The NIS2 directive, while not explicitly outlining a structured approach to the ICT system lifecycle from creation to decommissioning, provides guidelines and requirements that cover the main phases related to security, from acquisition and development to ongoing management and disposal.
Acquisition and development
- Supply chain security: The directive emphasizes the importance of considering cybersecurity risks within supply chains.
- Article 21, Paragraph 2(d): Requires essential and important entities to implement risk management measures that include “supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers.”
- Article 21, Paragraph 3: Specifies that, when assessing the adequacy of supply chain security measures, entities must take into account “the vulnerabilities specific to each supplier or direct service provider and the overall quality of the products and cybersecurity practices of their suppliers and service providers, including their secure development procedures.”
- Article 22: Allows for coordinated risk assessments of critical supply chains at the EU level, potentially influencing the selection and management of ICT suppliers.
- Secure development practices: The directive highlights the importance of considering security during the development of ICT systems, including those developed in-house.
- Article 21, Paragraph 2(e): Lists “security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure,” as a key element of the required cybersecurity risk management measures.
- Article 21, Paragraph 3: As indicated above, this paragraph emphasizes the importance of considering the “secure development procedures” of suppliers when assessing supply chain risks.
- Use of certified products and services: Although not mandatory in all cases, the NIS2 directive encourages and, in some situations, may require the use of certified ICT products, services, and processes.
- Article 24, Paragraph 1: Establishes that Member States “may require” essential and important entities to use ICT products, services, and processes certified under European cybersecurity certification schemes established by Regulation (EU) 2019/881.
- Article 24, Paragraph 2: Empowers the Commission to adopt delegated acts to specify which categories of essential and important entities “are required” to use certified solutions or obtain certification.
Ongoing management
- Cybersecurity risk management: Article 21 constitutes the cornerstone of the NIS2 directive’s approach to ongoing ICT security management, imposing a risk-based approach. For organizations that need to structure or verify their posture regarding these obligations, the NIS2 directive compliance path offers operational support from gap analysis to the implementation of the required measures.
- Article 21, Paragraph 1: Requires essential and important entities to implement “appropriate and proportionate technical, operational and organizational measures to manage the risks posed to the security of network and information systems which those entities use in their operations or for the provision of their services, in order to prevent or minimize the impact of incidents on recipients of their services and on other services.”
- Article 21, Paragraph 2: Provides a detailed list of 10 key elements that these measures must include. These elements cover various aspects of the ICT system lifecycle, such as risk analysis, incident management, business continuity, supply chain security, vulnerability management, use of cryptography, human resources security, access control, and asset management.
- Incident management: The NIS2 directive establishes a comprehensive process for incident management.
- Article 23: Requires essential and important entities to report significant incidents to their CSIRT or competent national authority.
- Vulnerability management and disclosure: The directive recognizes the importance of proactively addressing vulnerabilities.
- Article 12: Establishes a framework for coordinated vulnerability disclosure, encouraging the reporting of vulnerabilities to manufacturers and service providers and facilitating responsible disclosure practices.
- Article 12, Paragraph 2: Provides for the creation of an EU vulnerability database managed by ENISA. This database serves as a central repository for publicly known vulnerabilities in ICT products and services.
- Training and awareness: The NIS2 directive recognizes the importance of the human element in cybersecurity.
- Article 20: Requires Member States to ensure that members of the management bodies of essential and important entities receive training to improve their understanding of cybersecurity risks and management practices. The directive also encourages similar training for employees.
Disposal
The NIS2 directive does not explicitly address the secure disposal of ICT systems. However, some provisions concern data security and confidentiality, aspects that should be considered during decommissioning:
- Data protection considerations: Although not directly covered in NIS2, the disposal of ICT systems must comply with relevant data protection regulations, such as the GDPR. This includes ensuring the secure erasure or destruction of sensitive data.
- Confidentiality requirements: Article 23, paragraph 7, allows for the public disclosure of incidents, but emphasizes that this must be done “in consultation with the entity concerned” and with consideration for “the confidentiality of the information provided.” While referring to incident reporting, this principle of confidentiality should extend to data and information present on ICT systems during disposal.
How to apply NIS2 requirements throughout the ICT lifecycle
Although it is not the main focus of the directive, NIS2 addresses key aspects of ICT system security throughout the entire lifecycle. The directive emphasizes:
- Secure acquisition and development practices.
- Ongoing risk management, incident management, and vulnerability management.
- The importance of data protection and confidentiality, even during disposal.
Organizations should interpret and implement the directive’s requirements by considering the entire ICT system lifecycle. To learn more about what the main objective of the NIS2 directive is and how it translates into concrete obligations, it is useful to start from the general framework before diving into the technical details for each individual phase.
Frequently asked questions
- Does NIS2 require following a specific procedure for the disposal of ICT systems?
- No, the NIS2 directive does not explicitly regulate disposal. However, the provisions on information confidentiality and risk management indirectly require treating decommissioning with the same attention reserved for other phases of the lifecycle. The GDPR remains the primary reference for secure data erasure.
- Is ICT product certification mandatory for all NIS2 subjects?
- Not in a generalized way. Article 24 provides that Member States may require the use of products certified under European cybersecurity certification schemes, and that the Commission may make certification mandatory for specific categories of entities. Until such delegated acts are adopted, certification remains recommended but not universally imposed.
- How is the security of ICT suppliers assessed under Article 21?
- Article 21, paragraph 3, requires considering the specific vulnerabilities of each supplier, the overall quality of their cybersecurity practices, and the secure development procedures adopted. In practice, this translates into a supply chain risk assessment that should be documented and updated periodically.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
