NIS2 Directive and cybersecurity in public procurement

Direttiva NIS2 Cyber Security negli Appalti Pubblici

The NIS2 Directive promotes the integration of cybersecurity considerations into public procurement practices, particularly for information and communication technology (ICT) products and services.

The directive recognizes the crucial role that public procurement plays in strengthening cybersecurity across the European Union. The main objective of the NIS2 is to raise the common level of security of networks and information systems, and public procurement is one of the tools through which this objective is achieved.

Although the NIS2 Directive encourages the inclusion of cybersecurity requirements, it does not prescribe specific methods for implementing these requirements in procurement processes by Member States. However, it suggests the following measures to guide Member States.

NIS2 Directive: Cybersecurity certification

Promote the use of ICT products and services that have obtained cybersecurity certifications within the European cybersecurity certification framework. This ensures that such products and services meet specific security standards.

Encryption

Encourage the mandatory use of encryption technologies in ICT products and services acquired by public entities. Encryption protects sensitive data and communications from unauthorized access, improving overall data protection.

Open-source products for cybersecurity

Encourage the use of open-source products for cybersecurity in public procurement. Open-source solutions can offer transparency, flexibility, and cost advantages, while allowing for community-driven security improvements.

Risks according to the NIS2 Directive

In addition to these specific measures, the NIS2 Directive emphasizes the importance of a risk-based approach to cybersecurity in public procurement. This means:

  • Identify risks: Public entities should conduct thorough risk assessments to identify potential cybersecurity threats and vulnerabilities associated with the ICT products and services they intend to acquire.
  • Specify requirements: Tender specifications should clearly outline cybersecurity requirements to ensure that potential suppliers understand and can meet the necessary security standards.
  • Evaluate suppliers: Public entities should evaluate suppliers based on their cybersecurity capabilities, including risk management, incident response procedures, and adherence to relevant security standards.
  • Monitoring and review: Cybersecurity measures in public procurement should be regularly monitored and reviewed to adapt to evolving threats and ensure continued effectiveness.

The directive aims to create a more secure digital environment by promoting the acquisition of ICT products and services with robust cybersecurity features. For organizations that need to structure or verify their compliance journey, the NIS2 compliance support offered by ISGroup covers both the assessment of implemented measures and the definition of necessary corrective actions.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In