Iceland falls behind Europe on cybersecurity
Wednesday 2nd September 2026 on 13:45 in
Iceland
Iceland has fallen behind other European countries in cybersecurity and the implementation of cybersecurity rules, mbl.is reports, citing comments from the Telecommunications Authority on the government’s planned green paper on telecommunications and cybersecurity.
The authority says Iceland’s delayed implementation of the European Union’s NIS2 directive on network and information security is primarily the result of insufficient prioritisation and policymaking in the cybersecurity sector.
“It is noteworthy that the 2027 to 2031 financial plan does not provide for the implementation of NIS2 or other important measures aimed at strengthening the cybersecurity framework in Iceland,” the authority said. It added that cyber threats were growing rapidly, including through the use of artificial intelligence.
The authority said the government should be aware of the risks created by the limited ability of critical infrastructure in Iceland to defend itself against cyber threats. A substantial proportion of organisations already designated as critical infrastructure had not taken the necessary measures to establish adequate cybersecurity management systems, it said.
Findings from the authority’s inspections also indicated shortcomings in compliance with current cybersecurity legislation in too many places. The legislation sets minimum requirements for risk management and preparedness, and the authority said cybersecurity was therefore inadequate.
NIS2 was due to be implemented in October 2024
The implementation of the EU’s NIS2 cybersecurity directive has been pending in Iceland for a considerable time. The deadline for EU member states to implement it expired in October 2024, although implementation has not been completed in all member states.
The directive will be considerably broader than the previous directive it replaces, the Telecommunications Authority said, resulting in a significant increase in the number of organisations covered by the rules.
Warnings against excessive requirements
Thirty-two submissions have been made through the consultation portal for the green paper. The Icelandic Chamber of Commerce said the directive should be implemented with restraint, warning against “gold-plating” European Economic Area rules by introducing requirements that are stricter or broader than those arising from the relevant EEA legislation.
Míla also called for unnecessary gold-plating to be avoided. It said Iceland should not introduce additional national requirements beyond those necessary to meet its EEA obligations unless specific and documented risks in Iceland justified them.
The Telecommunications Authority said the directive should be implemented as soon as possible, with its entry into force and full funding in place no later than the beginning of 2028.
In its detailed comments on telecommunications and cybersecurity, the authority recommended assessing the need for a dedicated national emergency telecommunications system for serious disruptions in which backbone networks and the electricity system become unavailable. It said the rapid development of low-orbit satellite systems could create new and more cost-effective options for such infrastructure.
Korda ehf., a company formed through the merger of Farice, Öryggisfjarskipti and the technology division of Neyðarlínan at the end of last month, operates the three telecommunications subsea cables connecting Iceland with Europe, among other activities.