Full text
ū š A* j^lnvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe Long Policy Report on a Common Frame¬ work for the Protection of Critical Infra¬ structure in the EU and its Neighbourhood Authors Ram nas Vilpi auskas, Marts Ivaskis, Svitlana Chekunova, Danijela Jacimovic, Marco Siddi, Nana Tabagua, Teemu Tammikko H Funded by the European Union
ū š Executive Summary Long Policy Report on a Common Framework for the Protection of Critical Infrastructure in the EU and its Neighbourhood The report provides detailed analysis of the evolution and exiting policies of the EU in the field of the critical infrastructure (Cl) protection and resilience as well as structured assess¬ ment of how Cl related policies are adopted and implemented in selected EU Member States and candidate countries. To structure the comparative analysis of the national poli¬ cies and institutions it proposes an analytical framework based on the policy implementa¬ tion and compliance with EU norms literature focusing on the threat landscape, policy and institutional context as well as incentives and capacities for implementing Cl related poli¬ cies. This allows to provide an assessment of the current state of Cl related policies in three selected EU Member States and three candidate countries which is based on original ma¬ terial collected for the purpose of this report, including primary and secondary sources. The conclusions and recommendations section elaborates on the differences and similarities of national Cl related policies as well as challenges and opportunities for their alignment tak¬ ing into the functional needs originating from existing interdependencies as well as speci¬ ficities of national contexts. They also illustrate the ways and means of further contributions of the EU, in particular, the European Commission in advancing the goals of Cl related policies and their alignment in the enlarging EU and its neighbourhood. Authors Ram nas Vilpi auskas Professor Institute of International Relations and Political Science Vilnius University Svitlana Chekunova Research Associate The Razumkov Centre Marts Ivaskis Researcher / Head of the European Union Research Programme Latvian Institute of International Affairs (LIIA) Danijela Jacimovic Professor University of Montenegro (UoM)
Marco Siddi Assistant Professor Finnish Institute of International Affairs (FIIA) Teemu Tammikko Senior Research Fellow Finnish Institute of International Affairs (FIIA) Nana Tabagua Lead Researcher PMCG - Research Approved by: Funda Tekin, Director Institute for European Politics, Scientific Lead, InvigoratEU Michael Kaeding, Professor for European Integration and European Union Politics at the Department of Political Science at the University of Duisburg-Essen, Germany, Project Coordinator, InvigoratEU About InvigoratEU InvigoratEU is a Horizon Europe-funded project, coordinated by the EU-Chair at the University of Duisburg-Essen (UDE) together with the Institut für Europäische Politik (IEP) in Berlin. The project, with a duration of 5 years from January 2024 until December 2026, examines how the EU can structure its future relations with its Eastern neighbours and the countries of the Western Balkans. The consortium has received around three million euros for this endeavour.
DOI 10. 5281/zenodo. 17650178 License: This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivs 4,0 Unported License. Disclaimer: Views and opinions expressed are however those of the authors only and do not neces¬ sarily reflect those of the European Union or the European Research Executive Agency. Neither the European Union nor the granting authority can be held responsible for them. Funded by the European Union About the project: www.inviqorat.eu
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe Contents InvigoratEU | Policy Report 1 Introduction 2 2 Overview of the Evolution of EU-wide Framework 5 The Emergence of the EU-wide Framework on Cl Protection 5 From the ECI Directive to CER Directive 5 Evolution of EU-wide Policies in Cyber Security - from NISI to NIS2 8 The Symbiotic Nature of the CER and NIS2 Directives and Potential Challenges to their Implementation 10 Conclusion 12 3 The Analytical Framework for Assessing the Current State, Challenges and Ways for Improving the Alignment of Cl related Policies in selected EU Member States and Candidate Countries 13 The Literature on Policy Implementation and EU Compliance 13 The Alignment of Cl related National Policies - Guide for Analysis 16 4 The Analysis of Cl related Policies in Selected EU Member States and Candidate Countries 19 Finland 19 Latvia 25 Lithuania 31 Montenegro 40 Ukraine 49 Georgia 58 5 Conclusions and Recommendations 64 Bibliography 66 1
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report 1 Introduction This policy report provides analysis of the evolution of the rules on the protection and resilience of critical infrastructure (Cl) in the EU, its selected member states and candidate countries with a view to the need to align their policies and identifying the needs and opportunities to increasing connectivity between the EU and candidate countries. It builds on the policy report D.7.1, which discussed the evolving threat landscape in the Europe, the turn among policy makers and analysts from policy focus on protecting Cl to focusing on increasing its resilience as well as different challenges arising to Cl in the EU and selected candidate countries, provision of vital services to society, state and methods of coping with those challenges. It thus provides the assessment of the most recent policy trends and path¬ ways forward in the search for effective policy and institutional solutions in terms of aligning approaches of the EU Member States and candidate countries in facilitating integration of their economies and increasing their resilience in an increasingly hostile geopolitical environ¬ ment. As it will be discussed in the Chapter 2, the first EU-wide regulatory initiatives aimed at pro¬ tecting and, more than a decade later, increasing the resilience of critical infrastructure emerged in response to terrorist attacks in the US and some European countries in early 2000s. Although the EU legislative initiatives at the time focused on the threat of terrorism as a priority to be addressed, they adopted an all-hazards approach to the protection of Cl encompassing variety of threats ranging from man-made and technological to natural disasters. The evolution of the EU norms on protection and resilience of Cl presented in the Chapter 2 shows that during a decade the supranational norms were extended to cover more domains and increasingly more sectors in addition to shifting attention from protection to resilience. The expansion of the scope of Cl regulatory policy has been motivated by the growing inter¬ dependencies between member states as well as different sectors and Cl operators in the background of technological transformation and expanding landscape of threats. This func¬ tional spill-over was further complemented by geographical spill-over as candidate countries in the Western Balkans and, since geopolitical shock of 2022, Ukraine, Moldova and Georgia gradually aligned their policies with a view towards integrating into the EU, although at a different pace (and increasingly uncertain direction in the case of Georgia). However, the evolution of the EU-wide policy on protection and resilience of Cl was also partly motivated by the recognition of the evidence that actual application of common norms regu¬ lating Cl and the provision of vital services in its member states continued to diverge. This points to the need to be attentive to national politics and the patterns of state-society rela¬ tions, in particular, the perception of risks and threats since Russia's full-scale war against Ukraine and intensifying hybrid attacks against EU and NATO member states as well as com¬ peting external geopolitical influences in the candidate countries. Thus, the assessment of the current state of alignment with EU norms and their actual implementation in the EU member states and candidate countries should consider national context and factors, which influence how they actually regulate Cl in practice. For this purpose, the Chapter 5 develops an analytical framework based on the literature of policy implementation and compliance with EU norms. In addition to being attentive to the perception of threats, it proposes to focus on two sets of variables in the analysis of particular 2
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report countries' policies related to Cl protection and resilience - incentives and capacities. They emphasized by the enforcement and management approaches used by scholars investigating divergent patterns of compliance with EU norms. These factors are discussed in more detail to provide an analytical basis for a systematic analysis of the state of affairs in this policy field in selected countries allowing to discover the main commonalities and differences and, thus, providing the ground for evidence-based policy proposals on aligning norms and practices. Therefore, the Chapter 4 presents the systematic analysis of Cl related policies and practices in selected EU member states and candidate countries. Those are EU members Finland, Latvia and Lithuania, which are "front-line" states in terms of their geography as well as intensity of hybrid attacks faced in recent years. Also three candidate countries are analysed - Montene¬ gro, Ukraine and Georgia, which differ in terms of the perceived nature of threats, their state of integration with the EU and the state of transposition and implementation of EU norms. In terms of sectors, the analysis refers to the provision of vital services in two key sectors of Cl - energy and communications including both physical and cyber domains and relevant policies of their protection and resilience. The sectors are chosen due to their relative importance in most countries covered here. The report is based on the analysis of the relevant primary sources such as laws and other legal norms, security strategies (energy, cyber security, etc.), annual reports of relevant institutions, etc., and secondary sources such as available policy analyses and studies addressing those issues. They are supplemented by interviews with the key stakeholders in the ecosystem of Cl protection and resilience such as policy-making and regulatory institutions, Cl operators, rel¬ evant business associations, NGOs, experts. This comparative analysis provides the basis for policy recommendations regarding existing discrepancies in terms of having a common EU wide framework, the explanatory factors be¬ hind them and suggestions on increasing convergence and interconnectivity. These recom¬ mendations are presented in the concluding chapter of the report. 2 Overview of the Evolution of EU-wide Framework The Emergence of the EU-wide Framework on Cl Protection This chapter discusses the emergence of an EU-wide framework aimed at aligning policies of its Member States to protect and increase the resilience of Cl both in physical and cyber domains. After presenting the initial legal norms adopted by the EU it then discusses the two most important recently adopted legal norms -the so-called CER Directive and NIS2 Directive, which had to be transposed by Member States by 17 October 2024.1 They form the legal basis which should guide relevant policies of candidate countries as they align their legal norms in this policy area. 1 At the time of writing, the dedicated EUR-LEX website showed that only 14 member states notified about the national legal norms which were adopted to transpose CER Directive (see https://eur-lex.europa.eu/leqal-content/EN/NIM/?uri=CELEX:32022L2557 (accessed 16.07.2025)) and 19 member states notified about national legal norms transposing NIS2 Directive (see https://eur-lex.europa.eu/leqal-content/en/NIM/?uri=CELEX:52022L2555 (qccessed 16.07.2025)). 5
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report The protection of critical entities and the infrastructure which they operate is considered to be one of the EU's most important security and resilience priorities.2 These entities are consid¬ ered important to the functioning of the internal market and its four freedoms as well as daily lives of European citizens through the provision of essential services. Disruptions to their func¬ tioning and provision of services can cause severe economic consequences, undermine public confidence, and impact the ordinary lives and security of citizens across the Union. A formal EU-level approach on the protection of critical infrastructure can be traced back to the early 2000s, as a result of heightened security concerns following major terrorist attacks around the globe, such as those in the United States in 2001, Madrid in 2004, and London in 2005.5 These attacks ended up highlighting the vulnerability of EU infrastructural systems, and the cross-border impacts they might present. For example, energy grids, transportation net¬ works, financial systems, and digital communications infrastructure often cover multiple Mem¬ ber States. Therefore, a failure or disruption in one location could rapidly cascade, causing widespread disruption across the continent or a certain amount of Member States. This inher¬ ent cross-border character showed that, according to Article 5(5) of the Treaty on European Union (TEU) on the principle of subsidiarity, the EU could move forward with legislative pro¬ posals. In 2004, the Commission published the Communication on "Critical Infrastructure Protection in the Fight against Terrorism"4, and, in 2005, a Green Paper on a European programme for critical infrastructure protection5, in which stakeholders were consulted on the choice of policy approach. The result was the proposal for a European Programme for Critical Infrastructure Protection (EPCIP), which aimed to create a common EU framework for identifying and pro¬ tecting critical infrastructure.6 Echoing the anxieties of the time, the initial proposal was largely focused on the prevention of terrorism. The EPCIP framework included several components: the legislative basis (which became the European Critical Infrastructures Directive), the estab¬ lishment of a Critical Infrastructure Warning Information Network, the creation of specific ex¬ pert groups, and dedicated funding mechanisms.7 Directive 2008/114/EC (ECI Directive)8 was the first legislative step towards common Euro¬ pean standards for the protection of European critical infrastructure. The overall objective of 2 A 'critical entity' is an organisation designated by a Member State as essential for maintaining vital societal or economic functions, the disruption of which would have significant consequences. 5 Anglmayer, Irmgard: European Critical infrastructure: Revision of Directive 2008/115/EC, European Parliamentary Research Service (EPRS), February 2021, p. 1, available at https://www.europarl.europa.eu /Req Data /etudes /BRIE /2021 /662604/EPRS BRI( 2021)662604 EN.pdf (accessed 10.10.2025). 4 European Commission: Communication from the Commission to the Council and the European Parlia¬ ment - Critical Infrastructure Protection in the fight against terrorism, COM/2004/0702, 2004. 5 European Commission: Green Paper on a European programme for critical infrastructure protection, COM/2005/0576, 2005. 6 European Commission: "The European Programme for Critical Infrastructure Protection", MEMO/06/477, 12 December 2006, available at: http://ec.europa.eu/commission/presscorner/detail/en/memo 06 477 (last accessed 05.09.2025) 7 Ibid. 8 Council Directive 2008/114/EC of 8 December 2008 on the identification and designation of Euro¬ pean critical infrastructures and the assessment of the need to improve their protection, OJ L 545, 23.12.2008., p. 75/82. 4
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report the ECI Directive, as laid down in the Article 1, was to establish a common procedure for the identification and designation of European Critical Infrastructures (ECls) and to provide a common approach for assessing the need to improve their protection. Article 2(a) of the ECI directive provides that, firstly, critical infrastructure is an "asset, system or part thereof located on EU territory, which is essential for the maintenance of vital societal functions, health, safety, security, economic or well-being of people, and the disruption or destruction of which would have a significant impact on at least two Member States, as result of the failure to maintain those functions." Meanwhile Article 2(b) defines an ECI as "critical infrastructure located in Member States the disruption or destruction of which would have a significant impact on at least two Member States. The significance of the impact shall be assessed in terms of cross-cutting criteria. This includes effects resulting from cross-sector dependencies on other types of infrastructure". Therefore, the ECI Directive revolved around infrastructure with a cross-border element. The ECI Directive also had a very narrow scope, limited to just two sectors: Energy and Transport.9 Nuclear facilities were excluded, and while the potential future inclusion of the Information and Communication Technology (ICT) sector was mentioned in Article 5(5) and Recital (5) of the ECI Directive, it was not covered. The Directive established specific mechanisms. For the identification and designation of ECls, Articles 5 & 4 of the ECI Directive stated that Member States were responsible for identifying potential ECls within their territory based on cross-cutting criteria (potential casualties, eco¬ nomic impact, public effects) and sector-specific criteria. Importantly, the formal designation of an infrastructure as an ECI involved a bilateral or multilateral process, where other poten¬ tially affected Member States would be notified and have opportunities to provide input. After designation, the ECI Directive provided specific obligations for the operators of ECls. Crucially, according to Article 5 of the ECI Directive, the owners or operators of ECls had to develop an Operator Security Plan (OSP), which consisted of identifying assets, conducting risk assessments, and identifying security measures. Next to the OSP, each operator or owner of an ECI also had to designate a Security Liaison Officer (SLO) to act as a contact point between the ECI and the national authorities (Article 6 ECI Directive). Finally, Member States also had reporting obligations - providing the Commission with relevant information on risks, threats and vulnerabilities in the ECls on the territory of the respective Member State (Article 7). From the ECI Directive to CER Directive During the 2010s multiple academic analyses, evaluations of the ECI Directive, and a Commis¬ sion 2019 study on the ECI Directive identified that the impact of the ECI directive was limited and its implementation uneven.10 9 Ibid. Annex I. 10 European Commission: Evaluation study of Council Directive 2008/114 on the identification and des¬ ignation of European critical infrastructures and the assessment of the need to improve their protection, 2 April 2019, available at: https://op.europa.eu/en /publication-detail/-/ publication/118dcd5d-b041llea-bb7a-01aa75ed71al/languaqe-en (last accessed 05.09.2025). 5
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report of the CER Directive, leading to companies taking decisions on ensuring resiliency based on cost-efficiency rather than effectiveness.25 Finally, it should be noted that while the NIS2 Directive and the CER Directive are arguably the most notable and most directly concerned legislation on the protection and resilience of crit¬ ical infrastructure, there are other legislative and non-legislative mechanisms within the EU that are connected to this policy field. One such example is Regulation 2019/941 on risk-pre¬ paredness in the electricity sector, which provides a system for Member States to assess risks and identify possible electricity crisis scenarios. 26 In that regard, the Directive requires Member States to prepare national risk-preparedness plans and strengthens cross-border cooperation. Similarly, Regulation 2017/1958 on gas supply security27 also requires Member States to con¬ duct risk assessments and develop preventive action and emergency plans in crisis situations, as well as strengthening Member State solidarity and cooperation. Furthermore, the protection of critical infrastructure is not limited to legislative acts, but also strategy documents. For ex¬ ample, the EU Security Union Strategy 2020 - 2025, EU Preparedness Union Strategy and the EU Counter-Terrorism Agenda, as well as the EU Toolbox on 5G Security are all important frameworks, strategies and approaches that impact the protection of critical infrastructure in the European Union. Conclusion The emergence of the EU-wide framework for the protection of Cl reflects a gradual evolution from fragmented national measures to a coordinated, harmonised European approach, which is based on shared security and resiliency objectives. The initial framework, born out of post9/11 counter-terrorism concerns, laid the groundwork for identifying and protecting assets, which could affect multiple Member States, if they were to be disrupted. However, the ECI Directive was limited in scope both conceptually and regarding the covered sectors. As the EU continued developing, the increasing interconnectedness of sectors, the evolving digital interdependencies, and the growing complexity of hybrid and cyber threats revealed the need for a broader and more adaptive policy framework. The development of the subse¬ quent CER and NIS2 Directives marks a maturation of the common European approach, mov¬ ing away from a focus on the protection of specific Cl, to a more comprehensive system aimed at ensuring the resilience of CEs, not only against counter-terrorism and physical threats, but against all hazards, both physical and digital. In essence, the EU framework for the resilience of Cl has evolved from reactive, sector-specific measures to an integrated resilience-based strategy. This transformation underscores a shift 25 Ibid. 26 Regulation (EU) 2019/941 of the European Parliament and of the Council of 5 June 2019 on risk¬ preparedness in the electricity sector and repealing Directive 2005/89/EC, OJ L 158, 14.6.2019. p. 1 - 21. 27 Regulation (EU) 2017/1938 of the European Parliament and of the Council of 25 October 2017 con¬ cerning measures to safeguard the security of gas supply and repealing Regulation (EU) No 994/2010. OJL280, 28.10.2017, p. 1 - 56. 12
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report in the Union's understanding of security. At the same time, as noted above, it also raises im¬ portant challenges in terms of aligning Cl policies among countries and their practical imple¬ mentation. 5 The Analytical Framework for Assessing the Current State, Chal¬ lenges and Ways for Improving the Alignment of Cl related Policies in selected EU Member States and Candidate Countries The Literature on Policy Implementation and EU Compliance The evolution of the EU-wide norms on protection and resilience of Cl shows that during the last 10-15 years the supranational norms were extended to cover more domains (physical and cyber) and increasingly more sectors (from two to six to eleven) in addition to shifting attention from protection to resilience. The expansion of the scope of Cl regulatory policy has been presented by the European Commission as motivated by the growing interdependencies be¬ tween Member States as well as different sectors and Cl operators in the background of tech¬ nological transformation and expanding landscape of threats. According to scholars following these policy developments, they seem to fit three different, but compatible accounts of European integration: (neo)functionalist integration which takes place in response to the functional demands of economic entities and member states in re¬ sponse to growing cross-border interdependences, technological developments and changing external threats; European “multi-level governance" with different competencies being as¬ signed to different levels of governance while member states guard their national security competencies and at the same time aim to increase protection and resilience of Cl in a coor¬ dinated way; and "principle-agent approach" when member states decide to delegate certain functions to the European Commission because it has relevant expertise and better equipped to deal with information asymmetries.28 Moreover, one could add that after the revival of the EU enlargement agenda by the Russia's unprovoked full-scale war in 2022, this functional spill-over is in the process of being supplemented by geographical spill-over as prospective members align their Cl policies with above discussed EU norms. However, the conclusion that this regulatory evolution "attests to increasing regulation of the Cl sector, both deepening and widening the supranational tendencies in this field" has been so far based on the assessment of the regulatory norms adopted on the EU level.29 In other words, as it is well know from the implementation studies in political science generally and from the compliance studies within the EU member states more concretely, the same EU norms can be transposed and implemented differently in different member states. This has also been 28 Christer Pursiainen/Eero Kytomaa: From European critical infrastructure protection to the resilience of European critical entities: what does it mean? In Sustainable and Resilient Infrastructure, 8 (1), 2022, p. 95-96. 29 Christer Pursiainen/Eero Kytomaa: From European critical infrastructure protection to the resilience of European critical entities: what does it mean? In Sustainable and Resilient Infrastructure, 8 (1), 2022, p. 97. 15
ž ū •^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report the case with the ECI Directive and NIS Directive, as noted above in the discussion of the arguments provided by the European Commission for the need to upgrade the EU legislative framework. Besides, as studies of the Cl policies in the Baltic States (and Norway) illustrate, even countries with such a similar threat perception and recent history of institutional reforms as well as EU and NATO accession as Estonia, Latvia and Lithuania can have rather different approaches to protecting Cl.50 All of the above-mentioned studies, however, do not systematically analyse the causes of the divergence of Cl protection policies in the EU member states. This policy report aims to fill this gap in advancing the knowledge of Cl policy implementation and coordination issues which so far have been mostly assessed from the technical and engineering perspectives.51 Analyses of how threat perception is translated into Cl protection and resilience policy, how it interacts with the adoption of the EU-wide framework and which factors affect the implementation of these policy measures within selected EU member states as well as candidate countries could provide useful academic and policy relevant insights into advancing our understanding of this policy area and the alignment of functional needs originating from interdependencies with national policies and politics. This could also shed more light on the differences between pro¬ tecting and enhancing resilience of information (cyber) infrastructure compared to physical infrastructure. There is a rich body of literature which has been developed during the recent decades on policy implementation and compliance with EU norms. Originating from the US in 1970s, the studies of policy implementation pointed to the importance of paying closer attention to what happens after policy decisions are made and legal norms are adopted, pointing to the ample evidence that implementation results, outputs and outcomes deviate from those initially in¬ tended.52 The policy implementation studies focused on conditions of efficient and effective implementation pointing to the importance of clearly defined policy goals and objectives, and the agreement regarding them between participating institutions and stakeholders, proper causal theory to guide the choice of policy measures, proper institutional structure allowing to avoid overlaps of responsibilities, coordinate and communicate effectively as well as learn from implementation experience, adequate resources (personnel, funding, expertise, time) and taking into account external factors such as changing technological, political, economic and social circumstances.55 These insights have been later used in studying implementation of the 50 Maris And ans/Andris Spr ds/Ulf Sverdrup (eds.): Critical Infrastructure in the Baltic States and Nor¬ way: strategies and practices of protection and communication, Latvian Institute of International Affairs, 2021. 51 See, for example, Tim Prior: Measuring Critical Infrastructure Resilience: Possible Indicators, Risk and Resilience Report 9, Centre for Security Studies (CSS), ETH Zurich, 2014; Roberto Setola/Eric Luiijf/Marianthi Theocharidou: Critical Infrastructures, Protection and Resilience, in: Roberto Setola et al. (eds.) Managing the Complexity of Critical Infrastructures. A Modelling and Simulation Approach. SpringerOpen, 2016; European Commission: European Reference Network for Critical Infrastructure Pro¬ tection: ERNCIP Handbook 2018 edition, Joint Research Centre Technical report, 2018. 52 In this respect the full title of the study which initiated policy implementation debates is very instructive - Jeffrey L. Pressman/Aaron Wildavsky: Implementation. How great expectations in Washington are dashed in Oakland; or, why it's amazing that federal programs work at all, this being a saga of the economic development administration as told by two sympathetic observers who seek to build morals on a foundation. University of California Press, 1973. 55 See Brian W. Hogwood/Lewis A. Gunn: Policy analysis for the real world. Oxford University Press, 1984; Daniel A. Mazmanian/Paul A. Sabatier: Implementation and Public Policy. Bloomsbury Academic, 1989; 14
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report EU norms within the multi-level polity, especially since early 1990s as European integration advanced with the relaunching of the Single market project, Economic and monetary union and various regulatory policies aimed at dealing with externalities crossing borders and grow¬ ing interdependencies.* 54 The EU compliance studies have focused on the implementation of EU norms, often pointing to the uneven record of transposition and investigating possible causes of the uneven prac¬ tices. Some studies, representing state-based explanations, linked the difficulties in EU mem¬ ber states' compliance and implementation of EU norms to the lack of administrative capaci¬ ties, for example, government inefficiency or corruption.55 Other state-based explanations pointed to the importance of national public opinion and argued that higher support for Eu¬ ropean integration facilitates implementation of EU norms.56 The non-compliance has also been explained by high institutional misfit between the EU-wide norms and national status quo as well as preferences or beliefs held by domestic, political, administrative and social actors.57 Other research found that non-compliance resulted from national preferences when they were ignored during the stage of negotiations of particular directive as an incentive to deviate from it during the process of implementation as well as the amount of discretion granted to member states.58 Furthermore, examining large data sets of detected violations of EU legal norms au¬ thors assessed several dominant explanations proposed by enforcement, management and legitimacy approaches and concluded that powerful EU member states tend to violate EU law more often while best compliers are small countries with efficient bureaucracies.59 The related stream of EU external governance studies found that the effectiveness of EU rules transfer to Paul A. Sabatier: Top-Down and Bottom-Up Approaches to Implementation Research: a Critical Analysis and Suggested Synthesis, In Journal of Public Policy, 6(1), 1986, p. 21-48. 54 For an example of the discussion of the factors of successful policy implementation inspired by im¬ plementation studies in the context of implementing EU norms see Dionyssis Dimitrakopolous/ Jeremy Richardson: Implementing EU public policy, In Jeremy Richardson (ed.) European Union. Power and Pol¬ icy-making, Routledge, 2nd edition, 2001, p. 335-356. 55 See Carmel Coyle: Administrative capacity and the implementation of EU environmental policy in Ireland, in Regional Politics and Policy, 4, 1994, p. p. 62-79; Geoffrey Pridham: National environmental policy-making in the European framework: Spain, Greece and Italy in comparison, in Regional Politics and Policy, 4, 1994, p. 80-101; Heather Mbaye: Why national states comply with supranational law: ex¬ plaining implementation infringements in the European Union, 1973-1993, in European Union Politics, 2, 2001, p. 259-81. 56 Peter Lampinen/Petri Uusikyla: Implementation deficit - why member states do not comply with EU directives, in Scandinavian Political Studies, 21, 1998, p. 231-251. 57 See Christoph Knill/Andrea Lenschov: Coping with Europe: the impact of British and German admin¬ istrations on the implementation of EU environmental policy, In Journal of European Public Policy, 5(4), 1998, p. 595-614; Christoph Knill/Dirk Lehmkuhl: The national impact of European Union regulatory policy, in European Journal of Political Research, 41(2), 2002, p. 255-280; Viktoria Brendler/Eva Thomann: Does institutional misfit trigger customisation instead of non-compliance? In West European Politics, 47(3), 2024, p. 515-542. 58 See Robert Thomson/Rene Torenvlied/Javier Arregui: The Paradox of Compliance: Infringements and Delays in Transposing European Union Directives, in British Journal of Political Science, 37, 2007, p. 685709. 59Tanja A. Borzel/Tobia Hofmann/Diana Panke/Carina Sprungk: Obstinate and inefficient: why member states do not comply with European law, in Comparative Political Studies, 43(11), 2010, p. 1363-1390. 15
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report candidate countries depended on the credibility of EU conditionality and the domestic costs of rule adoption.40 As the EU enlarged, in particular with the "big bang" enlargement into Central and Eastern Europe in 2004-2007, increasingly more attention has been devoted to the compliance with EU norms in "old" and "new" member states or extending existing classifications of EU member states on the basis of their record of compliance to Central and Eastern European countries. The main finding was that most "new" member states, especially Baltic countries, showed rel¬ atively positive record of compliance, generally far better than most "old" member states.41 It was hypothesized that it might be explained by a greater susceptibility of new member states to naming and shaming by the European Commission and an institutional investment in legis¬ lative capacity (although in some Central European states such as Hungary or Poland the com¬ pliance with EU law, including the principle of the rule of law, has become a matter of con¬ troversy since 2010s-2015s highlighting the importance of shifting domestic political incen¬ tives). Other scholars argued that surprisingly good compliance record of recently acceded EU mem¬ ber states might be an outcome of the difference between purely formal compliance and actual non-compliance in practice ("the world of dead letters"), which was, however, more difficult to assess.42 Others came to the conclusion that neither this, nor other dominant ap¬ proaches of enforcement, management and legitimacy could convincingly explain why Central and Eastern European countries showed better compliance record compared to other EU member states.45 They hypothesized that pre-accession conditionality could explain why these new member states performed so well. However, this explanation could be linked back with factors emphasized by enforcement and management approaches, as pre-accession condi¬ tionality forms strong incentives for candidate countries to comply with EU norms in order to advance in their process of accession into the EU - of course, provided that there is a domestic political consensus on the goal of EU membership - and, at the same time, they benefit from EU technical and financial assistance measures aimed at improving their administrative ca¬ pacities to comply with EU norms . The Alignment of Cl related National Policies - Guide for Analysis This section presents the analytical framework for the qualitative analysis of implementing Cl related policies, especially their alignment with EU-wide norms, in selected EU member states and candidate countries based on the above reviewed studies. It adopts the argument pro¬ posed by Jonas Tal I berg that compliance with international regulatory agreements can be best achieved when two approaches of enforcement and management are combined to make 40 Frank Schimmelfennig/Ulrich Sedelmeier: Governance by conditionality: EU rule transfer to the can¬ didate countries of Central and Eastern Europe, in Journal of European Public Policy, 11(4), August 2004, p. 661-679. 41 Ulrich Sedelmeier: After conditionality: post-accession compliance with EU law in East Central Eu¬ rope, in Journal of European Public Policy, 15(6), September 2008, p. 806-825. 42 Gerda Falkner/Oliver Treib: Three worlds of compliance or four? The EU-15 compared to new member states, in Journal of Common Market Studies, 46(2), 2008, p. 293-513. 45 Tanja A. Borzel/Ulrich Sedelmeier: Larger and more law abiding? The impact of enlargement on com¬ pliance in the European Union, in Journal of European Public Policy, 24 (2), 2017, p. 197-215. 16
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report them more effective.44 In other words, enforcement, which focuses on the calculus of actors, whether it pays-off to comply with particular norms seeing it as a matter of incentives, and management, which sees compliance failures as originating from then lack of capacities (i.e. lack of information, expertise, funding) are seen as complimentary rather than alternative ap¬ proaches. Although it is not the objective of this policy report to come up with comparative assessment of which countries comply with Cl norms most, the analysis of the factors seen as relevant for the effective compliance can provide important material in advancing our understanding of the state of Cl protection and resilience in the EU and candidate countries and the factors behind it. First, however, drawing on the policy implementation literature which underlines the agree¬ ment of the participating institutions and stakeholders on policy as well as taking into account the importance of threat (or risk) perception for the implementation of Cl related policy measures, it points to the need to be attentive to how they are outlined in the relevant national policy documents, strategies and other legal norms. The evidence of alignment of views re¬ garding threats to Cl - arguably a key precondition for the agreement on the goals such as Cl protection and resilience - and policies aimed at mitigating or managing them among the key participants in the Cl related policy subsystem on supranational, national and micro levels should signal conditions conducive to effective policy implementation. Second, it is important to assess the institutional context of Cl related national policy formation and implementation: how are the institutional roles and responsibilities defined, are there over¬ laps or gaps in terms of national coordination and communication processes, how learning takes place. These sets of policy and institutional characteristics should be outlined before moving to the discussion of incentives and capabilities to implement Cl related policy measures as proposed by the enforcement and management approaches. Third, the factors stressed by the enforcement and management approaches should provide a more nuanced discussion of the current state of Cl policies in the selected countries, chal¬ lenges they face and directions to increase their effectiveness. The enforcement approach, focused on the structure of incentives, stresses coercive strategy of monitoring and sanctions and should direct attention to the instruments that both European Commission and national regulatory authorities monitoring compliance with Cl protection and resilience norms use with respect to operators/owners of critical infrastructure. It should be guided by the analysis of how monitoring procedures of risks assessments, designating responsible officers, reporting, conducting exercises, etc. are outlined and practically applied in particular country both with respect to physical Cl and information Cl (cyber), acknowledging that in practice both are interrelated. It should also assess the use of sanctions when non-compliance is detected - what types of sanctions are used by the EU and national institutions, are they consistently applied in practices, etc. It should be noted, that EU incentives and sanctions vary depending on whether the country is an EU member state or candidate country, as discussed by the liter¬ ature on conditionality of EU accession. 44 Jonas Tallberg: Paths to Compliance: Enforcement, Management and the European Union, in Interna¬ tional Organization, 56 (3), summer 2002, p. 609-643. 17
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report Meanwhile management approach with its focus on capabilities stresses the importance of capacity (administrative resources and expertise) building, rule interpretation and transpar¬ ency. This problem-solving approach focuses on technical assistance and advice with tech¬ nical matters such as the methodologies of risk assessment, learning through joint exercises with partner countries, building trust between state and private actors. Again, the country analysis should allow to compare which types of problem-solving instruments are employed by the EU and national authorities, how they compare between different EU Member States as well as Member and candidate countries, how operators/owners assess the usefulness of those instruments and what do they lack. The comparative analysis of factors outlined by each of those two approaches combined should allow to identify constraints and trade-offs faced by the authorities and opera¬ tors/owners of critical entities and possible ways of improving the protection and resilience of Cl from public policy perspective and coordination within the EU (and partner countries). Importantly, as noted above, the analysis should be based on the assessment of local (national) threat perceptions, including threats posed by Russia and other hostile actors, as well as cor¬ responding measures to improve protection and resilience of Cl and how these measures align with the relevant EU norms or are transformed during their transposition and practical imple¬ mentation. The importance of external factors on the implementation of particular public pol¬ icies has been stressed by implementation studies for a long time but it is even more relevant for the analysis of implementing Cl policies since the latter explicitly aim at minimising the impact of potential threats. The analysis based on the above presented framework should also allow to assess the chal¬ lenges related to the practical implementation of CER and NIS2 directives discussed in the section 2.4 of this report. Attention to institutions and policies as well as incentives and ca¬ pabilities should allow to provide a more nuanced picture of the need for additional resources and the trade-off between cost-efficiency and effectiveness of Cl protection and resilience policies as well as persistence of fragmentation between national Cl policies as applied by countries' authorities and Cl operators. To be sure, there are important constraints to such qualitative national analyses which should be outlined at the outset. One has to do with the fact that EU legal norms, which should refo¬ cus Cl policies of EU member states from protection to resilience, have been only recently adopted and currently are being transposed. The CER and NIS2 Directives are only now being implemented and some of their provisions should be put into practice only in the coming years. This issue of the moving target is even more acute for candidate countries which, depending on their progress in adopting EU norms, are in the early stage of the Cl policy alignment. Even more complexity is added by another moving target - constantly evolving landscape of threats as illustrated by the debates focusing on the undersea incidents affecting electricity and communications cables in the Baltic Sea in winter 2024-2025 and in summer 2025 on the need for improved protection against drones in EU/NATO Eastern flank countries. However, while these constraints are important, there is already a decade of experience with EU member states having in place national Cl protection policies and a patchwork of measures which aim at protecting Cl in all candidate countries. Therefore, analysis of primary and sec¬ ondary sources (i.e. national security strategies, public statements, annual reports of respon18
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report sible authorities, etc.) as well as interviews with stakeholders from sectoral business associa¬ tions and experts, who are easier accessed than officials, guided by the questions informed by the literature on policy implementation and compliance studies can provide original and policy relevant insights. It should also be noted, that national policies of Cl protection and resilience are often subject to confidentiality constraints and limits on information provided to the public and researchers due to national security concerns. This has indeed turned out to be an obstacle signalled by the authors of several country studies presented below, limiting their possibilities to conduct interviews with officials, regulators and operators of Cl entities. The comparative analysis of the Cl protection and resilience policies in response to external threats and EU norms and their implementation will focus on three EU member states, i.e. Finland, Latvia and Lithuania as well as three candidate countries, which are all in different stages of their integration into the EU - Montenegro, Ukraine and Georgia. Although the lim¬ ited length of the policy report does not allow to go deeper into analysis of particular Cl sectors, the country studies will refer energy and communications sectors, allowing to assess Cl policies with respect to both physical and informational/digital Cl protection and resilience, taking into account national specificities. Thus, each of the country case study presented below follows a common structure and ana¬ lytical framework by, first, discussing the (perception of) threats in the respective country and their evolution in recent years, then, outlining the institutional and policy context, relevant from the point of view of Cl protection and resilience, and, finally, assessing the changes and chal¬ lenges related to incentives and capacities of further strengthening Cl resilience . 4 The Analysis of Cl related Policies in Selected EU Member States and Candidate Countries Finland Threat landscape Finland is subject to low level of risks related to natural disasters, although its harsh climate does pose certain challenges to critical infrastructure objects, their surveillance and protec¬ tion. Preparations for these well-known and long-standing 'natural' risks have existed for a long time; they have recently been complemented and adapted to the changing environmen¬ tal situation, for instance by the National Climate Change Adaptation Plan 2050.45 Regarding the man-made hazards, the situation is somewhat different and in flux. Intentional actions targeting critical infrastructure - like sabotages, terrorism, or hybrid interference - are likely. Terrorist attacks targeting critical infrastructure are rare, but there have been waves of 45 Ministry of Agriculture and Forestry of Finland: National Climate Change Adaptation Plan 2030, 2 April 2024, available at: https:// mmm.fi/en/ nature-and-climate/ climate-change-adaptation/ national-climate-change-adaptation-plan-2030 (last accessed 24.10.2025). 19
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report violent extremism in the recent past with attacks on railway networks and road logistics,46 and it is not impossible that they could be repeated. Hybrid interference stemming from Russia is frequent and has taken many forms even prior to 2022 and Finnish accession to NATO. Be¬ tween 2025 and 2025 there was a wave of incidents undersea damaging critical infrastruc¬ ture, and the Finnish authorities have frequently reported suspicious surveillance activities in the proximity of drinking water and energy supply facilities. Whilst most of the incidents have not yielded evidence on possible state involvement, they are fully in line with Russian hybrid interference activities in Finland and elsewhere in the Russian neighbourhood. Due to the strong political consensus in Finland that the threats to Finnish critical infrastructure are stemming from Russia, the events since 2022 have only fortified the understanding that preparedness to all-hazards is the key to enhancing resilience in Finland. Country's decision to become a member of NATO after 2022 Russia's full scale war against Ukraine also illustrates the widely shared perception of the escalation of threats posed by authoritarian Russia and the need for additional deterrence. Policy and institutional context Finnish critical infrastructure resilience and security of supply are in many ways distinct from most European countries, including the ones compared in this report. The closure of the Finn¬ ish-Russian border and the end of nearly all traffic across the Eastern border after the Russia's full-scale attack against Ukraine in February 2022 makes Finland almost an island. Conse¬ quently, nearly 80 per cent of the Finnish export and import of material goods are currently transported via maritime routes.47 Moreover, Finland is highly dependent on the undersea en¬ ergy and communication cables and pipelines that connect it to the European grids and net¬ works. Dependence on maritime routes has logically impacted on Finnish priority setting. Even though Finland is facing similar threats to its critical infrastructure as most of its peers, such as cyber¬ attacks and natural disasters, understandably much of the political focus in the critical infra¬ structure protection has been put on maritime logistics and undersea structures, and how to enhance the security of supply through alternative routes in the case that the main routes fail. This approach has only been fortified after four suspected sabotages occurred in the Baltic Sea in a relatively short period of time, between October 2025 and January 2025.48 In all cases, undersea structures connecting Finland and Estonia, or Finland and Sweden were dam¬ aged by a ship dragging unnecessarily an anchor over the cables. Although none of the cases 46 Tammikko, Teemu: Vihalla ja voimalla: poliittinen väkivalta Suomessa, Helsinki: Gaudeamus 2019. 47 Merikuljetukset Suomessa: Logistiikan Maailma, 5 March 2025, available at: https:// mmm.fi/en/nature-and-climate/ climate-change-adaptation/ national-climate-changeadaptation-plan-2050 (last accessed 24.10.2024). 48 As discussed in deliverable D7.1, these sabotages began around a year after two major Russian gas pipelines meant for export to Germany and the EU, the Nord Stream pipelines, were sabotaged, con¬ ducted most likely by Ukrainian nationals. 20
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report made significant damage to the Finnish security of supply, the authorities enhanced their pur¬ suing and surveillance capacities and leaned on international cooperation in the EU and NATO context.49 In Finland, discussions on resilience and preparedness - both in terms of physical infrastructure and of the functioning of society as a whole - have focused on the concept of comprehensive security. In this concept, the vital functions of society in a crisis are taken care of in collabo¬ ration between the authorities, business community, civil society organisations and citizens in all circumstances and at all levels of society. This is an "all-hazard" approach. The crises may stem from human actions, technological de¬ velopments, or natural causes, and are addressed through strategic tasks defined for different actors. Executing tasks requires preparedness, namely measures to respond to threats, infor¬ mation sharing and effective implementation among multiple actors in different sectors.50 Such measures are meant to reduce the likelihood of threats realising and to promote society's readiness to face threats. Individuals are seen as key security actors, and mutual trust among people is considered a vital element in upholding society.51 This is the discursive and concep¬ tual context within which the transposition of the CER and NIS2 directives has occurred. From an institutional standpoint, significant measures had been taken already during the 2010s. In 2013, a Security Committee was created to assist the government and ministries in broad matters pertaining to comprehensive security, including 20 members and 4 experts from administrative branches, authorities and the business community. Recognising the value of the Finnish model for comprehensive security and national prepar¬ edness, where resilience is taken care of collaboratively by authorities, business community, organisations and citizens in all circumstances and at all levels of society, in March 2024 European Commission President Ursula von der Leyen tasked former Finnish President Sauli Niinisto with drafting a report on how the EU could enhance its civilian and military prepared¬ ness in the face of different crises.52 The report argued for more extensive foresight capacities and intelligence sharing at the EU level, as well as more centralized decision-making mecha¬ nisms for crisis situations. Based on the Finnish model, the report also emphasized that pre¬ paredness is not the responsibility of government authorities alone but should be pursued in close cooperation with the private sector and relevant civil society actors. Niinisto's report was quickly transformed into three different papers from the Commission services: the White Paper 49 On the incidents and responses to them, see for example Teemu Tammikko: The EU and NATO in pursuit of better deterrence: Baltic Sea sabotage prompts rethink of current prac¬ tices, FIIA Briefing Paper 404, January 2025. 50 For further details on the origins and articulation of the Finnish comprehensive security model, see Valtonen, Vesa/Minna Branders: Tracing the Finnish Comprehensive Security Model, in: Sebastian Larsson/Mark Rhinard (eds.): Nordic Societal Security: Convergence and Divergence, Routledge, 2020. 51 Finland's Security Committee: Comprehensive Security, 23 June 2025, available at: https: //turvalIisuuskomitea.fi/en/comprehensive-security/ (last accessed 24.10.2025). 52 The report, entitled 'Safer Together - Strengthening Europe's Civilian and Military Preparedness and Readiness', is available at https:/ /com mission. europa. eu /document/download /5bb2881f-9e29-42f 28b77-8739bl9d047c en?filename=2024 Niinisto-report Book VF.pdf(last accessed 24.10.2025). For an analysis, see Tuomas Iso-Markku/Niklas Helwig, The Niinisto report on preparedness: Finland's lessons for the EU and their limitations, FIIA Comment 9, 2024, https://fiia.fi/en/publication/the-niinisto-report-on-preparedness. 21
ā •^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report sessions with both their sectoral ministry and the MoD. This way the government ensures that it is aware of civilian resources and plans, and can integrate them into national defense strat¬ egies.77 In that regard, there is now a legal requirement that each critical infrastructure's con¬ tinuity plan must be coordinated with the respective sectoral ministry and the MoD.78 With regard to EU legislation on Cl protection and resilience, Latvia has transposed the CER Directive into national law. The Mol proposed amendments to the National Security law to bring into alignment with the CER Directive through introducing the concept of "critical entity resilience", updating criteria for identifying European-level "critical entities of particular im¬ portance", as well as adding amendments to empower the Cabinet of Ministers to set detailed rules on incident report, continuity measures, and resilience standards.79 Although Latvia missed the original October 2024 EU deadline, it moved swiftly in 2025, having the amend¬ ments first be approved by the Cabinet of Ministers in March 2025, and then by the Saeima (Parliament) in June 2025.80 With regard to the NIS2 Directive, Latvia has fully implemented its requirements through the new National Cyber Security Law,81 which was adopted on June 20, 2024, and came into force on September 1, 2024. This law replaced the older 2018 Infor¬ mation Technology Security Law, significantly expanding the scope of regulated entities and strengthening obligations. Following the transposition of the NIS2, Latvia now designated "es¬ sential" and "important" service providers across a broad range of industries, who must adhere to cybersecurity risk-management and reporting rules, leading to an increase of both sectors and private actors, who now fall under the NIS2 directive's scope. Incentives and capacities for implementing Cl related policy measures Latvia's primary incentive to strengthen Cl protection is largely based on national survival and security. The risk of large-scale disruptions caused by an adversary has been made real by both historical events and the current war in Ukraine. This threat perception creates strong political incentives to implement protective measures. Additionally, the comprehensive ap¬ proach of NIS2 and CER Directives aligns with the Latvian approach of CND. The expanded sectoral scope under CER resonates with authorities and Cl operators on all levels - threats are becoming more widespread and interconnected.82 Furthermore, the CER and NIS2 directives have acted as an anchor for national policy measures in Cl protection. The implementation of NIS2 directive through a new, restructured 77 Interview with representative of "Latvijas Mobilais Telefons". 78 Regulation of the Cabinet of Ministers No. 508, "Procedures for the identification, security measures and business continuity planning and implementation of critical infrastructure, including European crit¬ ical infrastructure" July 6, 2021. Accessible on: https:/ /likumi.lv/ta/id/324689-kritiskas-infrastrukturastaia-skaita-eiropas-kritiskas-infrastrukturas-apzinasanas-drosibas-pasakumu-un-darbibas-nepartrauktibas-planosanas-un-istenosanas-kartiba. 79 Ministry of the Interior: Government strengthens critical infrastructure resilience and national security, 21.03.2025, available at: https://www.iem.qov.lv/en/article/qovernment-strenqthens-critical-infrastructure-resilience-and-national-security (last accessed 16.09.2025). 80 Ibid. 81 "Law on National Cybersecurity" June 20, 2024. Accessible on: https://likumi.lv/ta/id/353390nacionalas-kiberdrosibas-likums. 82 M rcis Balodis/Marta Kepe: Lessons from Latvia's Efforts to Keep Essential Services Running During a Crisis, Atlantic Council - New Atlanticist, 07.05.2025, available at: https:/ /www.atlanticcouncil.org /bloqs/new-atlanticist/lessons-from-latvias-efforts-to-keep-essential-services-runninqduring-a-crisis/ ( Iqst accessed 15.09.2025). 28
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report and reorganised Cybersecurity law has given both the authorities and operators of Cis a clear, up-to-date structure to address cyber threats. Rather than reinvent the wheel, Latvian policy makers implement EU directives faithfully, choosing to build additional national measures on top to address specific geopolitical concerns. It would also be prudent to mention that EU infringement proceedings are also a major driver of compliance through their coercive effect. They are perceived as very costly, especially for smaller states. This is affirmed by the historical context of Latvia's track record with transposi¬ tion of EU legislation, as Latvia did not have any infringement proceedings initiated against it by the EUCJ until 2024, when the Court delivered a judgment against Latvia for failing to transpose the European Electronic Communications code. Finally, additional incentives such as attracting investment and increasing economic growth through providing reliable energy and communications services can also be identified.85 De¬ spite all of the incentives, Latvia along with most EU Member States failed to transpose the CER and the NIS2 Directives within the allotted time in 2024, pointing to the conclusion that the failure did not arise out of a faulty or inadequate incentive structure, but rather due to insufficient capabilities. Therefore, Latvia has continuously invested expertise and resources in strengthening its ca¬ pacity and capabilities, when it comes to implementing EU minimum standards on Cl protec¬ tion. To ensure compliance with CER and NIS2 Directives, as well as Latvian national require¬ ments, the government has incrementally raised budgets for security and defence. As a result, institutions and authorities such as CERT.LV84 under the umbrella of the MoD, the State Police and the National Guard have been able to expand their cybersecurity competences and ex¬ pertise to meet the increasing administrative and substantive demand.85 Cybersecurity author¬ ities such as CERT.LV emphasise that Latvia is focusing on a data-driven cybersecurity ap¬ proach to not only protect, but also to prevent cyberthreats proactively. A major aspect of this process, especially for smaller states, is qualitative analysis based on the data that is acces¬ sible.86 Operators of Cis and CEs have been closely engaged with Latvian institutions on the necessary steps to be taken for Cl policy development. Leading Cl operators in Latvia often have strong lines of communication with the relevant officials responsible for policy formulation, and fre¬ quently improvements and amendments are offered.87 Cl operators have highlighted that the joint Cabinet of Ministers Regulation No. 597 on Minimal cybersecurity standards, which among other things unifies security measures, continuity measures, resilience planning and incident notification under the NIS2 Directive and Directive 2018/1972 establishing the European Elec¬ tronic Communications Code, came about through close cooperation between operators and policy formulating institutions (MoD in this instance).88 85 Justina Budginaite-Froehly: Baltic States unplug from Russia's power grid - but Moscow still looms over critical infrastructure, in Atlantic Council, 05.02.2025. 84 Interview with representative of CERT.LV. 85 LSM+: Interview: Volunteers on the front line of Latvia's cyber defense capability, in: LSM (eng.lsm.lv), 24.07.2024. 86 Interview with representative of CERT.LV 87 Interview with representative of LMT. 88 Ibid. 29
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report Furthermore, the MoD as the National Coordination Centre within the remit of the Regulation 2021/887 establishing the European Cybersecurity Industrial, Technology and Research Com¬ petence Centre and the Network of National Coordination Centres maintains a community of cybersecurity experts, academics, NGOs and involved businesses. This cybersecurity commu¬ nity has the opportunity to separately or jointly apply for funding from the European Cyberse¬ curity Competency Centre's funding instruments,89 and strengthen expertise and competen¬ cies in the field of cybersecurity. Therefore, it is an opportunity for smaller CEs to not only apply for funding, but also exchange best practices, and ease implementation of EU standards. Fur¬ thermore, CERT.LV also heads a working group of security experts, creating a forum, where, for example, CEs can exchange best practices, and seek guidance on how to tackle existing security gaps.90 Next to exchange of best practices and funding opportunities, it should be noted that the CER and NIS2 Directives also creates a negative system of compliance through fines and a liability system. Finally, adjacent to the exchange of best practices and incentive systems, both private and public institutions involved in Cl protection engage in regular exercises, simulations and train¬ ings.91 Here the annual military exercise "Namejs", which involves civil actors, municipalities, and Cl operators, as well as the yearly cybersecurity training "Meduspods" organised by CERT.LV in collaboration with the MoD should be mentioned. Furthermore, CEs frequently en¬ gage in stress tests, penetration tests, and certain CEs in Latvia also participate in the NATO Cooperative Cyber Defence Centre of Excellence organised "Locked Shields" exercises among others.92 Concluding comments The protection of Cl is an integral part of Latvia's CND strategy, where attention is not only paid to cyberthreats and physical threats, but also to other aspects such as effective crisis management and the continuity of services, natural hazard preparedness and technical risk management among others. In that regard, a distinctive feature of the Latvian CND strategy is the close cooperation between the military and civilian sectors. This cooperation, and the arising expertise provided a strong foundation for implementing the NIS2 and CER Directives. In effect, Latvia's CND system reflected a high degree of cohesiveness with the EU minimum standards on Cl protection, which could be considered an incentive itself. Despite a strong incentive structure and institutional experience, Latvia's capacity and capa¬ bilities were initially insufficient to manage the transposition approach it had chosen, and the implementation of both Directives was delayed. However, continuous allocation of additional resources and funds aimed to remedy any potential gaps. Furthermore, Latvia chose a high degree of private sector involvement in the process of transposing and implementing both 89 Cabinet of Ministers Regulation No. 139, "Implementing rules of the European Cybersecurity Compe¬ tence Centre grant programme "Cybersecurity Transformation of Small and Medium-sized Enterprises" for the 2021-2027 programming period" February 27, 2024. Accessible on: https:/ /likumi.lv/ta/id/350225-eiropas-kiberdrosibas-kompetencu-centra-20212027-gada-planosanas-perioda-grantu-programmas-mazo-un-videjo-saimnieciskas-darbibas-veiceju-kiberdrosibas-transformacija-istenosanas-noteikumi. 90 Interview with representative from CERT.LV; Interview with representative from "Latvijas Mobilais Te¬ lefons". 91 Ibid. 92 Interview with representative from "Latvijas Mobilais Telefons". 50
Invigorating Enlargement and Neignbc Policy for a Resilient Europe InvigoratEU | Policy Report Directives, leading to a longer period of coordination and planning, but a potentially more successful end 'product'. Here, the public-private cooperation - both in policy development and crisis management - stands out as one of Latvia's most valuable tools and is a positive model for other EU Member States. Latvia's case also highlights other important aspects in the common framework of Cl protec¬ tion. Firstly, a strong institutional framework with both formal and informal coordination plat¬ forms is a strong necessity for cross-sectoral awareness and rapid response. Second, regular participation in both national and international exercises by private and public sectors has been vital for building expertise in a very specialized field such as Cl protection. Third, Latvia has identified the necessity to streamline obligations and reporting mechanisms for Cl opera¬ tors arising out of different EU Directives. To conclude, Latvia's experience points to several concrete lessons and recommendations. First, it is important to consolidate unified reporting mechanisms for Cl operators to reduce fragmentation and ensure timely threat detection. Second, Latvia's model of sustained public¬ private cooperation in Cl protection and crisis management can be seen as a good practice which might have useful lessons for other countries, in particular EU candidate states. Third, it is important to strengthen and formalize multisectoral coordination platforms, both of a formal and an informal nature. Lithuania Threat landscape In Lithuania, the perception of threats has been mostly influenced by the recent memories of Soviet occupation, the use of economic blockade by Moscow in response to the declaration of the re-establishment of Lithuania's independence in Spring 1990, weaponisation of energy supplies and authoritarian turn of Russia in 2000s and later. As discussed below, the first measures aimed at protecting enterprises considered important for national security were foreseen back in late 1990s. Later they have been expanded with additional restrictions related to investment and technology transfers from China and other authoritarian countries. Initially the decisions of country's authorities to protect Cl by limiting ownership rights and investing into diversification of energy supplies have been domestically contentious. However, after Russia's aggression against Ukraine in 2014 and especially after full-scale war in 2022, the political and societal consensus on the importance of threat from authoritarian Russia became particularly strong. Before that in 2020-2021, Lithuania's relations with Belarus, fluc¬ tuating for a couple of decades between dialogue through engagement and sanctioning in response to violations of domestic political freedoms and human rights and its cooperation with Russia took a decisive turn towards growing restrictiveness. The latter followed massive repressions of Minsk against domestic protesters after rigged presidential elections in 2021, forced landing of Ryanair flight in May 2021 and especially the use of irregular migration by Belarus in summer 2021. Similarly, in the sphere of cyber threats attribution of most important cyber attacks to author¬ itarian countries eventually led to the mobilisation of resources and institutional reforms, as 51
ū š ž ū •^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report discussed below. It should also be noted, that extreme weather events, for example, storm in summer 2024 leaving many households without electricity and mobile communications, have also affected the public debates on the Cl related policies, for example, on the need for stockpiling and purchases of electricity generators. Still, geopolitical threats related to au¬ thoritarian neighbours Russia and Belarus as well as China dominate political and expert de¬ bates.95 Policy and institutional context In the case of Lithuania, it is important to place the recent developments in its Cl protection and resilience policies in the context of the last 25 years, which includes developments in two partly overlapping policy subsystems each responding to different set of external factors.* 94 In particular, the initial focus of Lithuania's authorities on energy security - first characterised by the gap between rhetoric and actual implementation but later accelerated by external shocks and resulting domestic political mobilisation - deserves more detailed presentation as it is currently used as a basis for country's efforts to mobilise EU resources to increase the resilience of the Cl entities in this sector. The first Cl related policy subsystem was developed gradually since the adoption of the first law on the Basics of National Security in 1996 and the Law on the Protection of Objects of Importance to National Security in 2002 to regulate activities and transactions of economic entities considered important for national security, mostly from hostile activities of increasingly authoritarian Russia (and its satellite Belarus). Since early 2000s there has been an increase in political and media attention to the threats posed by Russia's influence in the energy sector via ownership or dominant position in terms of supply of oil, natural gas and electricity. Most of these interdependences in the energy sector - a legacy from the period of Soviet occupa¬ tion - were increasingly perceived as the source of corrupt political influences aimed at ob¬ structing country's efforts to reduce dependency on Russia and integrate into the EU and NATO. These measures have been subsequently developed with the regular revisions of the National Security Strategies, adopted by the parliament, driven by wider security concerns, often in response to escalating aggressive actions of Russia in its neighbourhood. Initially they were focused mostly on energy sector, but later included information and communications and other sectors as well as threats associated with investments from China and technology transfers of its companies (since around 2018 when the US intelligence services started signalling to their European counterparts about the security risks related to China's presence in critical sectors, and Baltic States taking them particularly seriously due to the importance of the US as a stra¬ tegic security partner and related need to align national policies with its). 95 For assessments of threats to national security including Cl, see annual reports of the State Security Department of Lithuania at https:/ / www.vsd.lt/en /archive-national-threat-assessments/ (last ac¬ cessed 27.10.2025). For assessment of cyber threats see the annual reports of the National Cyber Se¬ curity Centre under the Ministry of Defence at https://www.nksc.lt/en/ (last accessed 27.10.2025). 94 For a detailed discussion of the evolution of the legal norms and institutions responsible for Cl pro¬ tection in Lithuania see Ram nas Vilpi auskas: Regulatory patchwork that evolved in response to exter¬ nal threats, legal approximation and domestic influences, in: Maris And ans/Andris Spr ds/Ulf Sverdrup (eds.): Critical Infrastructure in the Baltic States and Norway: strategies and practices of protection and communication, Latvian Institute of International Affairs, 2021, p. 59-97. 32
ū š Š •^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report Introduction of foreign direct investment screening and other business transactions by the Governmental Commission established for this purpose in 2018-2020, also influenced by coun¬ try's accession into the OECD as well as relevant EU norms, constituted further important steps in trying to protect enterprises (also equipment, property, territory) considered important for country's national security in the sectors covering energy, transport, communications, financial and military. The most recent version of the National Security Strategy adopted in 2021 stressed the importance of the total defence model and, among other objectives, developing cyber security, also enhancing resilience and security of critical infrastructure (concretely men¬ tioning transport, energy, finance and credit, information technology and communications, agriculture and food) and ensuring strategic reserve or the necessary production capacity.95 Resilience of the state and society were described as the first line of defence with extensive list of objectives in the field of crisis and emergency management, cyber and information se¬ curity and resilience, economic and energy security, migration management, resilience of the health system, etc. dedicated for this purpose. In other words, evolution of the threat perception, usually in response to the weaponization of energy supplies by Russia (i.e. the termination of the oil supply via Druzhba pipeline in 2006 seen as a response to the decision of Lithuanian government to sell the only country's oil refin¬ ery to Polish company PKN Orlen instead of Russia's Lukoil) as well as external shocks such as cyberattacks, Russia's five days war against Georgia in 2008, hybrid aggression against Ukraine in 2014 and, COVID-19 pandemic, Belarus' instrumentalisation of irregular migration, and in particular, Russia's 2022 large-scale war against Ukraine have strengthened the polit¬ ical and societal consensus regarding the need to reduce vulnerabilities in sectors of Cl and to strengthen country's resilience by integrating infrastructure with other EU member states. Initially Lithuania's authorities focused their efforts at energy security which after initial delays led to diversification away from Russia and, as it will be argued below, to the current policy of trying to mobilise additional EU funds to reinforce energy Cl protection and resilience. So, for example, when Estonia established NATO cybersecurity centre of excellence following the cyberattacks on country's state and private organisations in 2007, Lithuanian policy-makers started working on a similar initiative culminating in the opening of the NATO energy security centre of excellence in Vilnius in 2012. The Baltic Energy Market Interconnection Plan (BEMIP) to a large extent initiated by Lithuania when it had to close down the Ignalina nuclear power plant due to EU accession commitments, and adopted by the European Commission and most of the EU's Baltic Sea countries in 2009 played an important role in facilitating agreements of the Baltic States on regional energy projects which connected them to the Nordic states and Poland and supporting those projects with EU funding96. Lithuanian authorities were also among the first in the region to use EU rules, namely, EU's third electricity and natural gas package to restructure the ownership and management of energy companies. These initiatives allowed Lithuania's government to declare in spring 2022, shortly after Rus¬ sia's war, that it decided to completely stop buying all energy resources from Russia becoming 95 For the last version of the Lithuania's National Security Strategy (which is being currently updated) see. https://e-seimas.lrs.lt/portal/legalAct/lt/TAD/5ec6a2027a9allecb2fe9975f8a9e52e?jfwid=rivwzvpvg (last accessed 27.10.2025). 96 See Jakub Godzimirski/Ram nas Vilpi auskas/Romas vedas: Energy Security in the Baltic Sea Re¬ gion: regional coordination and management of interdependence, Vilnius University Press, 2015, avail¬ able at: https:// nupi.brage.unit.no/ nupi-xmlui/handle/112 50/296761. 35
€ € Ž č ū ū š •^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report the first EU member state to do so. The decoupling of energy sector from Russia (and Belarus) was completed in February 2025, when the Baltic States switched from Russia-controlled power grid BRELL (IPS/UPS) to synchronise with the Synchronous Grid of Continental Europe (UCTE) managed by European Network of Transmission System Operators for Electricity (ENTSO-E). This synchronisation project of more than 2 billion benefited from EU funding through Con¬ necting Europe Facility (CEF) contributing 1,2 billion. As Lithuania's Minister of Energy ygimantas Vai i nas noted on that occasion "we are now removing Russia's ability to use the electricity system as a tool of geopolitical blackmail".97 Lithuanian authorities saw this as a Baltic project driven mostly by Lithuania - a view supported by the official ceremony of the event taking place in Lithuania's capital Vilnius with the participation of the heads of Latvia and Estonia and the president of the European Commission Ursula von der Leyen. It should be noted, though, that a similar large long-term project in the transport sector Rail Baltica, aiming to integrate Baltic States into the EU railway network, important also as a dual-use corridor to facilitate military logistics, has been marred by numerous delays and growing costs. The second (and related to the first) source of policy and institutional changes affecting the emergence of the Cl protection and resilience policy was linked to the domestic political con¬ sensus to strengthen the protection of the critical information infrastructure with the legal basis introduced by the Government Resolution in 2016 (later amended in 2018). It provided the definition of the critical infrastructure as an institution or its unit, an enterprise, particular equipment, its properties or components, planned, built or already functioning, irrespective of whether private or state-owned, which provides services of special importance, the unavaila¬ bility or interruption of which would cause serious harm to the national security, economy, interests of state and society.98 In other words, mobilisation of political attention to develop cybersecurity policy in the after¬ math of growing number of cyberattacks and especially Russia's use of them as one of the tools of aggression against Ukraine in 2014 led to the explicit adoption of the Cl protection policy in Lithuania. Initially protection of critical information infrastructure followed top-down approach by prescribing responsibilities, methodology, including the criteria (10 altogether) to conduct checks regarding the inclusion of the objects into the list of Cl, extending them to 14 sectors - significantly more than included into the relevant EU legislation at the time. Initially the responsibilities were dispersed among different Governmental institutions (in ad¬ dition to Prime Minister's office and six different ministries including Communications Regula¬ tory Authority, the State Data Protection Inspectorate and Police Department) with the Ministry of Interior acting as the main responsible policy-making and coordinating actor. However, dis¬ satisfaction with institutional fragmentation and institutional turf-wars seen by the key policy¬ makers as the main obstacle for more effective cybersecurity policy led to the establishment 97 Tom Bennett: 'Baltic States begin historic switch away from Russian power grid', BBC News, London, 8 February 2025, available at: https://www.bbc.com/news/articles/c627d55v07go. 98 See Ram nas Vilpi auskas: Regulatory patchwork that evolved in response to external threats, legal approximation and domestic influences, p. 59-60. 54
ū š •^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report of the National Cyber Security Centre (NCSC) under the Ministry of Defence in 2015 and fur¬ ther consolidation of responsibilities within it in 2016-2017 ." In 2018, the National Cybersecurity Strategy was approved by the Government. These institutional reforms included the introduction of financial sanctions for the persons re¬ sponsible for cybersecurity to incentivise them to take their duties seriously. At the same time, measures to strengthen capacities of Cl operators to detect, respond and, if needed, recover from cyberattacks have been developed with the NCSC becoming as a centre of expertise, advice to Cl operators, other state and private organisations, and capacity building through regular consultations and exercises, including EU and NATO partners as well as cooperation between private and state actors. The mobilisation of political attention, centralisation of institutional responsibilities and inten¬ sification of capacity building efforts soon led to Lithuania improving its position in the World Cyber Security ranking to reach 4th place in 2019 from being 57th several years ago. These improvements were also accompanied by the initiatives of Lithuanian authorities to take lead¬ ership within the EU. At the end of 2017 the EU endorsed Lithuania-led initiative to create cyber rapid response teams within the Permanent Structured Defence Cooperation (PESCO) agreement. This Lithuania-coordinated initiative includes twelve EU member states and coop¬ erates with NATO Rapid Reaction teams as well as partner countries such as Ukraine, especially after 2022 with more attention dedicated to the lesson-drawing from successful cyber de¬ fence performed by Ukraine. On the basis of their experience, Lithuanian officials also con¬ tributed with their proposals to the drafting of the NIS2 Directive. These Cl related policy developments in Lithuania, driven by domestic political initiatives in response to perceived external threats, often accompanied by the efforts to involve EU (and NATO) institutions with their expertise, financial resources and legal norms, form an important background to the recent adoption of CER and NIS2 Directives in Lithuania. Lithuania trans¬ posed them by amending a number of national legal norms. In the case of CER Directive, 15 laws and government resolutions have been amended, with the Law on Crisis Management and Civil Protection being the most important one. Important measures such as the risk as¬ sessment methodology, resilience strategy (guidelines) and the identification of the list of crit¬ ical entities based on common criteria are expected to be adopted in the first half of 2026. In the case of the transposition of NIS2 Directive, 22 laws and government resolutions were amended.99 100 The process of transposing the CER Directive was led by the National Crisis Management Cen¬ tre (NCMC) established under the Government Chancellery in 2025 to centralise the crisis¬ management in response to COVID-19 pandemic and other crises such as irregular migration orchestrated by Belarus since mid-2021, in cooperation with the Ministry of Interior. The NCMC is the competent authority representing the "whole-of-Government" approach to continuous 99 For a detailed discussion of the evolution of Lithuania's cybersecurity policy see Ram nas Vilpi auskas: Gradually and then suddenly: the effects of Russia's attacks on the evolution of cybersecurity policy in Lithuania, In Policy Studies, 45 (5-4), p. 467-488. 100 See the relevant EU law web sites on national transposition measures communicated by the Member States concerning CER and NIS2 Directives - available at: https://eur-lex.europa.eu/leqal-content/EN/NIM/?uri=CELEX:52022L2557 and available at: https:/ /eur-lex.europa.eu/leqal-content/en/NIM/?uri=CELEX:52022L2555. 55
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report monitoring, assessment and warning of risks and threats, receiving and sharing information on incidents, coordination of resilience-enhancing measures, management of crises and state level emergencies, coordinating national security communication, overseeing national stock¬ pile system, organisation of exercises and coordination with NGOs. The NCSC and the Ministry of Defence took the lead in coordinating the transposition of the NIS2 Directive and its prac¬ tical implementation benefitting from the expertise and working routines developed during the decade since its establishment. In early 2025, it was agreed in the State Defence Council, bringing together key institutions and parties, that the defence expenditure should reach 5% of country's GDP from the next year - a commitment now also written in the program of the recently formed 20th Government - with a long-term aim of maintaining it at 5-6% level up to 2050. The allocation of more funding for the defence is also likely to benefit Cl policy subsystem with some of those invest¬ ments directed to improving its resilience. The revision of the National Security Strategy initi¬ ated this year by the Ministry of Defence is likely to provide a legal basis for such investments. The current version of the Strategy adopted in 2021 prioritised protection against hybrid threats and stressed comprehensive defence. The new strategy is likely to have a stronger focus on societal preparedness and defence, economic and energy security and resilience, including Cl protection and resilience, for example, funding of dual-use infrastructure.101 Incentives and capacities for implementing Cl related policy measures As it has been underlined above, evolving (and escalating) external threats, mostly from au¬ thoritarian Russia and its allies, acted as the main incentive for developing Cl related policies in Lithuania. It is also the main reason why during the period of more than two decades of EU membership Lithuania's authorities invested significant efforts aimed at establishing the coun¬ try as the active and constructive partner in the fields related to security ranging from energy security to cybersecurity and cooperation with other like-minded partners within the EU and NATO as well as Eastern neighbours such as Ukraine, Moldova and (until recently) Georgia. The widespread view within country's institutions that influencing EU policies requires credible domestic actions and policies consistent with articulated national preferences most likely also acts as an additional incentive to avoid being late with the transposition of EU norms, in par¬ ticular such as CER and NIS2 Directives which relate to security concerns (according to the officials, Lithuanian was the fourth country among EU member states to transpose them - the fact that it was worth mentioning itself points to the importance of timely transposition).102 At the same time, it should be noted that country's political processes are characterised by le¬ galistic culture resulting in the proliferation of legal norms, thus increasing regulatory com¬ plexity and reducing flexibility in times crises - as noted numerously by the local experts and OECD.103 Thus, although the adoption of those EU norms required a number of changes to existing legal norms, those changes were incremental, for example, adding several new sectors such as '°' Interview with the senior official of the Ministry of Defence, September 5, 2025, Vilnius. 102 Interview with senior officials from the National Crisis Management Centre, August 26, 2025, Vilnius. 105 OECD: Mobilising Evidence at the Centre of Government in Lithuania, OECD Publishing, 29 November 2021, available at: https:/ /www.oecd.org/en/ publications/mobilisinq-evidence-at-the-centre-ofgovernment-in-lithuania 325e5500-en.html. 56
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report health care and public administration, while in many others similar or more demanding rules already existed in Lithuania. Besides, in the process of adopting NIS2 Directive responsible authorities such NCSC introduced additional measures considered the best practices such as foreseeing the position of cybersecurity chief or the possibilities to provide financial incentives for IT specialists which for many years had no possibility to get competitive salaries due to limits regarding pay for different categories of civil servants.104 Going to the level of Cl operators and entities, incentives for designated persons responsible for the procedures aimed at protecting Cl, in particular from cyber threats, have existed for some time. However, according the officials from the NCSC, there were only a few instances of issuing notifications to those responsible to take urgent actions but no cases of actual use of financial sanctions were reported.105 Officials from the authorities working with Cl protection and resilience policies stress that their focus in working with Cl operators and entities included into the relevant lists is on building capacities through regular advices, producing risk assessment manuals and training to use them, conducting awareness raising and training exercises, especially for senior management of Cl operators, and similar activities. The National Crisis Management Centre, which is a des¬ ignated institution responsible for the implementation of the CER Directive, uses also methods such as naming and shaming by comparing municipalities in terms of their preparedness for emergency situations (i.e. presence of shelters), collects and monitors information on variety of risks in real time, coordinates regular exercises and responses in emergency situations. The positive experience of cooperation with regulatory institutions has also been noted by the senior management of leading companies within the energy and telecommunications sec¬ tors.106 Interestingly, representatives of energy sector noted that the level of maturity in terms of or¬ ganisational practices and risk assessment procedures regarding Cl protection and resilience was higher in the cyber domain compared to physical infrastructure protection, the threats to which are relatively new and there is little experience in dealing with them (i.e. in the cyber domain the probability of attack is higher, the eventual damage is higher and the responsibility/sanctions are higher compared to attacks on physical infrastructure). In the case of the physical infrastructure protection and resilience, there is still significant uncertainty related to the risk assessment, its methodology and corresponding measures such as accumulation of redundancies (spare transformers, generators, cables, etc.) - eventually a matter of significant additional costs which have to be carefully assessed because they might eventually need to be reflected in the prices charged to electricity users. Another issue complicating the timely actions to increase protection and preparedness of en¬ ergy companies indicated by both Cl operators and officials of the Ministry of Energy was public procurement procedures set by the relevant EU directive. More concretely, the compli¬ cations arising when offers by companies with potentially high risk profile (i.e. Hungarian com¬ panies offering Chinese technologies and equipment) cannot be easily eliminated or procure¬ ment procedures cannot be accelerated. In general, the length of procurement procedures to 104 Interview with senior officials from the National Cyber Security Centre, September 4, 2025, Vilnius. 105 Interview with senior officials from the National Cyber Security Centre, September 4, 2025, Vilnius. 106 Interview with the senior management of the energy company LITGRID, March 4, 2025, Vilnius; Inter¬ view with the senior management of telecommunications company TELIA, March 6, 2025, Vilnius. 57
• š ć š ć š ć • •^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report The transition to the CER Directive (2022/2557) should reflect a shift from protectionfocused critical infrastructure legislation toward a resilience-oriented approach. How¬ ever, Montenegro has not fully transposed CER into national law yet. NIS2 Directive (2022/2555) was introduced and subsequently transposed into the new Law on Infor¬ mation Security, adopted at the end of 2024125. The 2019 Law on Critical Infrastructure* 124 defined critical sectors as energy, transport, water supply and healthcare, finance, electronic communications and ICT, environmental protection, functioning of state authorities, and other areas of public interest and Ministry of Interior as the responsible institution. The new sectors or subsectors were added in 2024, including space activities, ICT service management, food production, processing and distribution, manufactur¬ ing (covering medical devices, computers, electronics, machinery, vehicles, and other transport equipment), electronic service providers, and research entities focused on applied research and experimental development for commercial purposes. The 2024 Law shifts from a general sectoral approach toward a more comprehensive, detailed, and resilience-oriented frame¬ work, reflecting broader alignment with EU standards and the CER Directive. The adoption of the 2024 Law on Information Security served two primary purposes: fulfilling Montenegro's EU obligations and establishing a secure cyberspace that protects critical in¬ frastructure in line with EU best practices. As Du an Polovi noted, "The law has enabled the establishment of new and the strengthening of existing mechanisms for responding to cyber incidents and crisis situations." In addition, Mrs. Mi kovi emphasized: "This achievement re¬ flects substantial alignment with EU standards in digital policy, media regulation, and elec¬ tronic communications." The law represents a significant step in strengthening administrative capacity and achieving legislative harmonization, reinforcing confidence in Montenegro's readiness for EU accession. Its adoption also enabled the provisional closure of Chapter 10 - Information Society and Me¬ dia in December 2024. As Mrs. Mi kovi highlighted, "This marks a crucial milestone in the EU accession process." The 2024 Law on Information Security also clearly defines the roles and responsibilities of institutions responsible for critical infrastructure and cybersecurity. Notably, it establishes the Ministry of Public Administration (MPA) as a central coordinating body in this process, providing strategic oversight and ensuring that institutional responsibilities are clearly delineated across the government. The MPA's responsibilities include: Acts as the Single Point of Contact with the EU and regional partners. 125 Ministry of Public Administration: Law on Information Security, 11 December, 2024, available at: https:/ / www.qov.me/en/documents/23936380-482a-4784-bd94-be69413d7334 (last accessed 21,08.2025) 124 Ministry of Interior: Law on the Identification and Protection of Critical Infrastructure, 30 January, 2020, available at: https://www.gov.me/en/documents/2585570a-cdff-420f-a7c4-0f67fl9a6d8e (last accessed 21,08.2025) 44
• • • • • • • • • • • • • •^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report Coordinates national cybersecurity policy among ministries, agencies, and operators. Oversees the Cyber Security Agency and Gov-CIRT. Develops and maintains the national cybersecurity strategy and related action plans. Ensures proper categorization of essential and important entities. Coordinates regulatory oversight with sectoral regulators. Operational Cybersecurity Units, function under the strategic guidance of the MPA. These units are responsible for: Gov-CIRT and G-SOC125: Provide 24/7 monitoring, incident detection, and coordi¬ nated response across government networks. Cyber Security Agency (planned): It will centralize oversight functions, ensure NIS2 compliance, facilitate cross-border cooperation and conduct audits and enforcement. Agency for Electronic Communications and Postal Services complements this framework by Regulates telecoms and postal networks. Ensures network resilience and supervises the market. Oversees critical network obligations for private operators. While Montenegro's institutional framework reflects formal compliance with EU norms, its func¬ tional capacity remains limited — a common challenge among smaller EU-harmonizing states. Overlapping jurisdictions, where the Ministry of Interior operates under the 2019 Law and the Ministry of Public Administration under the 2024 Law, limit Montenegro's functional capacity in critical infrastructure protection. This challenge is further compounded by weak enforce¬ ment and political influence. Structural fragmentation, skills gaps, and insufficient funding fur¬ ther reduce the effective implementation of Cl-related measures. Multiple agencies are re¬ sponsible for Cl protection, with energy, telecom, and digital sectors each overseen by sepa¬ rate ministries. These overlapping or unclear mandates undermine efficiency, additionally. Beyond domestic arrangements, Montenegro engages actively in regional and international cooperation: EU rapid response teams and ENISA initiatives supported the establishment of G-SOC. The Western Balkans Cyber Capacity Centre (WB5C)126 provides training and capacity building for Cl operators and institutional staff. The Energy Community monitors Montenegro's compliance with EU energy and cyber¬ security standards. 125 Ministry of Public Administration, Directorate for Information Security and Gov-CIRT, 26 October, 2024, available at: https://www.gov.me/clanak/drzavne-institucije-privrede-i-gradani-u-crnoj-goriod-danas-bezbjedniji-u-internet-okruzeniu (last accessed 22.08.2025) 126 Ministry of Public Administration, Western Balkans Cyber Capacity Centre, 10 December, 2024, https://www.gov.me/clanak/otvoren-regionalni-centar-za-sajber-kapacitete-zapadnog-balkanadan-za-pamcenje (last accessed 22.08.2025). 45
• € € € € •^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report NATO, EU, and U.S. partners provide practical support in incident recovery and infra¬ structure strengthening. Incentives and capacities for implementing Cl related policy measures Montenegro's EU accession process provides a strong political and financial incentive to re¬ form its critical infrastructure protection and resilience policies in line with EU norms. The ne¬ gotiation process and provisional closure of Chapter 10 - Information Society and Media demonstrate the tangible benefits of alignment. Achieving this milestone signals progress in EU integration and reinforces Montenegro's commitment to modernizing its digital and cyber¬ security frameworks. Implementing EU legal norms for Cl protection and resilience provides access to EU funding, technical expertise, and improved security standards, thereby strengthening the country's re¬ silience. Pre-accession conditionality and funding play a key role as practical incentives— aligning with EU standards is essential not only for smooth accession but also to access EU pre-accession funds and international grants. This combination of political milestones and financial support encourages Montenegro to adopt EU directives such as NIS2, strengthen infrastructure secu¬ rity measures, and enhance overall resilience, while simultaneously highlighting the risks of re¬ liance on conditional or potentially unstable financing, which can affect the continuity of Cl protection projects.127 The EU contributes to Montenegro's cyber resilience through multiple instruments, such as IPA programs and the Western Balkans Investment Framework (WBIF), by providing grants, tech¬ nical assistance, and sector-specific cybersecurity training. 128 The EU-financed Cybersecurity Rapid Response project (Phase 2.0) for Albania, Montenegro, and North Macedonia (April 2024-September 2025) provides 1.8 million to strengthen Gov-CSIRTs, SOCs, and cyber re¬ silience in public institutions. Western Balkans Investment Framework (WBIF) provided Monte¬ negro with over 3 billion in grants, mobilizing more than 24 billion in investments, though not cybersecurity-specific. Additionally, Montenegro joined the Digital Europe Programme (2021-2027) in June 2023, gaining access to 7.5 billion through competitive calls. Funding for the new Cybersecurity Agency and Government CIRT comes mainly from national budgets and EU cooperation. To address this, the EU supports Montenegro through IPA III and the West¬ ern Balkans Digital Agenda, offering financial aid, technical assistance, and training However, the EU pre-accession incentives are necessary but insufficient: they encourage for¬ mal adoption of norms but cannot substitute for structural, financial, and technical capacity building. While conditionality has been effective in driving legislative alignment (for example, NIS2-based law adoption), it does not guarantee full implementation. Financial constraints 127 Milena Mihailovic/Ruggero Tabosi: Reforming the EU's pre-accession funding instrument, Issue Paper, European Policy Centre and CEPS, September, 2023, available at: https: / / cep.org.rs/wp-content/ uploads/2023/09/Reforming-the-EUs-pre-accession-funding-instrument.pdf (last accessed 21.08.2025). 128 European Commission: Montenegro report 2024, 30 October, 2024, available at: https://enlargement.ec.europa.eu/document/download/a41cf419-5473-4659-a3f3-af4bc8ed243b en (last ac¬ cessed 21.08.2025). 46
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report also exacerbate technical gaps: outdated power grids, vulnerable telecom networks, and in¬ sufficient digital security frameworks cannot be upgraded without substantial capital. In same time, Montenegro as a small economy, faces limited public and private funding for cybersecurity and critical infrastructure initiatives. Infrastructure operators often perceive EU norms as compliance burdens rather than strategic investments, particularly in regulated or low-profit sectors such as energy, where small market size, government price controls and high modernization costs constrain profitability.129 The central challenge for Montenegro is closing the financial gap while ensuring both modernization, cyber resilience and sustainable growth. The country's economic development heavily depends on foreign investment. However, interest from EU businesses remains limited, and Montenegro faces strong competition from alternative sources of capital, including China and the United Arab Emirates. This could strongly increase the country's resilience to potential cyberattacks in the future. In this context, EDI screening has become increasingly relevant, especially for sectors with national security implications. Montenegro has partially adopted frameworks influenced by the EU's EDI Screening Regulation - a specific EDI screening mechanism for the defence industry. However, no comprehensive EDI screening mechanisms have been in place for other sectors. Security concerns have also intensified around the procurement of Chinese telecom equip¬ ment— particularly from Huawei— which has led to stricter scrutiny under EU and NATO stand¬ ards. Cybersecurity measures to address these risks include national strategies, the establish¬ ment of the CIRT, regular training for operators, and regional cyber exercises supported by both the EU and NATO. As Kentera observed, "Control over strategic resources directly determines the degree of a state's independence— whoever controls the infrastructure, controls the state." Kentera* 150 noted that while partnerships with private companies are possible, the State must retain authority over strategic sectors of critical infrastructure. In particular, Montenegro remains highly vul¬ nerable in the energy and digital sectors. These efforts are reinforced by reforms in public procurement, aligned with Chapter 5 of the EU accession negotiations, which was provisionally closed in June 2025. The reforms intro¬ duced electronic procurement, anti-corruption safeguards, and transparency measures— strengthening oversight of telecom-related procurements. As a result, contracts (involving Chi¬ nese suppliers) are now subject to fair, competitive, and EU-compliant screening.151 Montene¬ gro has also adopted EU-aligned legislation, developed centralized e-procurement systems, and professionalized its oversight institutions. Together, these tools embed early-warning 129 Based on the interview with Mr. Ivan Bulatovic, General Manager of Elektroprivreda Crne Gore-EPCG the largest energy company, May 25, 2025, Podgorica. 150 Based on the interview with Mr. Savo Kentera, an expert in security and international relations, the President of the Atlantic Alliance of Montenegro, served as the Acting Director of the National Security Agency (ANB) of Montenegro in 2022, September 8, 2025, Podgorica. 151 EU ME, Chapter 5 - Public procurement, June, 2025. https:/ /www.eu.me/ en/ poqlavlje-5-javne-nabavke/ (last accessed 21.08.2025). 47
ć Č ć Č •^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report ("red-flag") mechanisms to enhance scrutiny of foreign vendors and improve institutional ca¬ pacity to detect and mitigate procurement-related security risks.152 Remaining challenges persist regarding Cl protection and resilience. The adoption of laws under the NIS2 framework demonstrates Montenegro's formal alignment with EU standards. Political volatility further undermines resilience efforts. Despite strong political and popular consensus on fast EU accession, frequent government changes and limited public awareness of Cl's importance reduce the motivation to invest in long-term security. Regulatory bodies and operators in the energy and telecommunications sectors face shortages of funding, per¬ sonnel, and expertise, limiting their ability to enforce standards and manage risks. While the government has adopted EU-aligned legal frameworks, the implementation remains challeng¬ ing. International support — particularly from the EU and the Energy Community — is therefore crucial to strengthening resilience.155 Domestic funds, both public and private actors, sometimes perceive EU cybersecurity norms as externally imposed obligations rather than strategic investments, thus weakening compli¬ ance. As Ivan Stankovi of the private IT company ikom observed, many companies will strug¬ gle to fully comply with Cl-related regulations due to shortages of staff, expertise, and ade¬ quate technologies.154 Concluding comments Montenegro's EU accession process has created strong political and financial incentives to reform its critical infrastructure protection and resilience policies, aligning them with EU norms. Achievements such as the provisional closure of Chapter 10 and the adoption of NIS2-aligned laws signal progress in integration and reinforce the country's commitment to modernizing digital and cybersecurity frameworks. EU support— including funding, technical assistance, and programs such as IPA, WBIF, and the Digital Europe Programme— strengthens national capacity and resilience, while pre-accession conditionality motivates formal compliance. However, financial constraints, limited domestic resources, and dependence on foreign invest¬ ment (telecommunications, banking, transportation...) pose significant challenges. Foreign ownership and competition for capital highlight the need for careful oversight, FDI screening, and strategic control over critical infrastructure. Reforms in procurement, regulation, and op¬ erational frameworks, together with EU-supported initiatives, have improved governance and early-warning capabilities in Montenegro. However, the country continues to face significant structural, technical, and human capacity gaps. Political volatility, limited public awareness, and perception of EU norms as compliance burdens further hinder full implementation. 152 Vijesti, EC: Conditions for closing Chapter 5 fulfilled, implementation of agreement with UAE to be in line with European legislation, 5 June 2025. Available at: https://en.vijesti.me/ news-b/ politika/761159/EC-fulfilled-the-conditions-for-closing-Chapter-5— the-implementation-of-the-aqreement-with-the-UAE-to-be-in-line-with-European-legislation (last accessed 21.08.2025). 155 Based on the interview with expert for telecommunication in Ministry of Public Administration, Sep¬ tember 5, 2025, Podgorica. 154 Based on the interview with Mr. Ivan Stankovi of the private IT company ikom September 8, 2025, Podgorica. 48
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report Lessons learned from Montenegro's experience emphasize the importance of combining for¬ mal legal alignment with practical capacity building, sustainable financing, and robust insti¬ tutional coordination. Moving forward, Montenegro's resilience will depend on sustainable investment, institutional capacity building, skilled personnel, and integrated coordination across public and private actors. These measures are essential to ensure that legal alignment translates into practical protection and continuity of critical infrastructure in the face of evolving cyber threats . Ukraine Threat landscape Since Russia's full -scale invasion, Ukraine has faced an unprecedented convergence of ki¬ netic, cyber, and hybrid threats targeting its critical infrastructure. Now going through its fourth year, the war has placed enormous strain on the country's essential systems, yet the resilience and determination of the Ukrainian people and institutions remain a central factor in sustaining national functionality. Critical Infrastructure has become both a direct target and an instrument in Russia's strategy to destabilise Ukraine. Disruptions in energy generation and transmission, damage to logistics networks, and interference with information and communication systems are designed to par¬ alyse governance, reduce industrial output, and undermine public confidence. Alongside phys¬ ical assaults, Ukraine continues to confront a wide range of coordinated cyber operations, disinformation campaigns, economic pressure tactics, environmental disasters, all aimed at amplifying the effects of kinetic warfare. A UN Human Rights Monitoring Mission report155 confirms that the destruction of vital infra¬ structure "violates the principles of international humanitarian law aimed at protecting civil¬ ians". This underscores both the severity of the threat and the urgency of building resilient, legally compliant systems of protection. At the same time, Ukraine's EU accession process adds a crucial strategic dimension to its efforts in Cl protection and resilience. Alignment with the EU acquis, not only strengthens Ukraine's institutional capacity, but also integrates its resilience framework into the broader European security architecture. Progress in this area is essential in both the country's recon¬ struction and its long-term integration with the EU. In this context, the legislative and institutional framework of Cl protection and resilience has acquired strategic importance. Ensuring the effective operation of vital systems under contin¬ ued attack requires not only defensive capabilities but also coherent policies, regulatory mechanisms, and incentives that support both public and private operators of critical infra¬ structure. 155 United Nations Ukraine: Attacks on Ukraine's energy infrastructure: harm to the civilian population, , available at: https: //ukraine. un.org /en/278992-attacks-ukrai ne' s-enerqy-inf rastructure-harm-civilian-population (last accessed 16.10.25). 49
• • •^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report Policy and institutional context Russia's aggression against Ukraine's critical infrastructure remains a central element of its military strategy, designed to inflict maximum operational, economic, and humanitarian dam¬ age. Its overarching objective is to destabilize the state and undermine national resilience. This strategy involves the physical destruction of key assets and costly facilities, the replace¬ ment of which requires considerable time and resources, while their disruption critically affects energy supply to the population and essential infrastructure enterprises. These kinetic threats are further compounded by persistent and sophisticated cyberattacks, aimed at eroding eco¬ nomic stability, weakening public morale. Cyberwar has become a full-fledged component of Russia's aggression against Ukraine. In 2022, the number of cyberattacks on Ukraine's information infrastructure nearly tripled com¬ pared to 2021. More than 1.5 million attempted attacks on the energy sector alone were rec¬ orded and blocked that year, with transmission and distribution system operators being the primary targets. The most significant cyber threat to Ukraine's energy sector is the Industroyer malware136, the first known malicious software specifically designed to disrupt electricity networks. Originally deployed in the 2016-2017 cyberattacks on Ukraine, it re-emerged in 2022 in an upgraded form known as Industroyer2, used by the Russian hacker group Sandworm. This new variant, aimed at disabling electrical substations, was combined with a destructive malware tool called CaddyWiper, designed to erase data on infected systems. The attack was scheduled for April 8, 2022, but was successfully prevented through the joint efforts of Ukrain¬ ian cybersecurity specialists at CERT-UA and international partners, including ESET and Mi¬ crosoft. Attempts such as Industroyer2 are not isolated incidents but part of a broader, coordinated cyber strategy. Russian groups exploit cyber tools to infiltrate energy company networks, con¬ duct reconnaissance, and prepare for both cyber and kinetic operations. According to a rep¬ resentative137 of the Verkhovna Rada of Ukraine, cyberattacks can be synchronized with planned physical strikes, aiming to: Disrupt control systems: disable or confuse supervisory control and data acquisition (SCADA) systems and protective relays. Destroy data: deploy wiper malware to erase critical information, making rapid recov¬ ery through manual or automated processes far more difficult. In the digital sector, Ukraine is in the process of adapting its national legislation to the NIS2 Directive (EU 2022/2555), which will facilitate integration into the EU digital single market138 136 Cyber threat bulletin: Cyber threat activity related to the Russian invasion of Ukraine , https:/ / www.cyber.gc.ca/sites/default/files/cyber-threat-activity-associated-russian-invasionukraine-e.pdf (last accessed 15.09.2025). 157 Communication with the Verkhovna Rada representative on Cl protection in the written format (re¬ ceived on 19.09.2025). 158 Ukraine: 3d Cyber Dialogue with the European Union takes place in Brussels, available at: https: //dig¬ ital-strategy. ec.europa.eu /en /news/ ukraine-5rd-cyber-dialogue-european-union-takes-place-brussels (last accessed 17.04.25). 50
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report - an essential step toward Ukraine's accession to the European Union. Harmonization of cy¬ bersecurity standards and practices with EU norms is vital, especially in light of the increasing cyber threats and attacks emanating from the Russian Federation. To this end, the State Service for Special Communications and Information Protection of Ukraine (SSSCIP) has established cooperative frameworks with European partners. Notably, collaboration has been initiated with the European Union Agency for Cybersecurity (ENISA), and a memorandum of understanding has been signed with CERT-EU. Ukraine has begun aligning its critical infrastructure sectors with the requirements outlined in NIS2 and has intro¬ duced procedures for incident response and information exchange concerning cyber incidents and attacks. Pursuant to the EU Directive on Security of Network and Information Systems (NIS/NIS2), amendments to existing Ukrainian legislation are underway to establish criteria for designating critical infrastructure facilities and to define risk management and incident response require¬ ments. The implementation of NIS2 standards in Ukraine is expected to enhance the resilience of national critical infrastructure against cyber threats, foster cybersecurity cooperation with European counterparts, and improve the protection of state information systems. Furthermore, Ukraine aims to establish a cybersecurity certification system aligned with the EU Cybersecu¬ rity Act* 139, which will support the entry of Ukrainian IT products and services into the European market and improve their global competitiveness. The Parliament of Ukraine has on 17 March 2025 adopted legislation concerning the protection of state information resources and critical information infrastructure. This law140 strengthens Ukraine's cybersecurity defence capabilities and includes the following key provisions: • Establishment and operation of national systems for responding to cybersecurity inci¬ dents, attacks, and threats, including the exchange of information concerning inci¬ dents that affect information, electronic communications, and ICT systems processing state or classified data. • Development of national, sectoral, and regional response teams within the national cybersecurity response system, following the recommendations outlined in the NIS2 Directive. • Delegation of responsibilities from the national CSIRT (CERT-UA) to sectoral and re¬ gional teams, with provisions for involving private response teams in the national cy¬ bersecurity framework. An important characteristic of Ukraine's Cl legislation is its two-fold nature. The law explicitly regulates activities in peacetime and under a state of emergency, while activities under mar¬ tial law are governed by the other laws of Ukraine. This legal 'two-sidedness' reflects a stra¬ tegic choice, enabling the state and its agencies to employ more flexible and operational protection tools during armed conflict. 159 Cyber Resilience Act, European Commission, available at: https: / /diqital-strateqy.ec.europa.eu/en/policies/cyber-resilience-act (last accessed 17.04.25). 140 Law of Ukraine 4336-IX dated 27.03.25, On Amendments to Certain Laws of Ukraine on Information Protection and Cybersecurity of State Information Resources and Critical Information Infrastructure Fa¬ cilities https://zakon.rada.qov.Ua/laws/show/4336-IX#Text (last accessed 17.04.25). 51
Vilpišauskas, Ramūnas et al.: •^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report Against the backdrop of ongoing threats, a key question is whether there exists a political consensus on the policy instruments used to address these risks, and whether this consensus is supported by regulatory authorities and by Cl operators and owners. In general, there is mutual understanding between government bodies, regulators, and market actors about the im¬ portance and priority of effective responses. Discussions are ongoing concerning funding sources, the creation of reserve funds and stocks, and the securing of alternative supply routes141. Nonetheless, discrepancies between key stakeholders remain. The most systemic difference concerns the strategic architecture of Ukraine's power system. Current state policy continues to prioritize the protection of large, centralized facilities, consistent with the historical model of Ukraine's power grid, which has relied on several large nuclear, hydro, and thermal power plants. However, in the context of war with Russia, which deliberately targets these facilities, the effectiveness of this approach has been called into question. For example, the level of readiness of protective structures at Ukrainian Transmission System Operator (TSO) Ukrenergo National Power Company (NPC) facilities is currently estimated at over 85%. However, physical barriers such as gabions142 and "big bags145" are not always effective against direct missile strikes. The construction of these fortifications is time consuming. This centralized model has been sharply criticized by experts, many of whom argue instead for a strategy of decentralized generation. Ukraine War Environmental Consequences Work Group (UWEC)144, among others, advocates for a model built around hundreds of smaller power plants, which would be significantly harder to disable through missile strikes. In their view, such a model offers greater sustainability. The issue of distributed generation in the energy sector is analysed in detail in report D.7.1145. In line with Ukraine's energy security strategy, the Cabinet of Ministers' Order No. 713-p of July 18, 2024, approved the Strategy for the Development of Distributed Generation until 2035 and its accompanying action plan for 2024-2026. This strategy aligns with Directive (EU) 2019/944 on common rules for the internal electricity market, as amended by Directive 2012/27/EU, which Ukraine is obliged to implement as part of its commitments to the Energy Community and its integration process with the EU. The plan also emphasizes the importance of guaranteed capacity and the modernization of transmission and distribution infrastructure. 141 Communication with the former executives of Ukrainian TSO (Ukrenergo) on Cl protection in the writ¬ ten format (received on 19.09.2025) 142 Gabions are wire mesh with cages filled with stones, used for protection of the critical infrastructure by providing durable barriers against physical threats like blasts or vehicle impacts 145 "Big bags" used for critical infrastructure protection are typically known as Giant Geotextile Bags (GGBs) or Megabags which are large containers made of high-resistance synthetic polymers and filled with soil (often sourced from surrounding area). 144 Ukraine War Environmental Consequences Work Group (UWEC): Environmental consequences of the war in Ukraine: October-November 2024 Review, available at: https: / / uwecworkqroup.info/environmental-consequences-of-the-war-in-ukraine-october-november-2024-review/ (last accessed 19.09.25). 145 Long policy report on rules alignment of protecting critical infrastructure in interdependent states, available at: https:/ /invigorat.eu/wp-content/ uploads/2025/05/D7.1 InviqoratEU lonq-policy-report public.pdf (last accessed 19.09.25). 52
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report The obligations placed on energy Cl operators and owners in Ukraine represent an important step forward and appear broadly adequate on paper, particularly in terms of alignment with EU standards. It reflects a shift from normative, state-driven approaches to the more compre¬ hensive, risk-based frameworks required by the EU Critical Entities Resilience146 (CER) and NIS2 Directives. However, their practical adequacy is constrained by limited resources, wartime dis¬ ruptions, and gaps in detailed enforcement mechanisms. At the facility level, Cl operators are required to develop and implement physical and infor¬ mation protection plans. These plans are not autonomous, as their approval for facilities of categories I and II of criticality rests with the Security Service of Ukraine (SBU). This hierarchy reflects the state's approach to Cl protection primarily through the prism of national security, with priority given to oversight by the security services. Beyond the SBU, a wide range of state bodies are involved in the system, underscoring its nationwide scope. Depending on circumstances, the Armed Forces of Ukraine, the National Guard, the National Police, and the State Emergency Service may be engaged in security and protection measures. The State Service for Special Communications plays a central coordi¬ nating role in cybersecurity, including training on countering cyberattacks developed in coop¬ eration with the US Cybersecurity and Infrastructure Security Agency (CISA). Even the NEURC, acting as regulator, has become involved in safeguarding Cl-related information during mar¬ tial law. This broad institutional coordination illustrates the existence of a coherent state policy framework. Incentives and sanctions for implementing Cl related policy measures The main incentives for applying Cl-related protection measures lie in ensuring the sustaina¬ bility of state functions, particularly the continuity of vital government operations, the preser¬ vation of economic stability and citizen security, and the prevention of negative consequences arising from disruptions in infrastructure operations. These measures are also crucial for pro¬ tecting against both external and internal threats. Further incentives on energy Cl protection and resilience are linked to access to financing mechanisms for sensitive expenditures, which depend on compliance with established indicators. As highlighted in the D.7.1 report, the obligations of Cl operators and owners, including in the energy sector, have evolved significantly since the adoption of the Law of Ukraine "On Critical Infrastructure" (2021) and related regulations. Importantly, the law tasked the Authorized Body in the field of critical infrastructure protection - the State Service for Special Communications and Information Protection - with preparing amendments to the Law on Critical Infrastructure, the Code of Ukraine on Administrative Offenses, and the Criminal Code. These amendments were intended to establish forms and amounts of penalties for Cl operators, define relevant offenses, and specify liability for violations, within one year of the law's entry into force. To date, however, these requirements remain unimplemented. The reason of non-implementation is a combination of war-related disruptions, limited institutional capacity, political sensitivities, and the need to synchronise with evolving EU legislation. 146 The CER Directive has not been transposed into Ukrainian legislation. 55
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report It should be noted that during the 2021-2025 period, steps were undertaken to clarify and regulate some key aspects of cyber supervision over CISSs and to operationalize the 2021 amendments. A series of by-laws were issued by the Head of the LEPL Georgian OperationalTechnical Agency (OTA) under the State Security Service of Georgia (SSSG) for Firstand Second-Category CISSs, and by the Head of the Digital Governance Agency (DGA) under the Ministry of Justice for Third-Category systems. These by-laws addressed minimum information security requirements, minimum standards for information security managers, rules for manag¬ ing information assets, procedures for conducting information security audits, rules for config¬ uring network sensors, and requirements for the conduct and frequency of penetration tests.170 Despite these advancements, significant challenges remain in further developing the legal framework to achieve closer alignment with EU standards. One of the most critical shortcom¬ ings in Georgia's legal framework concerns the process for designating entities as CISSs, as it provides only a general framework and lists several designation factors, while also mandating the development of detailed regulations and methodologies. However, by 2025 such instru¬ ments have not yet been adopted, and the designation process remains state-driven, noninclusive, and opaque. For example, in the absence of clear regulations and a systematic ap¬ proach, private healthcare service providers are entirely excluded from supervision. According to insights obtained from cyber experts with professional ties to CISSs,171 private companies are not meaningfully involved in the process and are often informed of their designation only retrospectively. Simultaneously, the introduction of a risk-based classification system for CISSs, distinguishing between "essential" and "important" categories as set out by the NIS2 Directive, is currently absent in Georgia, which is widely regarded as a critical priority for strengthening the supervisory framework and ensuring more effective oversight. Exploring the underlying reasons for these delays requires further research, however, possible factors include limited institutional capacity, weak policy leadership, and the relatively low prioritization of cybersecurity on the political agenda, all of which appear to have been further exacerbated by political instability. Incentives and capacities for implementing Cl related policy measures At the outset of any discussion on incentives for advancing Cl policy, it should be emphasized that broader political turbulence has undermined the coherence of policy development across all sectors in the country. The uncertain prospects of Georgia's EU accession have further constrained the prioritization of aligning national legislation with EU norms, including the GER Directive and the NIS2 Directive. Rather than fostering long-term strategic planning, institu¬ tional dynamics have become increasingly oriented toward regime preservation, often at the expense of democratic consolidation.172 Prior to the government's decision in December 2024 to delay EU accession negotiations until 2028, Georgia's Euro-Atlantic aspirations consistently guided efforts to align national legisla170 All by-laws are accessible at: https:/ / matsne.gov.ge/. 171 Interview with the director of the private cyber security consulting company, September 10, 2025, Tbilisi. 172 European Parliament Press Release, 4 July 2025, available at: https://www.europarl.europa.eu /news/en /press-room /20250704IPR29451/parliament-deplores-the-democratic-backsliding-and-repression-in-georgia. 60
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report tion with EU norms. Nonetheless, reform initiated in 2018 to establish a comprehensive frame¬ work for Cl protection, which at the time would have aligned Georgian legislation with the ECI Directive* 175 and laid the groundwork for transposing the CER Directive, remains stalled. This stagnation reflects not only recent political turbulence but also a lack of strategic leadership and a coherent, long-term policy vision. Consequently, limited prioritization has weakened in¬ centives and motivation, and deficiencies in the policymaking process are directly reflected in the private sector's limited awareness and underdeveloped capacities.174 As noted earlier, the highly digitalized nature of Georgia's financial sector, combined with the persistent threat of cyberattacks from Russia, has intensified the government's focus on devel¬ oping the national cybersecurity domain. Although the NIS Directive has never been formally binding, the country's pro-European orientation was evident in its cyber policy, with the most recent National Cybersecurity Strategy and Action Plan (2021-2024) explicitly identifying alignment with the NIS Directive as a strategic objective. While the strategy implementation report was never made publicly available, leaving the extent of progress toward this objective unclear, the commitment at the national policy level nonetheless served as a significant incen¬ tive and clearly articulated strategic goal. However, Georgia's cyber ecosystem exhibits significant gaps in incentives and state support mechanisms for CISSs. Field experts note,175 that rather than prioritizing trust-based coopera¬ tion and ecosystem strengthening, the government has adopted a predominantly supervisory approach, integrating the security service into the cyber domain. This has made the system more insular and focused primarily on formal legal compliance. The public-private partner¬ ships, widely recognized as critical for developing a coherent policy vision and establishing incentives, have largely remained ineffective in practice, despite their prioritization in the na¬ tional cybersecurity strategy and backing from international donors. Available open-source information indicates only occasional mentions of state supervisors conducting free capacity building trainings for CISSs. While such trainings could be considered a form of incentive, their fragmented and unsystematic nature limits their overall significance. While lacking a systemic approach to incentives and state support mechanisms, the 2021 re¬ form introduced administrative sanctions for violations of information security requirements, thereby establishing a form of legal accountability previously absent. Prior to this reform, the absence of such mechanisms and the predominantly recommendatory nature of the law hin¬ dered effective enforcement of cybersecurity legislation across both the public and private sectors. Interviewed field expert176 contends that, due to insufficient political will, potentially stemming from ongoing political turmoil in the country, state regulators often fail to enforce sanctions rigorously, opting instead for more lenient approaches, which undermines overall compliance. 175 Council Directive 2008/114/EC on the Identification and Designation of European Critical Infrastruc¬ tures (ECI Directive). 174 Interview with the former government official, Security Policy Expert, September 4, 2025, Tbilisi. 175 Interview with former senior official within Georgia's cyber governance framework, September 1, 2025, Tbilisi. 176 Interview with the founder of a Georgian cyber security civil society organisation, September 1, 2025, Tbilisi. 61
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report All interviews conducted with field experts highlight that the capacity of state supervisory agencies is limited, both in terms of human resources and technical capabilities. In addition, deficiencies and ambiguities within the regulatory framework and legislation further under¬ mine the effectiveness and overall capability of supervisory functions. The absence of formal coordination mechanisms among state stakeholders constitutes one of the most significant deficiencies. Each supervisory body maintains its own Computer Emer¬ gency Response Team (CERT), aligned with the CISSs under its jurisdiction. However, the law neither designates a single national CERT nor establishes a formal framework for coordination among existing teams during cyber incidents. This represents a significant gap, not only in terms of alignment with EU norms, but also in creating a fragmented operational landscape that may limit the effectiveness of incident response and undermine the overall resilience of Georgia's CISSs. Furthermore, the absence of an integrated approach leaves the national crisis management framework inadequate, representing one of the key shortcomings in Geor¬ gia's alignment with the NIS2 Directive. Among the key shortcomings undermining the overall capacity of the supervisory system is the absence of a sector-specific approach. The telecommunications sector remains the only do¬ main distinctly categorized within the supervisory framework. However, this formal distinction has not resulted in the establishment of sector-specific supervisory practices. The decision to place the sector under the oversight of the OTA SSSG was initially met with considerable criticism from civil society organizations and expert community, particularly regarding con¬ cerns over supervision of telecom operators and the potential access to sensitive data.177 How¬ ever, in the four years following the reform's implementation, experts have questioned178 the extent to which the OTA SSSG has actively fulfilled its supervisory responsibilities in this sector. In the context of political tensions, the agency may have limited its oversight to avoid conflicts with major private entities that hold substantial economic and political influence within the telecommunications field. Unlike the telecommunications sector, the energy sector is not categorized separately, and the approach applied here appears even less systematic. State-owned energy companies are designated as first-category CISSs and fall under the supervision of the OTA SSSG, whereas private energy companies are classified as third-category CISSs and are overseen by the DGA. The division of supervisory responsibilities between different authorities raises concerns re¬ garding regulatory coherence and the potential for uneven treatment within the energy sector. When assessing capacities within private critical sectors, all interviewed experts highlight a general lack of capability and awareness, an exception being banks, which, due to their high level of digitalization, have invested substantially in cybersecurity. One of the pressing issues identified during the interviews is the insufficient level of cyber awareness among the top management of CISSs. This lack of strategic understanding directly contributes to the under¬ development of institutional cyber capabilities, a concern particularly relevant given that lead¬ ership engagement and awareness are core requirements under the NIS2 Directive. An evident 177 IDFI: "Georgian Parliament should not support Draft Amendments to the Law of Georgia on Infor¬ mation Security", 2020. 178 Interview with the founder of a Georgian cybersecurity civil society organisation, September 1, 2025, Tbilisi. Interview with the former government official, Security Policy Expert, September 4, 2025, Tbilisi. 62
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report reflection of these capacity gaps is the repeatedly extended compliance period for CISSs to meet minimum information security standard. Initially set at two years at the outset of the 2021 reform, the deadline has since been doubled to four years. This pattern suggests both limited capacity among CISSs to meet regulatory requirements and a weak enforcement approach by the state, which has favored deadline extensions over the application of sanctions. It should be noted, that during the implementation period of the previous strategy, interna¬ tional donors launched numerous initiatives aimed not only at strengthening the capacity of state cyber agencies but also at enhancing the resilience of CISSs. However, the enactment of the so-called 'foreign agents law'179 in 2024 substantially reduced the scope of this assis¬ tance. Concluding comments Georgia has long been regarded as a frontrunner among the association trio. On many tech¬ nical benchmarks, the country remains more closely aligned with the European Union than Moldova or Ukraine. However, the recent erosion of democratic standards and the broader departure from the EU integration path have significantly slowed progress.180 As a result, nu¬ merous internal reforms, including those related to the harmonization of Cl regulations with EU-wide norms have stalled, leaving the process marked by stagnation and uncertainty, with no clear prospects or timelines for advancement. The preceding analysis highlights both persistent gaps and incremental advancements in Georgia's Cl policy alignment with EU standards. As noted above, the absence of a compre¬ hensive legal and institutional framework governing Cl suggests, that current cybersecurity efforts may be insufficient to address broader systemic risks. Progress in transposing the CER Directive into national legislation remains highly limited, as Cl reform in Georgia is stalled, lacking a clear roadmap or political commitment. Notably, efforts to strengthen national cyber resilience lay the groundwork for potential align¬ ment with the NIS2 Directive. This is reflected in the European Cyber Security Organisation's (ECSO) NIS2 Transposition Tracker, which indicates that transposition of the directive has com¬ menced and has already reached a partial stage.181 Nevertheless, the continuity of legislative harmonization and the resolution of critical gaps remain uncertain, particularly in light of cur¬ rent strains in EU-Georgia relations.182 179OSCE Office for Democratic Institutions and Human Rights: “Georgia's foreign agents legislation raises concerns over negative impact on civil society", 2025. 180 De Waal, T.: The Orbanizing of Georgia, 2023. 181 ECSO NIS2 Directive Transposition Tracker, available at: https://ecs-org.eu/activities/ nis2-directivetransposition-tracker/. 182 EU NEIGHBOURS east: "Georgia accession process de facto halted as EU calls on government to change course", 2024. 65
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report 5 Conclusions and Recommendations The changing threat landscape is the key driver behind Cl related policies The Cl protection and resilience policies in European countries have been evolving in response to the changing landscape of threats - from natural disasters and extreme weather events to terrorist acts, sabotage and, most recently, a range of potential and actual attacks attributed to Russia amidst Russia's large-scale war against Ukraine, targeting directly its energy and other critical infrastructure. The escalation of the threats to Cl represents a key challenge and at the same time a major incentive for European countries, especially 'front-line' states to continuously review and adapt their policies, institutional routines and practices in order to improve their agility and preparedness in the face of the high uncertainty and flux. The national context is important... The analysis of the Cl related policies in six European countries provided in this report leads to several conclusions. To start with, the national situations in terms of threats perceptions and existing policy and institutional templates aiming to increase protection and resilience of Cl differ. Even countries as similar in their threat perception and recent political, institutional and other reforms as Latvia and Lithuania adopted somewhat different institutional roles and pri¬ orities in responding to the changes in external threats and evolving legal framework as well as learning from experience, including experience of Ukraine. These national differences, often originating from path dependency of past decisions, also affect how EU norms such as CER and NIS2 Directives are being implemented with different institutional responsibilities assigned and different adjustments needed compared to previ¬ ously existing norms. This is particularly visible in the case of Finland where EU norms are seen to some extent as diverging from the established traditional voluntary mode of collaboration between state, private and societal actors in dealing with risks and threats to Cl and main¬ taining societal resilience. The national differences in their Cl related policies and institutional approaches are also visi¬ ble among the three candidate countries, originating first of all from general consensus re¬ garding the goal of EU accession or lack of it, as in the case of Georgia. Another reason for those divergent legal and policy templates is related to different geopolitical situation, in par¬ ticular, threats perception and actual state of experiencing daily kinetic and cyberattacks on the country's Cl as in the case of Ukraine. However, Ukraine's experience has also become a testing ground for new practical resilience measures in restoring the provision of essential services such as electricity, communications and other, thus providing important lessons not only for Ukrainian authorities, private and civil actors, but also for its partners in the EU and other candidate countries. In this respect, European Commission and EU's agencies acting in this field would also benefit from closely monitoring experience of Ukraine from developing anti-drone systems to findings ways how to deal with interruptions of communications and other disturbances by hostile actors. ... but there are important similarities and alignments At the same time, those national differences should not be exaggerated and should be seen in a broader temporal perspective. The analysis shows that in recent years threat perceptions of EU Member States, especially 'front-line states', became more similar. This is reflected in 64
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report comprehensive security (or defence) approaches adopted by Finland, Latvia and Lithuania. Also, dealing with the threats associated with cyberattacks in particular seems to be a com¬ mon policy priority in all countries analysed originating from their frequency, potential for dam¬ age and cross-border nature. In this respect, EU's norms such as NIS2 Directive provide useful template for improving the protection and resilience of Cl entities, while leaving sufficient flexibility to take into account national institutional characteristics and technological evolu¬ tion. More systematic use of the known best practices is important The analysis of selected country cases and their approaches to Cl protection and resilience confirms the importance of state and private actor cooperation as well as cross-border co¬ operation, especially among neighbouring countries facing similar risks and threats and through institutions such as the EU and NATO. Flexibility and agility allowing to respond to the changing nature of threats and technological advances is particularly important and needs to coexist with the tendencies of centralisation and the need for transparency in decision-mak¬ ing, for example, while conducting public procurements. European Commission and EU's rele¬ vant agencies would be advised to cooperate with Member States and candidate countries in the continuous search for the adequate balance, facilitating learning from each other's experience. Similarly, country studies once again confirm that important trade-offs exist in the search for the best methods of increasing resilience of Cl entities, especially in the times of hybrid and kinetic war. The key among those is the trade-off between cost-efficiency and effectiveness and more generally the acknowledgement that strengthening resilience often requires massive investments and regional coordination mechanisms. Finland, Latvia and Lithuania are exam¬ ples of countries which have significantly increased their defence-related spending (and pro¬ vide relatively high support for Ukraine), some of which is being used also for Cl protection and resilience purposes. However, here the role of EU funding and coordinator role of the European Commission seem particularly important. As the negotiations on the new MEE (2028-2054) gather pace in the EU, it is a very appropriate time to decide on allocating money for Ci related investments which would be adequate compared to the current challenges experienced by European countries. The geopolitical outlook signals that those challenges are not going to disappear - rather on the contrary. The new MME should also provide certainty to the candidate countries, which are on the path of EU accession related reforms, that they will also be able to benefit from EU funding and other capacity building measures. As the analysis in this report shows, EU's contribution to capacity building in terms of additional funding, providing of policy tem¬ plates and expertise as well as platforms for sharing best practices and conducting joint ex¬ ercises is extremely valuable and should be continued. 65
ž ū Invigorating Enlargement and Neignbc Policy for a Resilient Europe InvigoratEU | Policy Report Bibliography Alexopoulos, Marcos J., Arto Niemi, Bartosz Skobiej, Frank Sill Torres: Examination of the Critical Infrastructure Resilience Directive from the Maritime Point of View, in: Journal of Common Market Studies, vol. 65, 2025, p. 667-678, https://doi.org/10.1111/jcms.1568. And ans, Maris /Andris Spr ds/Ulf Sverdrup (eds.): Critical Infrastructure in the Baltic States and Norway: strategies and practices of protection and communication, Latvian Institute of International Affairs, 2021. Anglmayer, Irmgard: European Critical infrastructure: Revision of Directive 2008/115/EC, Eu¬ ropean Parliamentary Research Service (EPRS), February 2021, https://www.europarl.europa.eu/RegData/etudes/BRIE/2021/662604/EPRS BRI(2021)662604 EN.pdf (accessed 10.10.2025). "Amendments to the Law on National Security" 12 June, 2025. Accessible on: https: //likumi.lv/ta/id/561476-grozijumi-nacionalas-drosibas-likuma. "Amendments to the Law on Energy" 14 July, 2022. Accessible on: https: //I ikumi.lv/ta/id/554550-grozijumi-energetikas-likuma. Balkan Investigative Reporting Network: Montenegro needs to bolster cyber security institu¬ tions, June 2024, available at: https://balkaninsight.com/2024/Q6/24/montenegro-needsto-bolster-cyber-security-institutions-birn-report. Balodis, Marcis/ Marta Kepe: Lessons from Latvia's Efforts to Keep Essential Services Running During a Crisis, Atlantic Council - New Atlanticist, 07.05.2025, available at: https://www.atlanticcouncil.org/blogs/ new-atlanticist/lessons-from-latvias-efforts-to-keep-essential-services-running-during-a-crisis/ (last accessed 15.09.2025). Bennett, Tom.: Baltic states unplug from Russia and join EU power grid, in: BBC News (bbc.com), 09.02.2025. Boost in cyber resilience of Ukrainian critical infrastructure, EGA, Estonia, https://ega.ee/ukrainian-critical-infrastructure/. Borzel, Tanja A. /Tobia Hofmann/Diana Panke/Carina Sprungk: Obstinate and inefficient: why member states do not comply with European law, in Comparative Political Studies, 45(11), 2010, p. 1565-1590. Borzel, Tanja A. /Ulrich Sedelmeier: Larger and more law abiding? The impact of enlargement on compliance in the European Union, in Journal of European Public Policy, 24 (2), 2017, p. 197-215. Brendler, Viktoria /Eva Thomann: Does institutional misfit trigger customisation instead of noncompliance? In West European Politics, 47(5), 2024, p. 515-542. Budginaite-Froehly, Justina.: Baltic States unplug from Russia's power grid - but Moscow still looms over critical infrastructure, in Atlantic Council, 05.02.2025. 66
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report Cabinet of Ministers Regulation No. 159, "Implementing rules of the European Cybersecurity Competence Centre grant programme "Cybersecurity Transformation of Small and Medium¬ sized Enterprises" for the 2021-2027 programming period" February 27, 2024. Accessible on: https: //likumi.lv/ta/id/550225-eiropas-l<iberdrosibas-kompetencu-centra-20212027-gadaplanosanas-perioda-grantu-programmas-mazo-un-videjo-saimnieciskas-darbibas-veicejukiberdrosibas-transformacija-istenosanas-noteikumi. CEP, Reforming the EU's pre-accession funding instrument, September 2025, available at: https://cep.org.rs/wp-content/uploads/2025/09/Reforminq-the-EUs-pre-accession-funding-instrument.pdf. CER Directive (see https://eur-lex.europa.eu/legal-content/EN/NIM/?uri=CELEX:52022L2557 (accessed 16.07.2025). CERT.LV Activity Report Q4 2024, 27.02.2025, available at: http://cert.lv/uploads/eng/CERT_Report_2024_Q4_ENG.pdf (last accessed 15.09.2025). Civil Georgia: Bloomberg: Russia Hacked Entire Georgia Between 2017-2020, October 21, 2024, available at: https://civil.ge/archives/629567. Civil Georgia: Georgian Dream to Abolish National Security Council, June 16, 2025, available at: https://civil.qe/archives/687508. Competition Market Study of Ukraine's Electricity Sector, https://www.oecd.org/content/dam/oecd/en/publications/reports/2025/06/competition-market-study-of-ukraine-selectricity-sector 045259al/f 28f98ed-en.pdf. Council Directive 2008/114/EC of 8 December 2008 on the identification and designation of European critical infrastructures and the assessment of the need to improve their protection, GJ L 545, 25.12.2008. Council of Europe Parliamentary Assembly Resolution 2585, January 29, 2025, available at: https: // pace.coe.int/ en/files/54147. Council recommendation of 25 June 2024 on a blueprint to coordinate a response at Union level to disruptions of critical infrastructure with significant cross-border relevance GJ C, C/2024/4571, 5.7.2024. Coyle, Carmel: Administrative capacity and the implementation of EU environmental policy in Ireland, in Regional Politics and Policy, 4, 1994, p. p. 62-79. Cyber Resilience Act, European Commission, available at: https://diqital-strateqy.ec.europa.eu/en/policies/cyber-resilience-act. Cyber threat bulletin: Cyber threat activity related to the Russian invasion of Ukraine , https://www.cyber.gc.ca/sites/default/files/cyber-threat-activity-associated-russian-invasion-ukraine-e.pdf. Dimitrakopolous, Dionyssis/Jeremy Richardson: Implementing EU public policy, In Jeremy Rich¬ ardson (ed.) European Union. Power and Policy-making, Routledge, 2nd edition, 2001, p. 555556. 67
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 con¬ cerning measures for a high common level of security of network and information systems across the Union, OJ L 194, 19.7.2016. Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Reg¬ ulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148, OJ L553, 27.12.2022. EGA: Boost in cyber resilience of Ukrainian critical infrastructure, Estonia, available at: https://eqa.ee/ukrainian-critical-infrastructure/ (last accessed 15.09.2025). ENISA: Implementing Guidance on Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 laying down rules for the application of Directive (EU) 2022/2555 as regards technical and methodological requirements of cybersecurity risk-management measures, Oc¬ tober 2024. EU ME, Chapter 5 - Public procurement, June 2025. https://www.eu.me/en/poglavlje-5javne-nabavke/. European Commission: Montenegro report 2024, October 2024, available at: https: //enlarqement.ec.europa.eu/document/download/a41cf419-5475-4659-a5f5af4bc8ed245b en European Commission: Communication from the Commission to the Council and the European Parliament - Critical Infrastructure Protection in the fight against terrorism, COM/2004/0702, 2004. European Commission: Green Paper on a European programme for critical infrastructure pro¬ tection, COM/2005/0576, 2005. European Commission: European Reference Network for Critical Infrastructure Protection: ERNCIP Handbook 2018 edition, Joint Research Centre Technical report, 2018. European Commission: "The European Programme for Critical Infrastructure Protection", MEMO/06/477, 12 December 2006, available at: http://ec.europa.eu/comnnission/presscorner/detail/en/memo 06 477 (last accessed 05.09.2025). European Commission: Evaluation study of Council Directive 2008/114 on the identification and designation of European critical infrastructures and the assessment of the need to im¬ prove their protection, 2 April 2019, available at: https://op.europa.eu/en/ publication-de¬ tail /-/publication /118dcd5d-b041-11ea-bb7a-01aa75ed71al/languaqe-en (last accessed 05.09.2025). European Commission: Commission Staff Working Document - Impact Assessment Report Ac¬ companying the document Proposal for a Directive of the European Parliament and of the Council on measures for a high common level of cybersecurity across the Union, repealing Directive (EU) 2016/1148, SWD/2020/545 final - part 1/5, 2020. 68
•^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report European Commission: ReArm Europe Plan/Readiness 2050, available at: https: //commisSion.europa.eu/document/download/e6d5db69-e0ab-4bec-9dc0-5867b4575019 en (last accessed 24.10.2025). European Commission and the High Representative of the Union for Foreign Affairs and Secu¬ rity Policy: Preparedness Union Strategy, JCIN(2025) 150 final, 2025. European Commission: Communication from the Commission on Protect EU: a European In¬ ternal Security Strategy, no. COM (2025) 148 final, 2025. European Union: Cyber Direct Montenegro, 2025, available at: https://eucyberdirect.eu/atlas/country/montenegro. EU NEIGHBOURS east, Georgia accession process de facto baited as EU calls on government to change course, October 50, 2024, available at: https://euneighbourseast.eu/news/latestnews/qeorgia-accession-process-de-facto-halted-as-eu-calls-on-qovernment-to-chanqecourse/. European Cyber Security Organisation (ECSO), NIS2 Directive Transposition Tracker, available at: https://ecs-org.eu/activities/ nis2-directive-transposition-tracker/. European Parliament, "Parliament Deplores the Democratic Backsliding and Repression in Georgia." Press release, 4 July 2025. Available at: https://www.europarl.europa.eu/news/en/press-room/20250704IPR29451/ parliament-deplores-the-democraticbacksliding-and-repression-in-georgia. European External Action Service: Assessment of Cybersecurity Risks in Montenegro: Chal¬ lenges and Recommendations'. EU Publications, 2 October, 2025, available at: https://www.eeas.europa.eu/sites/default/files/documents/2024/Monteneqro%20Report7o202024.pdf (last accessed 21.01.2025). European Union Agency for Cybersecurity (ENISA), ENISA Threat Landscape 2024, September, 2024, available at: https://www.enisa.europa.eu/sites/default/files/202411/ENISA%20Threat%20Landscape%202024 O.pdf. Executive order of the Prime Minister No. 2024/1.2.1.-416 "On the National Cybersecurity Council", December 6, 2024. Accessible on: https:/ /likumi.lv/ta/id/557025-par-nacionalokiberdrosibas-padomi. Falkner, Gerda /Oliver Treib: Three worlds of compliance or four? The EU-15 compared to new member states, in Journal of Common Market Studies, 46(2), 2008, p. 295-515. Federation of employers of Ukraine, available at: https://www.facebook.com/story.php?story fbid=140164516l445456&id=l0004795897017l&mibextid=wwXlfr&rdid4j9ltvGjOku4XevN# (last accessed 15.09.25). Finland's Prime Minister's Office: Finland's Cyber Security Strategy 2024-2055, 25 October 2024, available at: https://julkaisut.valtioneuvosto.fi/bitstream/handle/10024/165895/VNK 2024 15.pdf?sequence=1&isAllowed=y (last accessed 25.10.2025). 69
š ć ć Č •^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report 11. Interview with the Montenegro Ministry of Interior's officials, October 17, 2024, via Zoom. 12. Interview with Du an Polovi , Director General of the Directorate for Infrastruc¬ ture, Information Security, and Digitalization, Ministry of Public Administration, May 18, 2025, Podgorica. 15. Interview with Ivan Bulatovic, General Manager of Elektroprivreda Crne GoreEPCG the largest energy company, May 25, 2025, Podgorica. 14. Interview with experts in IT department Montenegro Electric Power Company on September 10, 2025, Podgorica. 15. Interview with Savo Kentera, expert in security and international relations, the President of the Atlantic Alliance of Montenegro, September 8, 2025, Podgorica. 16. Interview with Ivan Stankovi of the private IT company ikom September 8, 2025, Podgorica. 17. Interview with former high official of a state cyber security agency of Georgia, September 1, 2025, Tbilisi. 18. Interview with the founder of a Georgian cyber security civil society organisation, September 1, 2025, Tbilisi. 19. Interview with the former Georgian government official, Security Policy Expert, September 4, 2025, Tbilisi. 20. Interview with the director private cyber security consulting company, September 10, 2025, Tbilisi. 21. Communication with the Verkhovna Rada of Ukraine representative on Cl pro¬ tection in the written format (received on 19.09.2025). 22. Communication with the former executives of Ukrainian TSO (Ukrenergo) on Cl protection in the written format (received on 19.09.2025). 23. Communication with the NEURC representative on Cl protection in Ukraine in the written format (received on 11.09.2025). 76
^^InvigoratEU 'Invigorating Enlargement and Neighbourhood Policy for a Resilient Europe InvigoratEU | Policy Report About InvigoratEU InvigoratEU is a Horizon Europe-funded project, coordinated by the EU-Chair at the Uni¬ versity of Duisburg-Essen (UDE) together with the Institut für Europäische Politik (IEP) in Berlin. The project, with a duration of 5 years from January 2024 until December 2026, examines how the EU can structure its future relations with its Eastern neighbours and the countries of the Western Balkans. The consortium has received around three million euros for this endeavour. How can the EU invigorate its enlargement and neighbourhood policy to enhance Europe's resilience? Our first goal is to investigate how to re¬ form the EU's enlargement strategy in a new geopolitical phase, HOW TO RE¬ SPOND to other actors' geopolitical am¬ bitions in the Eastern Neighbourhood and Western Balkans, and HOW TO RE¬ BUILD the EU's foreign policy arsenal in view of a new era of military threats (tri¬ ple "R" approach) combining the mod¬ ernisation and geopolitical logics of EU enlargement, leading to new data - e.g. a public opinion survey in Ukraine, a set of scenarios, an external influence index (Russia, China, Turkey), and a social policy compli¬ ance and cohesion scoreboard. 77 Our second goal is to elaborate an evidence-based, forward-looking vision for the EU's political agenda and institutional frameworks for co-designing a multidimensional toolbox (i.e. two tailor-made toolkits), together with InvigoratEU s Expert Hub, Civil Society (CS) Network, Youth Labs, Workshops for Young Professionals and Policy Debates in a gaming set up, which will result in context-sensitive and actionable policy recommendations for Euro¬ pean and national political stakeholders and (young) European citizens in particular. Funded by the European Union Our third goal is to deploy a CDE (communication, dissemination and exploitation) strategy aiming at recommendations from Day 1 to maximize our scientific, policy and societal im¬ pact in invigorating the EU's enlargement and neighbourhood policies to enhance Europe's resilience. Ultimately, InvigoratEU is a deliberately large consortium respecting the diversity of Europe and political perspectives; 7 out of 18 are from Georgia, Moldova, Ukraine, and the western Balkans (North Macedonia, Montenegro, Serbia), complemented by our Civil Society Network of 9 representatives from all Western Balkan countries, Georgia, Moldova and Ukraine. InvigoratEU is funded by the European Union. Disclaimer: Views and opinions expressed are however those of the author(s) only and do not nec¬ essarily reflect those of the European Union or the European Research Executive Agency. Neither the European Union nor the granting authority can be held responsible for them.