Glossary · Cross-regulation

Directive vs Regulation

The two main types of EU law: a regulation applies directly in all member states, while a directive must be transposed into national law first.

Explained in depth: NIS2 overview

An EU regulation, such as DORA, the AI Act, GDPR, and the Cyber Resilience Act, is directly applicable: the same text is binding law in every member state from its application date, with no national implementation needed. An EU directive, such as NIS2 and CER, sets goals and minimum requirements that each member state must implement through its own national legislation by a transposition deadline; organisations are then bound by the national law, not the directive itself. The practical consequences are real. Regulations give uniformity: DORA reads the same in Stockholm and Madrid. Directives give variation: NIS2 obligations in Sweden flow from Cybersäkerhetslagen and can differ in detail, scope additions, and timing from Germany's or France's implementation, and transposition delays create periods where the directive's deadline has passed but no national law yet binds anyone.

Why it matters

This distinction explains most of the confusion in EU compliance: why NIS2 "applied" in October 2024 but Swedish enforcement waited for Cybersäkerhetslagen, why DORA needed no Swedish law, and why multi-country NIS2 compliance requires reading several national laws.

Used in

See also

← All glossary terms