This Practice Note tracks the key steps of legislative initiatives on cyber security in the EU. Key EU cyber security initiatives include: • Revised EU Cybersecurity Act (proposal published on 20 January 2026) • EU Cybersecurity Act (adopted, amendments adopted in January 2025) • Digital Operational Resilience Act or DORA (adopted, started to apply on 17 January 2025) • NIS 2 Directive (adopted, started to apply on 18 October 2024. Amendments proposed on 20 January 2026) • EU Critical Entities Resilience Directive or CER (adopted, started to apply on 18 October 2024) • EU Cyber Security Regulation (adopted, started to apply on 7 January 2024) • EU Cyber Resilience Act (adopted, starts to apply on 11 December 2027) • EU Cyber Solidarity Act (adopted, started to apply on 4 February 2025) All these initiatives are tracked in this document, except for DORA, which historical legislative progress is tracked in Practice Note: Operational resilience—timeline [Archived]. Note that several of these pieces of legislation will be impacted by the proposal for a Digital Omnibus on the digital acquis published