EU Commission Urges Implementation of Cybersecurity Directive

Header Image

The cyberattack on European airports over the weekend, which caused huge delays across the continent, has brought a sense of urgency on the issue, warns the Commission.

The European Commission called on all 27 EU member states to implement the Network and Information Security Directive (NIS 2) on a high common level of cybersecurity across the Union, following cyberattacks that cripped European airports at the weekend.

Cyprus is one of 12 member states that have implemented the NIS 2 Directive, following the initiation of non-compliance procedures, the Commission confirmed to CNA, noting, however, that until all 27 member states incorporate the Directive, everyone remains vulnerable.

Commission spokesperson Thomas Regnier said on Monday: “The Commission has been closely monitoring the cyberattack, both over the weekend and today which has disrupted check-in and boarding systems at multiple airports. While passengers continue to face delays, air traffic safety and control remain unaffected.” 

He added: “On our side, I can confirm that the Commission is working with Eurocontrol, ENISA (European Network and Information Security Agency), national authorities, airports, and airlines to restore operations and support affected passengers.”

Regnier highlighted the importance of fully transposing the NIS 2 Directive.

“Aviation and transport are high-criticality sectors, and we urge all Member States to act swiftly and effectively in adopting NIS 2.”

Cyprus previously faced EU infringement proceedings for delayed transposition into national law of the Directive, receiving a warning letter in November 2024 alongside 22 other states and a reasoned opinion in May 2025 with 19 others. 

It has since fully incorporated NIS 2 into national law, as have Denmark, Romania, Greece, Belgium, Italy, Slovakia, Croatia, Lithuania, Malta, Slovenia, and Latvia.

Asked by CNA why Belgium – despite fully transposing NIS 2 – saw Brussels Airport fall victim to a cyberattack on Friday night, Regnier clarified: “This is precisely why we all need to enforce the Directive – otherwise, everyone will remain vulnerable, including those who have transposed it. Hence our push to all Member States to move forward with full implementation.”

The cyberattack on a service provider used by numerous major airports for automatic check-ins caused huge disruptions over the weekend, with Brussels, Berlin and Heathrow airports, among others, seeing many flight delays and cancellations.