI Opens NIS2 Enforcement: What German Entities Must Do Before the Audit

BSI has begun NIS2 enforcement audits. Essential entities in Germany face up to €10M fines. Here is what your audit readiness checklist looks like for 2026.

NIS2 Compliance Checklist for 2026: What Brokers Need to Verify Before Coverage Placement
NIS 2 · · 6 min read

NIS2 Compliance Checklist for 2026: What Brokers Need to Verify Before Coverage Placement

Before placing cyber coverage for NIS2 in-scope clients, verify these 10 compliance checkpoints. Missing documentation is the most common coverage gap.

NIS2 Penalties Explained: Essential vs Important Entities and What They Mean for Coverage
NIS 2 · · 9 min read

NIS2 Penalties Explained: Essential vs Important Entities and What They Mean for Coverage

NIS2 fines range from €7M to €10M depending on entity classification. Understand essential vs important entity penalties and how compliance posture affects cyber insurance pricing.

NIS2 Penalties & Fines Explained: What Organizations Actually Face in 2026
NIS2 Penalties · · 6 min read

NIS2 Penalties & Fines Explained: What Organizations Actually Face in 2026

NIS2 fines can reach €10 million or 2% of global annual turnover—whichever is higher. This breakdown explains exactly which penalties apply to essential vs important entities, what triggers enforcement, and how underwriters should factor penalty exposure into cyber risk assessment.

NIS2 Underwriting Questions: What Every Cyber Insurance Broker Should Ask
NIS 2 · · 16 min read

NIS2 Underwriting Questions: What Every Cyber Insurance Broker Should Ask

Practical Line 1, Line 2, and Line 3 underwriting questions for NIS2-exposed clients. Essential vs important entities. Coverage gaps brokers should flag.

NIS2 Compliance Checklist 2026: Complete Guide for the 2026 Deadline
NIS 2 · · 8 min read

NIS2 Compliance Checklist 2026: Complete Guide for the 2026 Deadline

Complete NIS2 compliance checklist with 70+ action items covering risk management, incident reporting, supply chain security, and governance. Essential preparation for EU enforcement.

NIS2 Compliance Checklist 2026: Complete Guide for Insurance Professionals
NIS2 Compliance Checklist · · 18 min read

NIS2 Compliance Checklist 2026: Complete Guide for Insurance Professionals

Complete NIS2 compliance checklist with requirements, deadlines, and implementation steps. Get your organization compliant with our expert guide.

What is NIS2 Compliance? A Complete Guide for 2026
NIS 2 · · 17 min read

What is NIS2 Compliance? A Complete Guide for 2026

Master NIS2 compliance in 2026. Understand the EU cybersecurity directive, who it affects, key requirements, penalties, and how to prepare before enforcement.

NIS2 Penalties Explained: Essential vs Important Entities for 2026
NIS 2 · · 5 min read

NIS2 Penalties Explained: Essential vs Important Entities for 2026

Understand the critical difference between NIS2 essential and important entities. Classification criteria, compliance requirements, penalty differences, and what it means for your cyber insurance.

NIS2 Incident Reporting: 24-Hour, 72-Hour, and 1-Month Requirements Explained
NIS2 Incident Reporting · · 18 min read

NIS2 Incident Reporting: 24-Hour, 72-Hour, and 1-Month Requirements Explained

Complete guide to NIS2 incident reporting timelines, requirements, and procedures. Learn what must be reported, when, and to whom under the EU cybersecurity directive.

The NIS2 Audit Crunch: What Underwriters Need to Know Before June 30, 2026
NIS 2 · · 10 min read

The NIS2 Audit Crunch: What Underwriters Need to Know Before June 30, 2026

With the June 30, 2026 NIS2 compliance audit deadline approaching, cyber underwriters face a narrow window to reassess risk profiles across their entire European portfolio. Here is what the audit requirement means for how you evaluate, price, and write cyber coverage.

NIS2 and DORA: What Cyber Underwriters Need to Know
Cyber Risk · · 2 min read

NIS2 and DORA: What Cyber Underwriters Need to Know

A practical breakdown of how the NIS2 Directive and DORA regulation affect cyber insurance underwriting in Europe.