The National Cyber Security Strategies Imposed by the NIS2 Directive: Strategic Convergence Despite Overall Divergence?

27 August 2026, Version 1
This content is an early or alternative research output and has not been peer-reviewed by Cambridge University Press at the time of posting.

Abstract

The second network and information security directive (NIS2) of the European Union (EU) obliged each member state of the EU to develop and publish a national cyber security strategy. The research note explores these strategies empirically, including particularly with respect to a question whether the strategies indicate convergence or divergence across Europe. According to the results, there exists institutional divergence but strategic convergence; with a few gaps excluded, most of the strategies have addressed the same strategic priorities. Of the noteworthy divergence gaps, a few countries have not defined digital identities and the security-privacy trade-off as strategic priorities. Some countries have also specified coordinated vulnerability disclosure policies as a strategic priority. Despite the overall convergence of the strategies, institutional divergence is also present. With these results and the accompanying discussion, the research note contributes to the research on cyber security law and governance in Europe.

Keywords

cyber security regulations
cyber security governance
cyber security strategy
public administration
critical infrastructure
Europe

Comments

Comments are not moderated before they are posted, but they can be removed by the site moderators if they are found to be in contravention of our Commenting and Discussion Policy [opens in a new tab] - please read this policy before you post. Comments should be used for scholarly discussion of the content in question. You can find more information about how to use the commenting feature here [opens in a new tab] .
This site is protected by reCAPTCHA and the Google Privacy Policy [opens in a new tab] and Terms of Service [opens in a new tab] apply.