Cybersecurity Policy, Strategic Resilience and the Governance of Emerging Technologies: The European architecture after the 2026 reform package and what it means for national administrations
This working paper examines the transformation of European cybersecurity policy from a regime of regulatory compliance into one of strategic resilience, in the context of the legislative reform package tabled in January 2026 and the accelerating diffusion of disruptive technologies. The central argument is that between 2022 and 2026 the European Union built a dense regulatory architecture — NIS2, the Cyber Resilience Act, the Cyber Solidarity Act, DORA, the AI Act — whose principal vulnerability is no longer the absence of rules, but the distance between legal obligation and effective operational capability. The paper proposes a five-dimensional analytical model (robustness, redundancy, resources, rapidity, reflexivity) and a compliance–capability matrix that distinguishes organisations which document security from those which produce it. The analysis is grounded in ENISA threat data, in the consolidated 2026–2035 compliance calendar and in the Romanian transposition of NIS2 as a national case study. It concludes by identifying five structural tensions — simplification versus protection, technological pace versus legislative cycle, sovereignty versus interdependence, centralisation versus subsidiarity, and administrative capacity versus regulatory ambition — and formulates eight policy recommendations. This record contains both the English version and the Romanian version of the same paper (Politici de securitate cibernetică, reziliență strategică și guvernanța tehnologiilor emergente). Project context. This working paper was prepared in the context of the CYBERGUARD project (Grant Agreement No 101190251), co-funded by the European Union, and serves as a background paper for the European Cyber Resilience Forum (Bucharest, 12 November 2026). It is not a contractual deliverable and does not commit the project consortium. The views expressed are those of the author alone and do not necessarily reflect the position of the European Union, the granting authority, or the National Cyber Security Directorate of Romania. Neither the European Union nor the granting authority can be held responsible for them.