European Union
Europe
The European Union governs telecom security through overlapping instruments: the NIS2 Directive (2022/2555), the European Electronic Communications Code (EECC) Article 40, ENISA guidance, and the 5G Cybersecurity Toolbox. Together they set the modern baseline for operator security programs across all 27 member states.
Regulator: ENISA + national NRAs (BNetzA, ARCEP, AGCOM, ANACOM, etc.)
Primary frameworks: NIS2 Directive 2022/2555, EECC Article 40, ENISA guidelines, 5G Cybersecurity Toolbox
NIS2 scope for operators
Telecom providers fall under Annex I as "essential entities". Obligations include risk management measures, 24-hour incident notification, supply-chain security, and management liability. Fines reach EUR 10M or 2% of global turnover.
EECC Article 40 signaling obligations
Article 40 requires operators to take technical and organizational measures against risks to security of networks and services. National regulators translate this into signaling firewall requirements (SS7 / Diameter / GTP) and roaming-security controls. ENISA has published implementation guidance mapping to GSMA FS.11, FS.19, FS.20.
5G Toolbox
The EU 5G Cybersecurity Toolbox is not binding law but member states have transposed most measures. Key items: high-risk vendor restrictions, defense-in-depth requirements, key network function protection, and coordinated risk assessment.
Cross-border coordination
CSIRTs Network and the EU-CyCLONe support cross-border incident coordination. Roaming security concerns escalate through BEREC and the NIS Cooperation Group.
Key takeaways
- NIS2 incident reporting is 24h initial + 72h detailed + 1m final — signaling firewall telemetry must feed the SOC ticketing chain.
- Article 40 is the legal basis regulators cite when asking about SS7/Diameter/GTP controls.
- Management liability under NIS2 creates board-level ownership of telecom-security posture.