Sources highlight several potential challenges in the implementation and enforcement of the NIS2 Directive.
1. NIS2 Directive: Legislative requirements
One of the main challenges consists of determining whether existing sector-specific EU legislation offers cybersecurity requirements and incident reporting obligations equivalent to those provided by the NIS2 Directive. This assessment requires an analysis of the effects of risk management measures and incident reporting obligations provided by sector-specific legislation, compared to Articles 21 and 23 of the NIS2 Directive.
- The Commission will provide guidelines to help Member States determine equivalence. However, interpreting these guidelines and applying them to various regulatory contexts could be complex. Sectoral provisions may, in fact, be more detailed than those of the NIS2 Directive. This granularity can make the equivalence assessment more complex, requiring careful analysis to ensure that the sectoral law achieves the same level of cybersecurity as provided by the directive.
- Ensuring that sectoral legislation allows for immediate access to incident notifications by competent CSIRTs (Computer Security Incident Response Teams), national authorities, and single points of contact can represent a technical and administrative challenge. The guidelines suggest that this could involve the direct transmission of notifications or access via a single access point. Implementing such mechanisms and ensuring their interoperability with the overall NIS2 framework could be complex.
2. NIS2 Directive: Identification
The NIS2 Directive significantly expands the scope of the previous directive by including new sectors and entities based on their size and risk profile. This expansion presents challenges in:
- Identifying all entities that fall under the directive. Member States must establish clear criteria to determine which entities meet the size threshold and identify smaller entities with a high risk profile. This process could be resource-intensive, requiring the collection of information on entities operating within national borders, including size, activities, and potential cyber risks. Sources suggest that Member States may use mechanisms such as registration to facilitate the identification of entities, but designing and implementing such mechanisms will be fundamental. For the Italian context, the article on ACN and the list of NIS2 subjects with a March 31st deadline offers an updated framework on registration procedures.
- Ensuring that entities are aware of their obligations under the directive. Sources emphasize the need to raise awareness among entities regarding the NIS2 Directive and their responsibilities. This will require effective communication and outreach efforts by both the Commission and the Member States.
- Coordinating with the Critical Entities Resilience (CER) Directive to ensure that entities identified as critical under the CER are also subject to NIS2 obligations. This requires clear communication and cooperation between the competent authorities responsible for the implementation of both directives.
3. Security measures
The NIS2 Directive requires covered entities to implement a set of cyber risk management measures. This presents several challenges for entities:
- Understanding and implementing the ten key elements of cyber risk management outlined in the directive. Entities must have a deep understanding of their cyber risks and develop appropriate policies and procedures to mitigate them. Sources indicate that the Commission will provide further guidance on these key elements, but entities will need to stay updated on this guidance and adapt their practices accordingly.
- Managing supply chain security and supplier relationships. Entities are required to manage cyber risks throughout the supply chain, a complex task that includes supplier due diligence, defining security requirements in contracts, and monitoring supplier security practices.
- Managing the costs of implementing cybersecurity measures. Implementing robust security measures can be expensive, especially for smaller entities. Member States may need to provide financial support or incentives to help entities cover such costs.
4. Incident reporting
The NIS2 Directive introduces a multi-stage incident reporting process, which aims to balance the need for rapid reporting with the need for detailed information. Entities must submit an early warning within 24 hours of becoming aware of a significant incident, followed by an incident notification within 72 hours and a final report within one month. This process presents challenges in:
- Establishing clear internal procedures to identify and report significant incidents. Entities must define what constitutes a significant incident, train staff on reporting procedures, and establish clear lines of communication.
- Meeting reporting deadlines. The 24-hour and 72-hour deadlines for early warnings and incident notifications could be difficult to meet for entities lacking well-developed incident response capabilities. Regarding the figure responsible to the CSIRT, it is useful to learn more about the obligation to designate the CSIRT contact person for NIS subjects.
- Providing complete and accurate information in incident reports. Sources indicate that the Commission will provide further guidance on the content of incident reports. However, entities will still need to accurately document incidents and provide all necessary information to the competent authorities.
5. Supervision and enforcement
The NIS2 Directive emphasizes stronger supervisory measures for national authorities and stricter enforcement requirements. This entails challenges in:
- Ensuring that national competent authorities have the necessary resources and expertise to effectively supervise and enforce the directive. This includes sufficient staff, technical expertise, and adequate financial resources.
- Implementing differentiated supervisory regimes for essential and important entities. This requires national authorities to develop different approaches and procedures for the supervision of each type of entity.
- Overcoming reluctance to apply sanctions. Sources note a general reluctance among Member States to apply sanctions for cybersecurity breaches. This must change to ensure that the NIS2 Directive has a deterrent effect.
- Ensuring that sanctions are applied consistently across Member States. The NIS2 Directive establishes a minimum list of administrative sanctions, but Member States have some flexibility in their implementation. This could lead to discrepancies in the application of sanctions between Member States, potentially creating unfair competitive conditions for entities operating in different jurisdictions. For organizations that want to address these challenges methodically, starting a structured NIS2 compliance path allows for mapping gaps, defining priorities, and meeting regulatory requirements in a sustainable way.
6. Collaboration and information sharing
The NIS2 Directive emphasizes the importance of collaboration and information sharing between Member States and EU institutions. This entails challenges in:
- Establishing effective mechanisms for sharing information on cyber threats, vulnerabilities, and incidents. This includes sharing information between Member States, between EU institutions, and between the public and private sectors.
- Overcoming language barriers and differences in national cybersecurity practices. The EU has 27 Member States, each with its own language, legal system, and cybersecurity culture. These differences can make it difficult to collaborate effectively on cybersecurity issues.
- Building trust between stakeholders. Effective collaboration requires trust between all parties involved, which can be difficult to build, especially in the context of cybersecurity, where sensitive information is often shared.
Frequently Asked Questions about the NIS2 Directive
- Who must verify if they fall under the scope of the NIS2 Directive?
- Any organization operating in one of the sectors covered by the directive โ whether essential or important โ must verify if it exceeds the established size thresholds or if it presents a risk profile that makes it subject to NIS2 obligations. In Italy, the ACN manages the identification and registration process for subjects.
- What happens if an organization does not meet incident reporting deadlines?
- Failure to report within the required timeframes โ early warning within 24 hours and notification within 72 hours โ exposes the organization to administrative sanctions. NIS2 provides for significant sanctions, with ceilings differentiated between essential and important subjects, and Member States are required to apply them effectively.
- Where is the best place to start to address NIS2 compliance?
- The most useful starting point is a gap assessment against the requirements of Articles 21 and 23: risk management measures, supply chain security, incident reporting procedures, and governance. From this analysis, a compliance plan with clear priorities and realistic timelines can be derived.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
