Regulatory Convergence, Institutional Divergence: Comparing NIS2 Incident-Reporting Transparency in the Healthcare Sectors of Croatia and Italy
Tomislav Vazdar, Mario SpremićDirective (EU) 2022/2555 (NIS2) designated healthcare a sector of high criticality, with a transposition deadline of 17 October 2024. Only four of twenty-seven Member States met it: Croatia transposed eight months early and Italy one day before the deadline. Because the formal regulatory gap between them is small—and, on the primary instrument, favours Croatia—this paper asks not whether but how two Member States with near-identical transposition timelines diverge in the operational practice and transparency of healthcare-sector incident reporting. Drawing on neo-institutional theory and the economics of information security, it synthesises the literature and compares the two transposition instruments against the primary legal texts. Both reproduce the NIS2 notification timeline faithfully, so divergence cannot be attributed to differing statutory obligations. Public-reporting transparency is therefore operationalised as a measurable dependent variable: Italy’s Agenzia per la Cybersicurezza Nazionale (ACN), an autonomous agency since 2021, publishes healthcare-specific data, whereas Croatia’s National Cybersecurity Centre (NCSC-HR)—competent authority only since 2025—publishes only aggregate figures. The asymmetry is autonomy and mandate, not institutional age. A portable four-indicator transparency index is proposed and demonstrated in a two-coder pilot (κ_w = 0.80); an independent incident-composition cross-check is consistent with the asymmetry.