The rulebook for subsea and offshore infrastructure in the EU and the Baltic, 2024-2026
CER, NIS2, the Cable Security Action Plan, national laws and the insurance market's answer
Almost every Baltic-region state missed the EU's October-2024 deadline for the CER and NIS2 directives, and enforcement by litigation — not the deadline itself — is what has actually moved Poland and Sweden. Meanwhile Finnish courts have flipped twice on who can prosecute the Eagle S crew, and an English court's Nord Stream ruling shows conventional war-risk exclusions can defeat a subsea-sabotage insurance claim without ever naming a perpetrator.
Select any sentence or paragraph to go deeper or ask a question. You see the evidence and the price first; if our research can’t answer, you’re not charged. First 2 answers free.
Two clocks, one Baltic Sea
Since late 2024 the Baltic Sea has run on two clocks that rarely agree. One is the legal clock: the EU's Critical Entities Resilience (CER) and NIS2 directives, a new Action Plan on Cable Security, and a wave of national bills that were all supposed to be in force by 17 October 2024. The other is the incident clock: the Eagle S cutting Estlink 2 and four telecom cables on Christmas Day 2024, the Fitburg dragging its anchor 130 km across the seabed a year later, and the Nord Stream pipelines' insurers fighting a €570-580m claim through the English courts in 2026. This report tracks where the legal clock actually stands, state by state, against what the incident clock has already forced operators, insurers and courts to decide.
The EU's legal architecture: CER and NIS2
NIS2 (Directive (EU) 2022/2555) sets cybersecurity risk-management and incident-reporting rules for entities across 18 sectors, including energy, transport, health and digital infrastructure, and was meant to apply from 18 October 2024. It also puts personal accountability for non-compliance on top management and creates an EU-wide CSIRT network plus the EU-CyCLONe crisis-liaison network for large-scale incidents.
CER (Directive (EU) 2022/2557) is NIS2's physical-resilience counterpart: it covers natural and man-made risks — including sabotage — to essential services in sectors such as energy, transport, banking, water and digital infrastructure, and builds on a December-2022 Council Recommendation and the Commission's ProtectEU internal-security strategy. Its deadlines are staggered: transposition by 17 October 2024, a national risk assessment and resilience strategy by 17 January 2026, and formal designation of individual critical entities by 17 July 2026.
The transposition scoreboard: who has actually done it
Almost every Baltic-region state missed the 17 October 2024 deadline for one or both directives. On 7 May 2025 the Commission sent a reasoned opinion to 19 Member States for incomplete NIS2 notification — seven of the eight states in this bundle (Denmark, Germany, Estonia, Latvia, Poland, Finland, Sweden) were on that list; only Lithuania was not. A separate, later wave on 8 July 2026 referred four other Member States (Ireland, Spain, France, the Netherlands — none of them Baltic-region) to the Court of Justice for NIS2, showing the enforcement pipeline running two tracks in parallel. On 29 April 2026 a second enforcement wave referred seven states, including Poland and Sweden, to the Court of Justice for still not having transposed CER at all.
- 20252025-04-08Finland: Cybersecurity Act 124/2025 (NIS2) in force
- 2025-05-07EC reasoned opinion to 19 states incl. 7 of 8 Baltic states (NIS2)
- 2025-06-28Latvia: National Security Law amendments (CER) in force
- 2025-07-01Finland: Critical Infrastructure Act 310/2025 (CER) in force
- 2025-07-01Estonia: Emergency Act amendments (CER) in force
- 2025-07-01Denmark: Act on Resilience of Critical Entities (CER) in force
- 2025-07-08Lithuania: NIS2 status confirmed 'Transposed' by EC
- 2025-12-06Germany: BSIG (NIS2) applies to ~30,000 entities
- 20262026-01-15Sweden: Cybersecurity Act 2025:1506 (NIS2) in force
- 2026-02-19Poland: NIS2 amendment signed by President
- 2026-03-17Germany: KRITIS-Dachgesetz (CER) in force
- 2026-04-29EC refers Poland and Sweden (+5 others) to CJEU for CER
- 2026-06-19Poland: CER-implementing law signed by President
- 2026-07-14Sweden: CER bill submitted to Riksdag, proposed force 2027-01-01
| State | NIS2 status (as of Sept 2026) | CER status (as of Sept 2026) |
|---|---|---|
| Finland | In force 2025-04-08 (124/2025) | In force 2025-07-01 (310/2025) |
| Estonia | Reasoned opinion 2025-05-07; since resolved (no later referral) | In force 2025-07-01 (Emergency Act amendments) |
| Sweden | In force 2026-01-15 (2025:1506) | Proposed only — bill filed 2026-07-14, force expected 2027-01-01; referred to CJEU 2026-04-29 |
| Denmark | Reasoned opinion 2025-05-07; since resolved (no later referral) | In force 2025-07-01 |
| Poland | In force 2026-04-03 (signed 2026-02-19) | In force 2026-07-04 (signed 2026-06-19), ~10 weeks after CJEU referral |
| Germany | Reasoned opinion 2025-05-07; in force 2025-12-06 (BSIG) | In force 2026-03-17 (KRITIS-Dachgesetz) |
| Lithuania | Transposed — the only Baltic state never on a reasoned-opinion or CJEU list | Transposed via 2024-2025 amendments, later than the Oct-2024 deadline but not referred to CJEU |
| Latvia | Reasoned opinion 2025-05-07; since resolved | In force 2025-06-28 |
Lithuania stands out: it is the only one of the eight states never named on either the NIS2 reasoned-opinion list or the CER referral list, giving it the cleanest transposition record in the region even though its CER law arrived late.
Estonia's criminal-law answer to a jurisdiction gap
Separately from CER/NIS2, Estonia's Riigikogu advanced Bill 656 SE, extending Estonian criminal jurisdiction to its own continental shelf and exclusive economic zone, criminalising negligent (not just intentional) damage to submarine cables and pipelines, and permitting covert surveillance in such investigations. The Legal Affairs Committee sent it to a first reading on 8 October 2025. A committee member flagged that the Bill bundles very different offence types — from major infrastructure damage to misdemeanours involving state secrets committed abroad — and suggested its title be updated to match.
Read together with the EEZ-jurisdiction extension, this looks like a deliberate pivot: where NIS2/CER-style administrative fines only reach regulated operators, Estonia is building a criminal-liability track aimed at the vessels and owners actually responsible for the damage — entities that regulatory fines against domestic TSOs or telecoms operators cannot touch.
Eagle S, Estlink 2, and a jurisdiction ruling that flipped twice
On 25 December 2024 the Cook Islands-flagged Eagle S dragged its anchor across the Gulf of Finland, cutting the Estlink 2 power cable and several telecom cables. Fingrid, Finland's transmission operator, moved fast: it applied to the Helsinki District Court to seize the vessel to secure its damages claim before Eagle S could sail on.
Repairing Estlink 2 cost an estimated €50-60m, split between Fingrid and Elering; prosecutors later cited 'at least €60 million' in repair costs alone. Nexans completed the physical repair, under contract to Fingrid, on 6 August 2025 — roughly six months after the cut. Rather than wait on an insurance payout, Fingrid and Elering chose to sue Eagle S's shipowner directly, accepting that a full court process could take five to six years and that the two utilities would have to front the repair costs themselves in the meantime.
On 3 October 2025 the Helsinki District Court dismissed the criminal case against Eagle S's master and two officers, holding that under UNCLOS Article 97(1) the cable-cutting was an 'incident of navigation' that only the flag state (Cook Islands) or the officers' own states could prosecute, and that Finland's own implementation of Article 113 protects only Finnish cables and nationals.
Finland appealed. On 27 August 2026 the Helsinki Court of Appeal reversed course entirely: because the damage and its effects on Finland's power and telecoms supply occurred in Finland, and because the crew's conduct after Finnish authorities intervened went beyond an ordinary 'maritime accident' under UNCLOS, Finland does have jurisdiction. The case now returns to the district court for a full merits hearing — though the three defendants have since left the country.
UNCLOS's cable gap — and the two answers on offer
The underlying legal problem both Helsinki rulings wrestled with predates any of them: under the prevailing reading of UNCLOS, a coastal state generally cannot board a foreign-flagged vessel suspected of cutting its cables in its own exclusive economic zone without the flag state's permission — permission that can be slow, or may never come.
SIPRI's Pierre Thévenin argues the fix has to be domestic legislation: Baltic states should create cable safety zones banning anchoring, dredging and trawling, paired with strict liability and a reversed burden of proof, following approaches Denmark, Australia and New Zealand already use in some form. The industry's own International Cable Protection Committee (ICPC) — founded in 1958, now over 260 members from 75+ nations — takes a more conservative line: it backs the existing UNCLOS framework as sufficient and pushes instead for faster, more predictable national permitting for repair and maintenance, describing the industry's existing repair-vessel network as already 'robust and well-established'.
The EU's cable-security money and toolbox
On 21 February 2025 the Commission and the EU's High Representative jointly adopted the Action Plan on Cable Security, built on a February-2024 Recommendation and an October-2025 EU risk assessment. Its Cable Security Toolbox report — published 5 February 2026, corrected 16 March 2026 — sets out six strategic and four technical/support measures spanning prevention, detection, response/recovery and deterrence.
The first dedicated repair-module funding call, worth €20m, opened around 6 February 2026 — and deliberately targets the Baltic Sea first, before the Mediterranean and Atlantic, because that is where cable disruptions have concentrated.
Insurance: who actually pays when a cable or pipeline is cut
The clearest answer so far comes not from the Baltic but from Nord Stream. In September 2022 explosions ruptured both Nord Stream pipelines and left a separate indentation on one line; Nord Stream AG, majority-linked to Gazprom, held offshore all-risks cover with Lloyd's Insurance Company S.A. and Arch Insurance (EU) DAC.
On 6 July 2026 the English Commercial Court (Judge Clare Moulder) dismissed Nord Stream's claim entirely. The court held that the war exclusion applied because the Russia-Ukraine war was a 'significant' — noticeable, specifically accountable — contributing cause of the sabotage, without needing to rank that cause against any other, and without the court ever having to decide whether Russia, Ukraine or another actor actually did it.
The practical read-across for the Baltic: because the ruling did not require identifying the actual saboteur, operators of Baltic cables, pipelines and offshore wind facing an unattributed attack should expect a broadly worded war exclusion to bite regardless of whether the eventual culprit turns out to be a state or a private actor. Law-firm analysts separately expect (re)insurers to keep widening state-sponsored-sabotage exclusions across subsea-energy risk more generally — which a market-gap prediction says will leave a coverage hole even as offshore/subsea assets multiply.
Screening the vendors and the money
On 20 January 2026 the Commission proposed a Cybersecurity Act recast ('CSA2') that would let it require exclusion of high-risk ICT suppliers from designated supply chains — extending the EU's 5G-style vendor-security approach to fibre-optic network equipment specifically — backed by fines reaching up to 7% of worldwide turnover for the most serious supply-chain breaches. It remains a proposal, not law, as of this report.
On the investment side, the EU's new Foreign Investment Screening Regulation (FISR) — replacing the 2019 regime — was adopted by Parliament on 19 May 2026 and Council on 8 June 2026, enters into force 16 July 2026 and applies from 17 January 2028. It ends the voluntary opt-out: every Member State must now run a national FDI-screening mechanism, with a mandatory minimum scope covering energy, transport and digital-infrastructure critical entities, hyper-critical technologies, dual-use items, critical raw materials, electoral infrastructure and part of the financial system.
National law is already moving in the same direction at the sharpest edge: Germany's KRITIS-Dachgesetz lets its Interior Ministry designate additional facilities as 'critical' case-by-case, feeding directly into German FDI-screening thresholds, while Latvia's CER-implementing law goes further still, barring Russian and Belarusian citizens and Russia/Belarus-registered entities from owning, controlling or working inside critical infrastructure at all, absent case-by-case security-authority approval.
What the owner should double-check before publishing
- Confirm Poland's exact CER/NIS2 publication and entry-into-force dates (this run relied on search-engine synthesis of Polish legal-advisory sites for the 2 March / 3 April / 4 July 2026 dates, not a single directly-opened Polish government primary source).
- Confirm whether Estonia's Bill 656 SE (jurisdiction/penalties) has completed all Riigikogu readings and entered into force since its 8 October 2025 first reading.
- Verify Lithuania's exact CER transposition date and instrument name (this run found only 'amendments during 2024-2025' via a private tracker, not an official Lithuanian or EC-page date).
- Re-check Sweden's CER bill (Proposition 2025/26:303) status after its 13 October 2026 counter-motions deadline and expected autumn-2026 Riksdag decision.
- Reconcile the Nord Stream claim-size discrepancy (€570m / €579m / €580m across sources) against the judgment text itself if a full-text copy becomes available.