NIS2
NIS2 is the EU's second-generation network and information security directive, widening the scope of regulated 'essential' and 'important' entities across eighteen sectors, imposing baseline risk-management measures, holding management personally accountable, and putting incident reporting on a strict clock — an early warning within 24 hours, an incident notification within 72, and a final report within a month. It regulates how organizations run security, not how they expose it, but its reporting clock is only survivable with the operational instrumentation an API contract can carry.
Countries
Where this binds. Each links to the providers apis.io has catalogued there.
Industries
Each links to that industry as a scored cohort — so the question "how ready is this sector for the regime that governs it?" becomes one you can actually look at.