How does this initiative interact with other EU policies?

Direttiva NIS2 Frequently Asked Questions

The NIS2 Directive does not exist in isolation. It is part of a broader framework of EU policies aimed at strengthening the overall security and resilience of the Union. Understanding how it intertwines with other regulations is the first step in building a NIS2 Directive compliance path that takes into account the entire regulatory context in which the organization operates. To delve deeper into the general framework, you can also read about what the main objective of the NIS2 Directive is.

🔴 NIS2 compliance: identify hidden risks and strengthen your security with a focused assessment by ISGroup specialists.

Here is how NIS2 interacts with some of these policies:

NIS2 and the CER Directive: Ensuring Holistic Resilience for Critical Entities

The NIS2 Directive and the Critical Entities Resilience (CER) Directive are closely interconnected, with largely aligned scopes of application. This alignment aims to provide a comprehensive approach to both physical and cyber resilience for entities considered critical in the EU.

  • Shared Scope for Critical Entities: Entities identified as “critical” under the CER Directive automatically fall under the jurisdiction of NIS2, ensuring they adhere to cybersecurity obligations.
  • Cooperation and Information Exchange between Authorities: National competent authorities designated under both directives are required to cooperate and exchange relevant information regularly. This includes sharing data on cyber threats and incidents, as well as non-cyber risks and incidents, facilitating a holistic understanding of threats.
  • Regular Meetings between Cooperation Groups: To improve strategic coordination, the NIS Cooperation Group and the Critical Entities Resilience Group, established under the CER Directive, must hold regular meetings at least once a year. This fosters dialogue and collaboration in addressing resilience-related challenges.

NIS2 and DORA: Optimizing Cybersecurity in the Financial Sector

Although NIS2 includes credit institutions, trading venue operators, and central counterparties, the Digital Operational Resilience Act (DORA) for the financial sector prevails for these entities regarding cybersecurity risk management and reporting obligations.

  • DORA as the Primary Regulation for Financial Entities: For financial entities covered by DORA, the provisions related to cybersecurity risk management and incident reporting under DORA take precedence over those of NIS2.
  • Continuous Information Exchange and Collaboration:
  • Participation in the NIS Cooperation Group: The European Supervisory Authorities (ESAs) for the financial sector and national competent authorities under DORA may participate in NIS Cooperation Group discussions, ensuring that the financial sector’s perspective is considered in broader cybersecurity strategies.
  • Information Sharing with NIS2 Entities: DORA competent authorities can consult and share relevant information with Single Points of Contact (SPOCs) and CSIRTs established under NIS2, facilitating cross-sector information flow and improving awareness and incident response. Regarding the operational role of CSIRTs in the NIS2 context, it is useful to also delve into the obligation to designate a CSIRT contact person for NIS subjects.
  • Reporting of Major ICT Incidents: Authorities operating under NIS2 must receive details regarding major cyber incidents from their DORA counterparts, ensuring visibility and timely responses to incidents with potential impact across multiple sectors.
  • Continued Inclusion in National Strategies: Despite DORA’s primary role, the importance of maintaining the inclusion of the financial sector in national cybersecurity strategies is emphasized. Furthermore, national CSIRTs may cover the financial sector in their activities, further strengthening the cybersecurity posture.

NIS2 and Other Sector-Specific Regulations

NIS2 recognizes the existence of specific EU sector-specific regulations regarding cybersecurity. Where these regulations offer an equivalent or higher level of security compared to NIS2, they prevail. This principle is evident in the interaction with DORA but also extends to other sectors. However, the directive does not provide specific examples of other sector-specific regulations beyond DORA where this applies.

Key Points

  • Interaction and Complementarity: NIS2 is not a standalone policy; it interacts with and complements other EU regulations, particularly those related to critical entities and the financial sector.
  • Essential Collaboration: Although sector-specific laws like DORA may take precedence in their respective areas, collaboration and information exchange between these sectors and the broader NIS2 framework remain crucial for maintaining a strong and unified cybersecurity posture across the EU.
  • Common Goal of Resilience: The main objective is to ensure a high and harmonized level of cybersecurity resilience in the EU, taking into account the unique characteristics and specific needs of different sectors.

NIS2 plays a fundamental role in strengthening cybersecurity in the EU, interacting closely with other policies and regulations to create an integrated and consistent approach to the resilience of critical infrastructure and essential services. To consult the full text, the official NIS2 Directive document is available.

Frequently Asked Questions

  • If my organization is already subject to DORA, do I still need to worry about NIS2?
  • In general, for financial entities covered by DORA, the latter’s provisions prevail over those of NIS2 regarding ICT risk management and incident reporting. However, NIS2 continues to apply to aspects not covered by DORA, and the competent authorities of the two regimes are required to coordinate. It is advisable to verify on a case-by-case basis which obligations overlap and which remain distinct.
  • What does it mean in practice to be identified as a “critical entity” under the CER Directive?
  • Entities classified as critical by the CER Directive also automatically fall within the scope of NIS2, meaning they must comply with both the physical resilience obligations provided by the CER and the cybersecurity obligations imposed by the NIS2. The national competent authorities of the two directives are required to cooperate and exchange information on risks and incidents.
  • How do national authorities concretely cooperate across different regulatory regimes?
  • NIS2 provides structured cooperation mechanisms: the NIS Cooperation Group meets at least once a year with the Critical Entities Resilience (CER) Group, while DORA authorities can participate in NIS Cooperation Group discussions. National CSIRTs and Single Points of Contact (SPOCs) serve as operational channels for exchanging information on incidents and threats between different sectors.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In