What are the obligations imposed on Member States regarding the development and assessment of national cybersecurity strategies?

Direttiva NIS2 Frequently Asked Questions

The NIS2 Directive imposes specific obligations on Member States regarding the creation, implementation, and periodic review of national cybersecurity strategies. These strategies provide a high-level framework to improve cybersecurity posture and resilience at the national level.

🔴 NIS2 compliance: identify hidden risks and strengthen your security with a focused assessment by ISGroup specialists.

Here is an overview of the main obligations:

  • Adoption of a National Cybersecurity Strategy: Each Member State is required to establish a comprehensive national cybersecurity strategy. This strategy should outline the country’s strategic cybersecurity objectives, the resources allocated to achieve those objectives, and the strategic and regulatory measures in place to achieve and maintain a high level of cybersecurity.
  • Content of the Strategy: The NIS2 Directive provides specific details on the elements that should be included in every national cybersecurity strategy. These include:
  • Objectives and Priorities: Clear definition of cybersecurity objectives and priorities, with particular attention to the sectors listed in Annexes I and II of the directive, which include a wide range of critical sectors such as energy, transport, health, and digital infrastructure.
  • Governance Framework: A well-defined governance structure to achieve the established objectives and priorities. This framework should clarify the roles and responsibilities of stakeholders involved in cybersecurity at the national level, including competent authorities, Computer Security Incident Response Teams (CSIRT), and single points of contact (SPOC). It should also outline cooperation and coordination mechanisms between these entities.
  • Risk Assessment and Asset Identification: A mechanism to identify and assess cybersecurity risks within the Member State, along with an assessment of the resources available to address those risks. This element ensures a risk-based approach to resource allocation and priority setting.
  • Incident Preparedness and Response: A plan outlining measures to ensure preparedness, response, and recovery from cybersecurity incidents, including collaboration between the public and private sectors. This emphasizes the importance of a coordinated approach to incident response and recovery.
  • Stakeholder Identification: A list of the various authorities and stakeholders involved in the implementation of the national cybersecurity strategy, promoting transparency and accountability.
  • Coordination Framework: A strategic framework to improve coordination between competent authorities responsible for cybersecurity under the NIS2 Directive and those operating under Directive (EU) 2022/2557. This framework aims to optimize information sharing and collaboration on cyber and non-cyber risks, threats, and incidents, as well as joint supervisory tasks when necessary.
  • Public Awareness: A plan, including necessary measures, to raise general public awareness about cybersecurity. This element emphasizes the importance of educating citizens on cyber risks and promoting safe online practices.
  • Strategic Measures: In addition to the main elements, the NIS2 Directive encourages Member States to consider specific strategic measures in their strategies, such as:
    • Cybersecurity in the ICT supply chain
    • Cybersecurity requirements in public procurement of ICT products and services
    • Vulnerability management, including coordinated vulnerability disclosure
    • Support for a secure and open Internet
    • Promotion of advanced cybersecurity technologies
    • Active cyber defense
  • Notification to the Commission: Member States are required to notify the European Commission of their adopted national cybersecurity strategies within three months of their adoption. This notification allows the Commission to monitor implementation and assess the overall alignment of national strategies with the objectives of the NIS2 Directive. For organizations falling within the scope of the directive, understanding these obligations is the first step toward a structured NIS2 compliance path. On the Italian front, the ACN manages the registration of obligated entities: everything you need to know about the NIS2 list and ACN deadlines.
  • Periodic Review and Updates: The NIS2 Directive requires Member States to regularly evaluate and update their national cybersecurity strategies.
  • Frequency: This review should take place periodically, at least once every five years, and be based on a set of key performance indicators (KPIs) to assess the effectiveness of the strategies.
  • Support from ENISA: Recognizing the complexity in developing and updating these strategies, the NIS2 Directive highlights the support available to Member States from ENISA, the European Union Agency for Cybersecurity. Upon request, ENISA can assist Member States in drafting, updating, or evaluating their strategies and developing relevant KPIs, ensuring alignment with the Directive’s requirements.

By establishing these clear obligations, the NIS2 Directive aims to ensure that all Member States have robust and up-to-date national cybersecurity strategies in place. These strategies, developed and reviewed in line with a common set of principles and objectives, play a crucial role in promoting a higher level of cybersecurity preparedness and resilience across the European Union. To delve deeper into the regulatory framework, the text and main objective of the NIS2 Directive are available.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In