The NIS2 Directive recognizes that cybersecurity needs and risk profiles vary significantly across different sectors.
It therefore adopts a sectoral approach through several key mechanisms:
- Sector-Specific Scope: The scope of the directive is explicitly defined through a list of sectors and sub-sectors considered critical to the EU economy and society (Annexes I and II of the NIS2 Directive). This sectoral delimitation ensures that the obligations imposed by NIS2 are relevant to the specific risks and challenges faced by entities operating in those sectors.
- Sector-Adapted Security Requirements: Although NIS2 establishes a minimum level of cybersecurity risk management measures applicable to all entities concerned, it allows for sectoral customization of these requirements. Article 21, Paragraph 5, empowers the Commission to adopt implementing acts that specify technical and methodological requirements, including “sector-specific requirements,” for the implementation of these security measures. This flexibility acknowledges that some sectors may require more detailed or context-specific cybersecurity practices.
- Sector-Based Incident Reporting: NIS2 recognizes that the types of cybersecurity incidents considered “significant” and therefore reportable to national authorities may differ across sectors. While a general definition of “incident” is provided, Article 23, Paragraph 11, allows the Commission to adopt implementing acts to further define what constitutes a significant incident in particular sectors. This provision allows for a more targeted approach adapted to sectoral characteristics in incident reporting.
- Involvement of Sectoral Expertise: The Directive emphasizes the importance of involving industry experts in its implementation and oversight:
- NIS Cooperation Group: Article 14 establishes the NIS Cooperation Group, composed of representatives from the national cybersecurity authorities of the Member States. This group plays a crucial role in promoting strategic cooperation and information exchange among Member States on cybersecurity issues. Importantly, the group’s mandate includes considering the “specific characteristics of each sector” when developing its opinions, guidelines, and best practices.
- European Cyber Crisis Liaison Organisation Network (EU-CyCLONe): EU-CyCLONe, established under Article 16, supports the coordinated management of large-scale cybersecurity incidents and crises. To ensure that EU-CyCLONe’s response strategies are aligned with the unique needs of different sectors, its activities and information exchange may involve “sectoral or cross-sectoral communities” if necessary.
- Consultation with Stakeholders: The Directive provides for consultation with relevant stakeholders, including those representing specific sectors, in the development of implementing acts and guidelines. This ensures that sectoral perspectives are taken into account in the practical application of NIS2.
- Coordination with Sectoral Legislation: NIS2 is designed to operate in harmony with existing and future EU sectoral legislation related to cybersecurity. Article 4 clarifies the relationship between NIS2 and such legislation:
- Equivalent Obligations: If a sectoral legal act imposes cybersecurity risk management or incident reporting obligations on essential or important entities, and if those obligations are deemed at least equivalent to those provided for by NIS2, then the corresponding provisions of NIS2 do not apply to those entities. This ensures that entities are not subject to duplicate or conflicting requirements. However, if sectoral legislation does not cover all entities in a given sector that would otherwise fall under NIS2, the relevant provisions of NIS2 continue to apply to those entities not covered by the sectoral legislation.
- Harmonization and Cooperation: To facilitate proper interaction between NIS2 and sectoral legislation, the Commission provides guidelines clarifying the criteria for determining the equivalence of obligations. This helps ensure consistent implementation and minimizes the regulatory burden for businesses. The NIS Cooperation Group plays a role in promoting cooperation and information exchange between national authorities responsible for NIS2 and those overseeing sectoral cybersecurity rules.
Examples of Sectoral Considerations:
The sources and our conversation highlight how NIS2 addresses the specific needs of sectors through various examples:
- Financial Sector: Recognizing the robust cybersecurity framework already existing in the financial sector under the Digital Operational Resilience Act (DORA), NIS2 exempts entities already subject to DORA from NIS2’s cybersecurity risk management and incident reporting obligations. However, considering the interconnected nature of cybersecurity, NIS2 maintains channels for information exchange and cooperation between financial authorities and those responsible for implementing NIS2. This ensures that the financial sector’s expertise contributes to broader cybersecurity efforts and vice versa.
- Public Administration: NIS2 recognizes the unique role and structure of public administration entities. It provides a specific definition for public bodies and grants Member States some flexibility regarding their inclusion, particularly at the local level. The Directive also provides exemptions for public bodies engaged in sensitive areas such as national security, while emphasizing the importance of their inclusion to strengthen overall cybersecurity in the EU. This multifaceted approach recognizes the peculiarities of the public sector while aiming for comprehensive cybersecurity coverage.
- Healthcare Sector: NIS2 explicitly includes entities involved in the research and development of medicinal products, including vaccines, within its scope. This inclusion reflects the growing importance of cybersecurity in the healthcare sector, especially in light of the increasing reliance on digital health solutions and the potential impact of cyberattacks on patient safety.
Key Points:
- The NIS2 Directive adopts a sectoral approach to cybersecurity, recognizing the diversity of risks and needs across various sectors.
- It defines its scope by sector, allows for tailored security and incident reporting requirements, encourages the involvement of sectoral expertise, and aims for harmonization with sectoral legislation.
- This targeted approach aims to improve the effectiveness of the Directive, ensuring that cybersecurity measures are proportionate to risks and adapted to the specific circumstances of each sector. For organizations that need to assess their scope of applicability and start a structured NIS2 compliance path, it is useful to start with an analysis of the measures already implemented against the obligations provided by the Directive.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
