Abstract
The second network and information security directive (NIS2) of the European Union (EU) obliged each member state of the EU to develop and publish a national cyber security strategy. The research note explores these strategies empirically, including particularly with respect to a question whether the strategies indicate convergence or divergence across Europe. According to the results, there exists institutional divergence but strategic convergence; with a few gaps excluded, most of the strategies have addressed the same strategic priorities. Of the noteworthy divergence gaps, a few countries have not defined digital identities and the security-privacy trade-off as strategic priorities. Some countries have also specified coordinated vulnerability disclosure policies as a strategic priority. Despite the overall convergence of the strategies, institutional divergence is also present. With these results and the accompanying discussion, the research note contributes to the research on cyber security law and governance in Europe.



![Author ORCID: We display the ORCID iD icon alongside authors names on our website to acknowledge that the ORCiD has been authenticated when entered by the user. To view the users ORCiD record click the icon. [opens in a new tab]](https://www.cambridge.org/engage/assets/public/coe/logo/orcid.png)