Abstract network of glowing blue nodes representing national cybersecurity coordination under NIS2 Article 7

NIS2 National Strategy: The 18 Things Article 7 Requires — and the 5 That Reach Your Company

Almost every secondary summary of NIS2 Article 7 repeats a list of “nine elements”. Count the operative text and there are eighteen: eight mandatory contents in Article 7(1), and ten mandatory policies in Article 7(2) [1]. The gap matters, because the components that create work for your compliance team sit mostly in the second list — the one those summaries drop.

Article 7 is also the one NIS2 provision that can never be enforced against you. It binds Member States, not entities. Read correctly, though, it tells you which authority will supervise you, what will appear in your public-sector contracts, and who is allowed to phone you about a vulnerability in your own product.

Who Article 7 binds — and what it can do to you

In plain terms, Article 7 is a homework assignment for governments. Your obligations live in Article 21 and Article 23. Nothing in Article 7 can ground a fine or an enforcement order against your organisation.

Who What Article 7 asks of them Enforceable against your entity?
The Member State Adopt a strategy containing all 18 components; notify it to the Commission within three months; reassess it at least every five years against key performance indicators [1] No. The duty runs to the Commission, and the remedy is infringement action against the state
Competent authority, CSIRT, single point of contact Operate inside the governance framework the strategy defines, under Article 7(1)(c) Indirectly — it decides which regulator supervises you and which team receives your incident reports
Essential or important entity Nothing. Article 7 imposes no duty on entities at all No
SME outside NIS2 scope Nothing — but Article 7(2)(i) names you as an intended beneficiary of state guidance No

If you are still working out which side of that line you sit on, start with the essential entity definition rather than with Article 7.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

The 18 mandatory components, counted from the text

Article 6 defines a national cybersecurity strategy as “a coherent framework of a Member State providing strategic objectives and priorities in the area of cybersecurity and the governance to achieve them” [2]. Article 7 then sets out what that framework must contain, in two separate lists.

Article 7(1) — eight mandatory contents:

Point What it requires
(a) Objectives and priorities, covering in particular the Annex I and Annex II sectors
(b) A governance framework to achieve those objectives, including the Article 7(2) policies
(c) A governance framework clarifying national roles and responsibilities, and coordination between competent authorities, single points of contact and CSIRTs
(d) A mechanism to identify relevant assets, and an assessment of risks in that Member State
(e) Measures for preparedness, response and recovery, including public-private cooperation
(f) A list of the authorities and stakeholders involved in implementing the strategy
(g) A policy framework for coordination with the competent authorities under the CER Directive (EU) 2022/2557
(h) A plan to raise the general level of cybersecurity awareness among citizens

Points (b) and (c) both open with “a governance framework”. That is not a slip in the Official Journal — (b) is the framework for delivering the objectives, (c) is the framework for allocating institutional roles. Collapsing them is how an eighteen-item list becomes a nine-item one.

Article 7(2) — ten mandatory policies. The verb is the same binding “shall”: Member States “shall in particular adopt policies” on (a) ICT supply chain cybersecurity; (b) cybersecurity requirements in public procurement, including certification, encryption and open-source products; (c) vulnerability management and coordinated disclosure under Article 12(1); (d) the public core of the open internet, including undersea communications cables; (e) advanced technologies for state-of-the-art risk management; (f) education, skills, awareness and R&D; (g) support for academic and research institutions; (h) voluntary information sharing between entities; (i) cyber resilience for SMEs, “in particular those excluded from the scope of this Directive”; and (j) active cyber protection [1].

Two items commonly attributed to Article 7 are not in it. International cooperation is Article 17; national crisis management is Article 9 [2].

Article 7 never says “publish”

The verb in Article 7(1) is “adopt”. Article 7(3) then requires Member States to “notify their national cybersecurity strategies to the Commission within three months of their adoption”, adding that they “may exclude information which relates to their national security from such notifications” [1]. No obligation to publish the strategy appears anywhere in Article 7.

The contrast with the surrounding text is deliberate. Article 41(1) tells Member States to “adopt and publish” their transposition measures by 17 October 2024 [4]. Article 8(6) says each Member State “shall make public the identity of its competent authority” [7]. Where the drafters wanted publication, they wrote it.

In practice this costs you little — every EU Member State has published a strategy since 2017, and ENISA republishes them [8]. But it changes what you can expect. A Member State that withholds an annex on national-security grounds, or publishes a summary rather than the full instrument, is acting inside the text. Do not build a compliance argument on the assumption that the complete strategy is public.

The five components that reach your company

Thirteen of the eighteen stay inside government. Five produce something an entity can be handed, asked for, or contacted about.

Component What actually lands on you
7(1)(c) and (f) — governance framework and authority list Decides which regulator supervises your sector and which team receives your Article 23 reports. Where a state appointed several sector authorities, this is often the only document mapping them. See competent authority powers and the single point of contact.
7(2)(b) — public procurement policy If you sell to the public sector, this is where certification schemes, encryption requirements and open-source preferences enter your tender documents — as contract terms, not regulation. See NIS2 for procurement teams.
7(2)(c) — coordinated vulnerability disclosure Article 12(1) makes one national CSIRT the CVD coordinator; its listed tasks include “identifying and contacting the entities concerned” and “negotiating disclosure timelines” [5]. Researchers may report anonymously, so you can be contacted about a flaw in your own product by someone you cannot call back. See coordinated vulnerability disclosure.
7(2)(h) — information-sharing policy The only one creating a direct duty. Article 29(3) ties state assistance to “their policies referred to in Article 7(2), point (h)”, and Article 29(4) requires entities to notify the competent authority on joining such an arrangement and again on withdrawal [6]. See Article 29 information sharing.
7(2)(i) — SME resilience policy Aimed at SMEs “excluded from the scope of this Directive” — your long tail of small suppliers. State-published SME guidance is a free, nationally endorsed baseline you can point to in supplier due diligence.

Note what is not on the list. Article 7(2)(a) obliges the state to hold an ICT supply-chain policy; it does not change your Article 21(2)(d) duties. Union-level coordinated supply-chain risk assessments sit in Article 22, are run by the Cooperation Group, and are discretionary — the group “may carry out” them [12].

Your national strategy is not your national NIS2 law

This is the most common practical error: a team finds the country’s cybersecurity strategy, reads it for obligations, finds almost none, and concludes NIS2 has not landed yet.

They are different instruments. The strategy is a policy framework adopted under Article 7. The law binding you is the national transposition required by Article 41(1) by 17 October 2024 [4]. Recital 48 makes the looseness explicit: strategies “can be composed of one or more legislative or non-legislative instruments” [3] — a cabinet decision, a ministerial programme, or a bundle of documents, none of it necessarily enforceable law. A Member State can have a current strategy and still have failed to transpose; check both separately, and see the transposition tracker for the second half.

The Commission’s own NIS2 FAQ adds a cross-regime wrinkle: Member States “should continue to include the financial sector in their cybersecurity strategies” even though DORA governs those entities’ risk management and reporting [10]. Appearing in a strategy does not mean the strategy regulates you.

Four strategy topics that exist only in the recitals

NIS2’s recitals are interpretive aids and create no obligations — worth remembering whenever a vendor quotes one at you (see what the recitals actually do). Four strategy topics widely cited as Article 7 requirements appear nowhere in the operative text [3]:

  • Ransomware. Recital 54 says Member States “should develop a policy addressing the rise of ransomware attacks as part of their national cybersecurity strategy.” The word does not appear in Article 7.
  • Smart cities and connected utilities. Recital 53 asks for a policy on connected urban infrastructure; Article 7 does not mention it.
  • An SME point of contact. Recital 56 says Member States “should have a point of contact for small and medium-sized enterprises at national or regional level.” Article 7(2)(i) requires only “easily accessible guidance and assistance”.
  • Undersea cable risk mapping. Article 7(2)(d) names the cybersecurity of undersea cables; the instruction to “include a mapping of potential cybersecurity risks and mitigation measures” is Recital 97 alone.

Recital 57 is the one worth reading in full, because Article 7(2)(j) requires a policy “promoting active cyber protection” without defining the term. The recital supplies it — “the prevention, detection, monitoring, analysis and mitigation of network security breaches in an active manner” — and closes by stating that active cyber protection “is based on a defensive strategy that excludes offensive measures”, ruling out hack-back before anyone proposes it.

The five-year clock, and what ENISA’s own map shows

Article 7(4) requires Member States to assess their strategies “on a regular basis and at least every five years on the basis of key performance indicators” and update them “where necessary” [1]. Read the modal verbs carefully: the assessment is mandatory on a five-year cycle; the update is conditional. An old strategy is not automatically an infringement.

That distinction is doing real work. ENISA’s NCSS interactive map records each Member State’s strategy validity window, and several have run out. Croatia’s listed strategy covers 2015 to 2020. Lithuania’s, Portugal’s and Bulgaria’s ran to 2023; Denmark’s and Ireland’s to 2024; Cyprus’s to 2025. Poland’s 2019–2024 strategy has since been succeeded by a 2026–2029 one, and Slovakia adopted a 2026–2030 strategy — the two newest entries on the map [8]. Two caveats before quoting that as a compliance scorecard: ENISA builds the map “on publicly available material or the Member States have contacted us and provided the information”, so it lags reality; and an expired cover date proves nothing about whether the Article 7(4) assessment happened, since an assessment can properly conclude no update is necessary. The narrower, useful reading is that in several Member States the strategy you can download is older than the Directive it is meant to serve — so do not expect it to describe your NIS2 obligations.

On the state side, ENISA released version 2.0 of its National Capabilities Assessment Framework on 22 April 2026 to measure “the maturity of national cybersecurity strategies’ implementation” and help Member States prepare for the voluntary Article 19 peer review [9]. ENISA is explicit that it addresses policymakers and government officials — it is not an entity self-assessment tool, whatever a consultant may say.

What to do with your Member State’s strategy

Reading the whole document is a poor use of a quarter. Read it for four answers, by role.

Role What to extract, and why
Compliance officer The Article 7(1)(f) authority list. Confirm which competent authority supervises your sector and which CSIRT receives reports, then check it against the authority published under Article 8(6). Where the two disagree, treat the Article 8(6) publication as the current one — it carries a standing duty to notify the Commission of “any subsequent changes thereto”, which a strategy document does not.
CISO / security manager The 7(2)(j) active-protection and 7(2)(c) CVD policies. These reveal which free national services exist — Recital 57 anticipates “self-service checks, detection tools and takedown services” — and who will contact you about a reported vulnerability. Add the CVD coordinator to your inbound-security routing before you need it.
Procurement / sales lead The 7(2)(b) procurement policy, if you sell to government. It previews the certification, encryption and open-source clauses likely to surface in future tenders, before they arrive as draft contract terms.
SME owner outside scope The 7(2)(i) guidance and, where it exists, the Recital 56 national or regional SME contact point — free, state-endorsed baseline material to work through alongside a structured 90-day roadmap.

Start from ENISA’s national cybersecurity strategies hub rather than a search engine [11] — it links the current document per country, in English where a translation exists.

Frequently asked questions

Can my company be fined for something in the national cybersecurity strategy?
No. Article 7 places duties on Member States only. NIS2 administrative fines attach to breaches of the risk-management and reporting obligations, not to strategy documents.

How many elements does Article 7 actually require?
Eighteen: eight contents in Article 7(1)(a) to (h), and ten policies in Article 7(2)(a) to (j). The “nine elements” figure in circulation appears to merge the two lists and drop most of the second.

Does every Member State have to publish its strategy?
Article 7 requires adoption and notification to the Commission within three months, not publication, and allows national-security information to be withheld from the notification. In practice all EU Member States have published a strategy, and ENISA hosts them.

My country’s strategy is from 2019. Is it still valid?
Probably, in legal terms. Article 7(4) requires assessment at least every five years and an update only “where necessary”. An expired cover date signals the document may not reflect NIS2; on its own it does not establish an infringement.

Is the national strategy the same as my country’s NIS2 law?
No. The strategy is adopted under Article 7 and may consist of non-legislative instruments. The binding rules come from the national transposition required by Article 41(1) by 17 October 2024.

Sources

  1. Directive (EU) 2022/2555, Article 7 — National cybersecurity strategy: verbatim text.
  2. Directive (EU) 2022/2555, Article 7 and the Article 6 definition — independent verbatim cross-check.
  3. Directive (EU) 2022/2555, Preamble — Recitals 48, 53, 54, 56, 57 and 97.
  4. Directive (EU) 2022/2555, Article 41 — Transposition.
  5. Directive (EU) 2022/2555, Article 12 — Coordinated vulnerability disclosure.
  6. Directive (EU) 2022/2555, Article 29 — Cybersecurity information-sharing arrangements.
  7. Directive (EU) 2022/2555, Article 8 — Competent authorities and single points of contact.
  8. ENISA, National Cyber Security Strategies interactive map.
  9. ENISA, National Capabilities Assessment Framework 2.0, 22 April 2026.
  10. European Commission, NIS2 Directive FAQs.
  11. ENISA, National Cybersecurity Strategies hub.
  12. Directive (EU) 2022/2555, Article 22 — Union level coordinated security risk assessments.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: