Skip to main content

LUP Student Papers

LUND UNIVERSITY LIBRARIES

EU Cybersecurity obligations for healthcare providers - The NIS 2 Directive, the Cybersecurity Act, and the Emerging EU Certification Framework

Simfors, Daniel LU and Helander, Mathilda LU (2026) HARN63 20261
Department of Business Law
Abstract
The purpose of this thesis is to examine the extend of cybersecurity obligations imposed on healthcare providers under EU law. To achieve this, the research questions focus on selected parts of the NIS 2 Directive and the Cybersecurity Act. Particular attention is afforded cybersecurity risk-management measures required under Article 21 of the NIS 2 Directive, as well as the role of certification schemes established under the Cybersecurity Act. The thesis further considers the recently proposed Cybersecurity Act 2, with its targeted amendments to the NIS 2 Directive, in order to assess the future development of EU cybersecurity regulation within the healthcare sector.
The thesis finds that neither the NIS 2 Directive nor the Cybersecurity... (More)
The purpose of this thesis is to examine the extend of cybersecurity obligations imposed on healthcare providers under EU law. To achieve this, the research questions focus on selected parts of the NIS 2 Directive and the Cybersecurity Act. Particular attention is afforded cybersecurity risk-management measures required under Article 21 of the NIS 2 Directive, as well as the role of certification schemes established under the Cybersecurity Act. The thesis further considers the recently proposed Cybersecurity Act 2, with its targeted amendments to the NIS 2 Directive, in order to assess the future development of EU cybersecurity regulation within the healthcare sector.
The thesis finds that neither the NIS 2 Directive nor the Cybersecurity Act establishes a fully cohesive or horizontally applicable cybersecurity framework. Nevertheless, the NIS 2 Directive achieves an important regulatory foundation, requiring healthcare providers to implement appropriate technical, operational, and organisational cybersecurity measures. Examples include secure medical devices, protecting its physical environment, and cybersecurity training for staff. At the same time, healthcare providers retain considerable discretion in determining which of those measures are suitable in practice.
By contrast, the regulatory significance of certification schemes under the Cybersecurity Act remains limited. The certification framework operates largely on a voluntary basis and predominantly targets manufacturers of digital solutions. From the forward-looking perspective, the proposed Cybersecurity Act 2 indicates a significant strengthening of EU certification. It suggests a shift toward more market- oriented perspectives, introduces cyber posture assessments, and enhanced operational supply-chain security. Whether these developments will produce a more functionable cybersecurity framework within the healthcare sector, remains to be determined. (Less)
Please use this url to cite or link to this publication:
author
Simfors, Daniel LU and Helander, Mathilda LU
supervisor
organization
course
HARN63 20261
year
type
H1 - Master's Degree (One Year)
subject
keywords
EU Cybersecurity law, Healthcare, NIS 2 Directive, Cybersecurity Act, ICT certification.
language
English
id
9234637
date added to LUP
2026-06-10 09:36:40
date last changed
2026-06-10 09:36:40
@misc{9234637,
  abstract     = {{The purpose of this thesis is to examine the extend of cybersecurity obligations imposed on healthcare providers under EU law. To achieve this, the research questions focus on selected parts of the NIS 2 Directive and the Cybersecurity Act. Particular attention is afforded cybersecurity risk-management measures required under Article 21 of the NIS 2 Directive, as well as the role of certification schemes established under the Cybersecurity Act. The thesis further considers the recently proposed Cybersecurity Act 2, with its targeted amendments to the NIS 2 Directive, in order to assess the future development of EU cybersecurity regulation within the healthcare sector.
The thesis finds that neither the NIS 2 Directive nor the Cybersecurity Act establishes a fully cohesive or horizontally applicable cybersecurity framework. Nevertheless, the NIS 2 Directive achieves an important regulatory foundation, requiring healthcare providers to implement appropriate technical, operational, and organisational cybersecurity measures. Examples include secure medical devices, protecting its physical environment, and cybersecurity training for staff. At the same time, healthcare providers retain considerable discretion in determining which of those measures are suitable in practice.
By contrast, the regulatory significance of certification schemes under the Cybersecurity Act remains limited. The certification framework operates largely on a voluntary basis and predominantly targets manufacturers of digital solutions. From the forward-looking perspective, the proposed Cybersecurity Act 2 indicates a significant strengthening of EU certification. It suggests a shift toward more market- oriented perspectives, introduces cyber posture assessments, and enhanced operational supply-chain security. Whether these developments will produce a more functionable cybersecurity framework within the healthcare sector, remains to be determined.}},
  author       = {{Simfors, Daniel and Helander, Mathilda}},
  language     = {{eng}},
  note         = {{Student Paper}},
  title        = {{EU Cybersecurity obligations for healthcare providers - The NIS 2 Directive, the Cybersecurity Act, and the Emerging EU Certification Framework}},
  year         = {{2026}},
}