NIS2 Directive: Requirements for ICT products and services

Direttiva NIS2: Requisiti per prodotti e servizi ICT

According to the NIS2 Directive, Member States have the power to require essential and important entities to use certified ICT products, services, and processes to demonstrate compliance with the specific cybersecurity risk management measures set out in Article 21. This requirement applies to ICT products, services, and processes developed internally by these entities or acquired from external suppliers. For organizations starting or consolidating their NIS2 compliance journey, understanding when and how the certification obligation applies is one of the fundamental operational steps.

Certification must take place within the framework of European cybersecurity certification schemes established in accordance with Article 49 of Regulation (EU) 2019/881.

The directive also encourages the use of qualified trust services by essential and important entities.

NIS2 Directive and ICT: When certification is required

According to the NIS2 Directive, the Commission may adopt delegated acts to specify the categories of essential and important entities required to use certified ICT products, services, and processes or to obtain certification under a European cybersecurity certification scheme. These delegated acts will be adopted if insufficient levels of cybersecurity are identified and will include an implementation period. Furthermore, procedures will be defined to ensure a harmonized approach among Member States, avoiding discrepancies in the application of measures.

Assessment and consultation before delegated acts

Before adopting delegated acts, the Commission will carry out an impact assessment and consult stakeholders as provided for in Article 56 of Regulation (EU) 2019/881. The consultation will serve to gather opinions from industry operators, cybersecurity experts, and national institutions, ensuring that the new provisions are effective and realistic.

Managing the lack of adequate certification schemes

In the event that adequate European cybersecurity certification schemes are not available, the Commission may request ENISA to develop a proposal for a new scheme pursuant to Article 48(2) of Regulation (EU) 2019/881. This request will be made in consultation with the Cooperation Group and the European Cybersecurity Certification Group. During this process, the specific needs of the entities involved and the effectiveness of existing solutions will be evaluated, ensuring a system that addresses emerging cybersecurity challenges. For a broader overview of the scope and objectives of the NIS2 Directive, it is useful to start from the general context before delving into individual technical obligations.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In