Since 2016, the European Union (EU) has developed an increas- ingly integrated cybersecurity framework, moving from NIS 1 Directive (Di- rective 2016/1148) to NIS 2 Directive (Directive 2022/2555) and comple- menting horizontal instruments with sector ‑specific regimes to raise the com- mon level of cybersecurity. Key instruments include the Cybersecurity Act (Regulation 2019/881), the Digital Operational Resilience Act (DORA) (Regulation 2022/2554), the Critical Entities Resilience (CER) Directive (Di- rective 2022/2557), the Cyber Resilience Act (Regulation 2024/2847), and, finally, the Cyber Solidarity Act (CSA) (Regulation 2025/38). The centre- piece, however, is the NIS 2 Directive, which significantly expands the scope to cover a broader range of “essential” and “important” entities based on size thresholds, imposes detailed and uniform risk management obligations, strengthens Member State cooperation, and introduces effective and dissua- sive supervision and sanctioning powers, thereby ensuring a high common level of cybersecurity across the Union. The most recent institutional debate points to a possible “digital omnibus” to rationalise and coordinate the digital acquis—including the interfaces among the DSA/DMA, consumer protection in digital markets, and data protection—with implications for enforcement and systemic coherence.
The EU Cybersecurity Landscape: Regulatory Architecture, Enforcement and the Road to a "Digital Omnibus" / P. Perri - In: EU Product Liability Law: Platforms, Internet of Things and Artificial Intelligence / [a cura di] S. Martinelli, P. Perri, C. Poncibò. - [s.l] : Routledge, 2026 Jul. - ISBN 978-10-412-5653-3. - pp. 371-394
The EU Cybersecurity Landscape: Regulatory Architecture, Enforcement and the Road to a "Digital Omnibus"
P. Perri
2026
Abstract
Since 2016, the European Union (EU) has developed an increas- ingly integrated cybersecurity framework, moving from NIS 1 Directive (Di- rective 2016/1148) to NIS 2 Directive (Directive 2022/2555) and comple- menting horizontal instruments with sector ‑specific regimes to raise the com- mon level of cybersecurity. Key instruments include the Cybersecurity Act (Regulation 2019/881), the Digital Operational Resilience Act (DORA) (Regulation 2022/2554), the Critical Entities Resilience (CER) Directive (Di- rective 2022/2557), the Cyber Resilience Act (Regulation 2024/2847), and, finally, the Cyber Solidarity Act (CSA) (Regulation 2025/38). The centre- piece, however, is the NIS 2 Directive, which significantly expands the scope to cover a broader range of “essential” and “important” entities based on size thresholds, imposes detailed and uniform risk management obligations, strengthens Member State cooperation, and introduces effective and dissua- sive supervision and sanctioning powers, thereby ensuring a high common level of cybersecurity across the Union. The most recent institutional debate points to a possible “digital omnibus” to rationalise and coordinate the digital acquis—including the interfaces among the DSA/DMA, consumer protection in digital markets, and data protection—with implications for enforcement and systemic coherence.| File | Dimensione | Formato | |
|---|---|---|---|
|
EU Product Liability Law - Perri.pdf
accesso riservato
Tipologia:
Publisher's version/PDF
Licenza:
Nessuna licenza
Dimensione
6.79 MB
Formato
Adobe PDF
|
6.79 MB | Adobe PDF | Visualizza/Apri Richiedi una copia |
Pubblicazioni consigliate
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.




