What is the NIS Cooperation Group?

Direttiva NIS2 Frequently Asked Questions

The NIS Cooperation Group is a body established by the NIS 2 Directive to support and facilitate strategic cooperation and information exchange among EU Member States regarding cybersecurity. Its role is central to achieving the cybersecurity objectives that the directive imposes on States and subject organizations.

🔴 NIS2 compliance: identify hidden risks and strengthen your security with a focused assessment by ISGroup specialists.

The group is composed of representatives from:

  • Member States
  • The European Commission
  • ENISA (European Union Agency for Cybersecurity)

Additionally, the European External Action Service participates as an observer, and the European Supervisory Authorities (ESAs) and competent authorities under Regulation (EU) 2022/2554 (regarding digital operational resilience for the financial sector) may also participate. The European Parliament and representatives of relevant stakeholders may be invited to participate in the group’s work when appropriate. The European Commission provides secretariat services to the group.

The NIS Cooperation Group has a wide range of responsibilities, including:

  • Providing guidance to competent authorities on the implementation of the NIS 2 Directive.
  • Offering guidelines on the development and implementation of policies for coordinated vulnerability disclosure.
  • Facilitating the exchange of best practices and information related to the implementation of the NIS 2 Directive, including cybersecurity threats, incidents, vulnerabilities, and awareness-raising initiatives.
  • Exchanging advice and collaborating with the Commission on new cybersecurity strategies and ensuring consistency between sector-specific cybersecurity requirements.
  • Providing input on draft delegated or implementing acts adopted under the NIS 2 Directive.
  • Exchanging best practices and information with relevant EU institutions, bodies, offices, and agencies.
  • Sharing views on the implementation of sector-specific EU legal acts that contain cybersecurity provisions.
  • Discussing and, where appropriate, drawing conclusions and recommendations from peer review reports (as described in Article 19 of the NIS 2 Directive).
  • Conducting coordinated risk assessments of critical supply chains for security.
  • Discussing cases of mutual assistance, including experiences and results of joint and cross-border supervisory actions.
  • Addressing, at the request of the concerned Member States, specific requests for mutual assistance.
  • Providing strategic guidance to the CSIRT network and EU-CyCLONe (European cyber crises liaison organisation network) on specific and emerging issues.
  • Sharing views on policy regarding actions taken following large-scale cybersecurity incidents and crises.
  • Facilitating the exchange of national officials to improve cybersecurity capabilities across the EU.
  • Organizing regular joint meetings with private sector stakeholders across the EU.
  • Discussing activities undertaken regarding cybersecurity exercises, including work done by ENISA.
  • Establishing the methodology and organizational aspects of peer reviews.
  • Preparing reports on experience gained at the strategic level and from peer reviews.
  • Periodically discussing and assessing the state of cyber threats or incidents.

The NIS Cooperation Group is required to submit reports on its experience to the Commission, the European Parliament, and the Council. Member States must ensure that their representatives in the group collaborate effectively, efficiently, and securely.

To guide its work, the NIS Cooperation Group establishes a biennial work program that outlines the actions it will take to achieve its objectives and tasks. It is also required to meet with the Critical Entities Resilience Group (established by the CER Directive) at least once a year to foster cooperation and information exchange. For organizations subject to the directive, understanding the functioning of this body is an integral part of a structured NIS2 compliance path.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In