Comparing Global CIIP Frameworks: What Each One Assumes About You
Earlier in this series
Critical information infrastructure protection — CIIP — is the part of cyber governance that deals with the systems a country cannot function without: power, payments, telecoms, water, health.
Three international instruments dominate the conversation: the OECD's 2019 Recommendation on the digital security of critical activities, the European Union's NIS2 Directive, and the African Union's Malabo Convention. They are usually compared by their text. I want to compare them by their assumptions — what each one takes for granted about the state adopting it.
This continues an argument I made in Minimum Viable Cyber Governance: frameworks do not fail because their text is wrong. They fail because they assume machinery the adopting state does not have. So let us read each instrument as a job description for the state, not just a rulebook for operators.
The OECD Recommendation: trust the market, steer with risk
The OECD's 2019 Recommendation reframed the field. Instead of protecting infrastructure — the pipes and servers — it protects critical activities: the economic and social functions the infrastructure serves. Operators are expected to manage digital security risk the way they manage any other enterprise risk, proportionately, with government setting expectations rather than prescriptions.
It is elegant, and it is non-binding. That is not an accident. The OECD writes for its members, and the approach only works given what those members already have.
What it assumes: a mature market economy where critical services are run by capable private operators; regulators who can hold a risk conversation with those operators as near-equals; enough public-private trust that guidance, dialogue, and reputational pressure actually move behavior; and boards that respond to risk framing because insurers, auditors, and investors are watching.
Take away those conditions and the Recommendation has nothing to push against. "Manage your risk proportionately" is empty advice to a state-owned utility with no security staff, no regulator asking questions, and no market watching. The OECD text is the lightest instrument of the three precisely because it presumes the heaviest institutional background.
EU NIS2: obligations with teeth, machinery included — and required
NIS2, adopted in 2022, is the opposite temperament. It is binding law. It names sectors — energy, transport, banking, health, digital infrastructure, public administration, and more — and sorts entities into categories with registration duties, security measures, management accountability, incident-reporting deadlines measured in hours, and penalties that echo the GDPR playbook, including personal responsibility for management bodies.
What it assumes is easy to miss because for EU members it is ambient: a legal system that transposes directives into national law on schedule; a funded supervisory authority per sector or per state, with inspectors who can audit and sanction; a national CSIRT wired into the EU's cooperation structures — the CSIRTs Network, the Cooperation Group, ENISA behind them; courts where a fined operator can appeal, which is what makes fines legitimate rather than arbitrary; and thousands of mid-sized companies that can absorb real compliance costs without folding.
NIS2 is, in effect, the top floor of a building. The EU spent decades constructing the floors underneath — administrative capacity, legal harmonization, the earlier NIS Directive as a rehearsal. States outside that building sometimes copy the NIS2 text into national law because it is prestigious and available. What they get is what I have called paper convergence: the obligations exist, the supervision does not, and operators learn quickly that the law is decorative.
The Malabo Convention: build the floor first
The African Union's Malabo Convention, opened for signature in 2014, is the broadest of the three. It covers electronic transactions, personal data protection, and cybercrime alongside cybersecurity proper. Where the OECD assumes institutions and NIS2 mandates specific ones, Malabo asks member states to create the basics: adopt a national cyber strategy, establish legal frameworks, criminalize core offenses, set up data-protection authorities.
Its assumptions run in the opposite direction. It assumes less — and that is the point. It is written for states where the foundational layer may not exist yet, and its content is largely instructions for building that layer.
Its weakness is the mirror image. Because it demands ratification-then-construction rather than compliance-with-existing-machinery, progress has been slow; the convention took roughly a decade to gather enough ratifications to enter into force, as reported, and implementation across signatories remains uneven. There is no ENISA-equivalent with comparable resources, no penalty regime, and enforcement rests on peer pressure within the AU. Malabo tells you what to build but brings limited scaffolding.
Reading the three side by side
Line them up and the pattern is clean.
The OECD Recommendation assumes the most and demands the least: it works where governance is already strong and merely needs orientation. NIS2 assumes a lot and demands a lot: dense obligations that only bite where supervision, courts, and cooperation networks already run. Malabo assumes the least and demands construction: it is a starter kit, with a starter kit's limits.
None of the three is "best." Each is the right tool for the state it was written for and a poor fit elsewhere. The practical failure I see is always a mismatch: a foundation-stage state adopting top-floor law, or a mature state treating a starter framework as sufficient.
If I were advising a government choosing its reference point, the diagnostic would not start with the frameworks at all. It would start with the four-item checklist from the minimum-viable piece — accountable agency, readable strategy, recurring budget, narrow legal basis. States still building those belong in Malabo's world regardless of geography. States with functioning supervision can borrow NIS2's structure selectively. States with genuinely mature operator ecosystems can afford the OECD's light touch.
The states none of them address
There is a fourth category the frameworks share an assumption about, silently: that the adopting state is inside the international system — able to join cooperation networks, buy from global vendors, and sit in the rooms where these instruments are drafted.
Some states cannot. Sanctioned, isolated, or excluded states face the CIIP problem with none of the three instruments really written for them, and their answers look very different. That thread — where deliberate self-reliance ends and forced disconnection begins — is where this series goes next.
A Non-Technical Guide to Reading a Security Incident Report →