This Practice Note tracks the key steps of legislative initiatives on cyber security in the EU.
Key EU cyber security initiatives include:
- •
EU Cybersecurity Act (adopted, amendments adopted in January 2025)
- •
Digital Operational Resilience Act or DORA (adopted, started to apply on 17 January 2025)
- •
NIS 2 Directive (adopted, started to apply on 18 October 2024)
- •
EU Critical Entities Resilience Directive or CER (adopted, started to apply on 18 October 2024)
- •
EU Cyber Security Regulation (adopted, started to apply on 7 January 2024)
- •
EU Cyber Resilience Act (adopted, starts to apply on 11 December 2027)
- •
EU Cyber Solidarity Act (adopted, started to apply on 4 February 2025)
All these initiatives are tracked in this document, except for:
- •
EU Digital Operational Resilience Act or DORA which historical legislative progress is tracked in Practice Note: Operational resilience—timeline [Archived]
- •
NIS 2 Directive which historical legislative progress is tracked in Practice Note: The EU NIS 2 Directive—timeline
For more information on other EU’s digital strategy initiatives such as the EU Artificial intelligence Act, the European
To view the latest version of this document and thousands of others like it,
sign-in with LexisNexis or register for a free trial.