EU Maritime Regulatory Convergence · 2026–2027

Where the pressure is.
How long it lasts.

Three European regulatory frameworks — NIS2, CER, and Italy's Circolare 177 — converge on maritime operators between June 2026 and approximately June 2027. This is not a one-time audit. It is twelve months of compounding obligation.


Three instruments. One window. No sequencing relief.

Each framework has its own authority, its own deadline, and its own penalty regime. They do not wait for each other. A port authority facing CER designation in July cannot defer its NIS2 categorisation in June. A PFSO managing Circolare 177 in November cannot pause CER risk assessment preparation due the following spring.

NIS2
Network & Information Security Directive
D.Lgs. 138/2024 · ACN Enforcement
Requires documented risk management processes, supply chain security, incident reporting capability, and active governance — continuously, not at audit time. Personal director liability under Article 20.
Annual categorisation30 Jun 2026
Italy full compliance (est.)Oct–Nov 2026
Annual review cycleJun 2027
Max fine (essential)€10M / 2% turnover
CER
Critical Entity Resilience Directive
D.Lgs. 134/2024 · All-hazards scope
Designated critical entities must conduct all-hazards risk assessments covering physical, cyber, and hybrid threats. Formal notification — following designation — starts a roughly 10-month compliance clock with no extensions.
Designation17 Jul 2026
Risk assessment due (est.)May 2027
Full compliance (est.)Jun 2027
ScopePorts · ferries · cables (likely)
Circ. 177
Circolare 177/2025
Capitanerie di Porto (under MIT) · Maritime cyber risk
Italy's maritime cyber risk circular, aligned with IMO MSC-FAL.1/Circ.3/Rev.3. Requires mandatory cyber risk assessments for port facilities and ferry operators under the Capitanerie di Porto command — narrower in scope than NIS2 or CER's hybrid/all-hazards coverage.
Binding date1 Nov 2026
Enforcement authorityCapitanerie di Porto
ScopePorts · ferries · AdSP
ConsequenceRemediation orders

Twelve months. No gap between obligations.

The three frameworks do not overlap neatly. They stack. Each new deadline arrives before the previous obligation is resolved. The pressure window opens in June 2026 and does not close until approximately June 2027.

JUN
JUL
AUG
SEP
OCT
NOV
DEC
JAN
FEB
MAR
APR
MAY
NIS2
Categorisation 30 Jun
Italy full Oct
CER
Designation 17 Jul
Risk assess. May (est.)
Full compliance Jun (est.)
Circ. 177
Binding 1 Nov
▸ Computing deadlines…
Where the pressure is.
The pressure is concentrated on port authorities and PFSO licence holders — the only operators who sit in scope of all three frameworks simultaneously.
Port authorities (AdSP) — NIS2 + CER + Circolare 177. All three, no sequencing relief. Personal director liability under NIS2 Article 20 attaches to management bodies from June 30.
PFSO licence holders — NIS2 + CER + Circolare 177 obligations all apply, though personal director liability is a NIS2 Article 20 matter, not a PFSO-specific one. Circolare 177 cyber risk assessment and training obligations apply directly from November.
Ferry and Ro-Ro operators — CER + Circolare 177. Designation in July starts the notification clock toward risk assessment.
Subsea cable operators — NIS2 + likely CER. Cable inclusion under CER sits at member state discretion — not explicitly named in the Directive Annex — but Mediterranean exposure makes in-scope treatment likely.
How long it lasts.
The pressure window is roughly twelve months. It does not end at the first deadline — it escalates. Each new deadline raises the standard required by the previous one.
June 30 — NIS2 annual categorisation. Entities submit risk classification to the ACN portal. ACN's on-site inspections are expected from late 2026.
July 17 — CER designation. Formal notification typically follows within weeks, starting the roughly 10-month clock. Entities arriving without active monitoring already behind from day one.
November 1 — Circolare 177. Enforceable. The Capitanerie di Porto command begins inspections. Operators without cyber risk documentation face formal remediation orders.
~June 2027 — CER full compliance (est.). The final deadline. Everything built since July must be documented, demonstrable, and continuous.
The overlap

Between July 17 and November 1, 2026, port authorities, PFSOs, and ferry operators are simultaneously under active NIS2 enforcement, inside the CER designation and notification window, and preparing for Circolare 177 to become binding. There is no gap in which one obligation can be satisfied before the next begins. The only answer is a platform that satisfies all three continuously — not a document produced per deadline.


One platform. Three obligations. Continuous.

Sentinella Mare is built for this window — not retrofitted to it. The MHTES scoring framework, the compliance export architecture, and the three-panel intelligence workflow are designed around the specific requirements of NIS2 Article 21, CER's all-hazards scope, and Circolare 177's cyber risk mandate.

NIS2 Response
The Asset Status panel is your continuous risk management record — updating every 30 minutes, auditable on demand. The compliance CSV export maps directly to Article 21 requirements. The AI compliance report (PDF/A-1b) is board and auditor ready at Sentinel and Command tiers. NIS2 is a process obligation, not a report obligation. Sentinella is the process.
CER Response
P-MHTES and C-MHTES scores provide the external hybrid threat intelligence layer required by CER's all-hazards risk assessment — the component no internal IT tool can produce. Entities beginning monitoring at designation in July arrive at the estimated May 2027 risk assessment deadline with approximately ten months of continuous documented history. The risk assessment is not written — it is already recorded.
Circolare 177 Response
Sentinella's cyber vulnerability signals (OT/IT) and Asset Status panel map directly to Circolare 177's cyber risk assessment obligation. The Convergence Alert fires when cyber signals converge with other threat vectors on an asset — before an incident occurs, offering broader coverage than Circolare 177 requires alone.

The window is open. The clock is running.

Founding Client Programme — 6 slots across three tiers. Rate locked for up to five years.

Request Access