CTIPilot

EU NIS2 Directive

policy · policy:eu-nis2-directive

EU directive requiring member-state transposition and mandatory incident reporting by essential/important entities. The European Court of Auditors' Special Report 19/2026 (2026-09-22) finds transposition two years behind schedule in most member states and cross-border incident notification unreliable in practice; national transposition laws (Austria's NISG 2026, Poland, the Netherlands, Germany) are tracked as their own entities.

Aliases: NIS 2, Directive (EU) 2022/2555

Coverage timeline
2
first 2026-09-23 → last 2026-09-23
Peak priority
notable
2 notable
Sources cited
4
3 hosts
Sections touched
1
research
Co-occurring entities
3
see Co-occurring entities below
ATT&CK techniques
0
no mapped behavior yet

Hunting pivots

Story timeline

  1. 2026-09-23EU Court of Auditors: cyber-incident cooperation framework only partially effective, cross-border notification failed for the 2025 airport ransomware disruption
    researchEU auditors find no member state ever formally notified the bloc of the 2025 Collins Aerospace airport ransomware attack
  2. 2026-09-23Austria's NISG 2026 creates the Bundesamt für Cybersicherheit, 24h/72h incident-reporting clock live 1 October 2026
    researchAustria stands up a new federal cybersecurity authority with 24h/72h reporting and active-scanning powers

Where this entity is cited

  • research2

Source distribution

  • heise.de2 (50%)
  • eca.europa.eu1 (25%)
  • ots.at1 (25%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about EU NIS2 Directive (2)

2026-09-23 · view entry permalink →

NOTABLENATOA1

Austria's NISG 2026 creates the Bundesamt für Cybersicherheit, 24h/72h incident-reporting clock live 1 October 2026

Austria's Netz- und Informationssystemsicherheitsgesetz 2026 (NISG 2026) (the country's NIS2 transposition, two years late) enters into force on 1 October 2026: "with the entry into force of the [NISG 2026], the new Federal Office for Cybersecurity (BCS) officially begins its work on 1 October 2026" (translated from German; Austrian Federal Ministry of the Interior, via OTS, 2026-09-22). The new Bundesamt für Cybersicherheit (BCS), under the Interior Ministry and led by former Austrian Power Grid CIO Markus Kasinger, becomes the central registration and supervision authority for "essential" and "important" entities across energy, transport, health, water, digital infrastructure, industry and food supply (municipalities excluded), takes over operation of the civilian-administration GovCERT, and gains oversight of sectoral CERTs (including the Austrian HealthCERT) and the general-economy CERT.at (heise online, 2026-09-22). Covered entities face a graduated reporting clock: "an initial early warning is required without delay, in any case within 24 hours of becoming aware of the incident. A more detailed notification must be made without delay, at the latest within 72 hours" (translated from German; Austrian BMI, via OTS, 2026-09-22), followed by further reports and a final report as the incident develops. The law also mandates security-awareness training for management and gives the BCS new powers to run active vulnerability scans against internet-facing systems of essential entities: "blocking or defending against such state scans is a criminal offence from 1 October, and affected essential entities must also actively cooperate on request" (translated from German; heise online, 2026-09-22). Enforcement and fines run through the competent district administrative authority rather than the BCS itself (heise online, 2026-09-22).

This continues the pattern already tracked for Finland's NCSC-FI CRA reporting checklist and Canton Bern's ICSG (also a 24h/72h reporting clock, entering force 1 November 2026) giving Swiss cantonal and federal authorities a further live comparator for reporting-obligation design as additional cantons stand up their own ICSG-equivalents.

With the entry into force of the Network and Information System Security Act 2026 (NISG 2026), the new Federal Office for Cybersecurity (BCS) officially begins its work on 1 October 2026.

An initial early warning is required without delay, in any case within 24 hours of becoming aware of the incident. A more detailed notification must be made without delay, at the latest within 72 hours.

Austrian Federal Ministry of the Interior (BMI), via OTS press release

Blocking or defending against such state scans is a criminal offence from 1 October, and affected essential entities must also actively cooperate on request.

heise online 2026-09-22
policy23 Sep 04:44Zmulti-sourceOpen finding ↗

2026-09-23 · view entry permalink →

NOTABLENATOA1

EU Court of Auditors: cyber-incident cooperation framework only partially effective, cross-border notification failed for the 2025 airport ransomware disruption

The European Court of Auditors published Special Report 19/2026 on 2026-09-22, concluding that the EU's cooperation framework for detecting and responding to cybersecurity incidents (the CSIRTs network, EU-CyCLONe, the Cyber Blueprint, the European Cybersecurity Alert System and the EU Cybersecurity Reserve) is only partially effective. Three structural gaps drive the finding: NIS2 transposition delays ("member states had until October 2024 to transpose the NIS 2 Directive into national law, but only two met the deadline" (European Court of Auditors, Special Report 19/2026, 2026-09-22)); national-security legislation that lets member states withhold incident information with no obligation to share it; and no EU-wide platform to correlate cross-border incidents in real time. As its case study, the report documents that the September 2025 Collins Aerospace ransomware attack on airport passenger-processing systems; "the disruption was most severe at London Heathrow Airport, Brussels Airport, Berlin Brandenburg Airport, and Dublin Airport" (European Court of Auditors, Special Report 19/2026, 2026-09-22), was never classified as "significant" or "large-scale cross-border" under NIS2 by the affected member states, named by heise as Germany, Belgium and Ireland (heise online, 2026-09-22): "no member state treated this incident as being either significant or large-scale cross-border. Therefore, none of the affected member states formally notified ENISA or other member states of the incident. The CSIRTs network did not advise EU-CyCLONe, which therefore did not support the coordinated management of the incident" (European Court of Auditors, Special Report 19/2026, 2026-09-22). EU-wide, "in 2025, only 14 significant cross-border incidents were reported, by seven member states" (European Court of Auditors, Special Report 19/2026, 2026-09-22), and "no cybersecurity incident has been considered 'large-scale' by any member state since 2016", despite events the report itself cites as comparably severe, including WannaCry and NotPetya (European Court of Auditors, Special Report 19/2026, 2026-09-22). The Court's Recommendation 1, targeted for 2027 (information-sharing analysis and cross-border-incident detection) and 2028 (real-time incident reporting), calls for a Commission/ENISA-led review of national-security restrictions on information sharing and progress toward real-time incident reporting to ENISA (European Court of Auditors, Special Report 19/2026, 2026-09-22).

Switzerland sits outside NIS2's scope but is embedded in the same cross-border supply chains (aviation, finance, cloud) the report's case study concerns. The finding that formal EU cross-notification cannot be relied on for early warning is a direct input to how Swiss public-sector CERTs and GovCERT.ch should weight direct primary-source monitoring of national CERTs and vendor advisories against EU cross-notification channels, since a serious incident affecting an EU supply-chain partner may never surface through the formal EU mechanism at all.

Yet, no member state treated this incident as being either significant or large-scale cross-border. Therefore, none of the affected member states formally notified ENISA or other member states of the incident. The CSIRTs network did not advise EU-CyCLONe, which therefore did not support the coordinated management of the incident.

Member states had until October 2024 to transpose the NIS 2 Directive into national law, but only two met the deadline.

In 2025, only 14 significant cross-border incidents were reported, by seven member states.

European Court of Auditors, Special Report 19/2026

Despite the significant impact of the incident, the affected member states (Germany, Belgium and Ireland) reportedly did not notify the EU cybersecurity agency ENISA or the other member states accordingly, the report criticizes.

heise online 2026-09-22
policy23 Sep 04:43Zmulti-sourceOpen finding ↗