Full Breakdown
EU’s NIS2 Cybersecurity Law Stumbles Over Unexpected “Critical” Sectors
8/18/2026, 4:13:05 AM
Core Event: Confusing Scope of the New Cybersecurity Regime
The EU’s Network and Information Security Directive 2 (NIS2) requires operators of “essential and important” entities to register with national cyber agencies and adopt heightened security measures. While the law was intended to be fully implemented by late 2024, many firms are only now grappling with the details of compliance. Legal advisers report that the definition of “critical infrastructure” is so broad that it can encompass businesses such as ice-cream manufacturers, chewing-gum wholesalers, and other seemingly low-risk sectors.
Background & Context: Delayed National Transposition
Member states were expected to enact complementary national legislation by the end of 2024. However, France and Spain have yet to pass the required laws, and Germany’s registration process remains sluggish. The rollout therefore coincides with a broader EU effort to streamline regulation, creating tension between the goal of tighter cyber defenses and the desire to avoid additional bureaucratic burdens.
Impact and Challenges for Companies
The expansive wording forces companies to determine whether they fall under the “essential” or “important” categories, a task described by lawyers as a “real-world puzzle.” Small businesses are generally exempt, and lighter obligations apply to less critical organizations, according to an anonymous European Commission official. Nonetheless, firms in sectors not traditionally viewed as high-risk must allocate legal and technical resources to assess their status, draft compliance plans, and complete registration—activities that many deem disproportionate to the actual cyber threat they face.
Official Statements & Responses
An unnamed European Commission source emphasized that NIS2 includes “several mechanisms” to keep obligations proportionate, aiming to protect smaller operators while focusing enforcement on truly critical services. National authorities in Germany have acknowledged the slow pace of registrations and indicated plans to issue clearer guidance, though no concrete timeline has been provided.
Why It Matters
The ambiguity surrounding NIS2’s scope risks undermining the law’s effectiveness by diverting attention and resources away from genuinely vulnerable sectors. If businesses continue to spend significant effort on compliance without clear criteria, the EU’s broader objective of strengthening cyber resilience could be compromised, prompting calls for more precise definitions in future legislative updates.
