Yes, public administration entities are covered by the NIS2 Directive, but with some specificities. To understand the main objective of the NIS2 Directive and its scope, it is useful to start by analyzing the provisions that directly concern the public sector.
Here is a detailed analysis:
- General Inclusion: Article 2 of the NIS2 Directive explicitly establishes that the directive applies to both public and private entities operating in various sectors. This means that, in general terms, public administration entities fall within the scope of NIS2.
- Specific Provisions for Public Administration: The sources highlight some provisions within NIS2 that directly concern public administration entities:
- Definition: Article 25, point 35, defines a “public administration entity” as an entity recognized as such in a Member State under national law, excluding the judiciary, parliaments, and central banks. To qualify as such, the entity must meet specific criteria, such as being established for non-commercial purposes, possessing legal personality, receiving funding predominantly from public sources, and having the power to adopt administrative decisions that affect certain rights related to the internal market.
- Essential Entities: Article 2, Paragraph 2(f), clarifies that public administration entities can be designated as “essential entities” under NIS2. Two categories are specified:
- (i) Entities belonging to the central administration, as defined by the national legislation of each Member State.
- (ii) Entities at the regional level, as defined by the national legislation of each Member State, provided that a risk assessment determines that disruptions to their services could have a significant impact on critical societal or economic activities.
- Local Level and Educational Institutions: Article 2, Paragraph 5, grants Member States the discretion to extend the application of NIS2 to:
- (a) Public administration entities at the local level.
- (b) Educational institutions, particularly those engaged in critical research activities.
- Exemptions: While generally included, some exceptions apply to public administration entities:
- Article 2, Paragraph 7, states that the directive does not apply to public administration entities operating in areas such as:
- National security;
- Public security;
- Defense;
- Law enforcement (including the prevention, investigation, detection, and prosecution of criminal offenses).
- Article 2, Paragraph 8, allows Member States to exempt specific entities engaged in national security, public security, defense, or law enforcement, or providing services to such entities, from certain obligations under Articles 21 (cybersecurity risk management measures) and 23 (incident reporting obligations). Exemptions may also apply to Articles 3 (national cybersecurity strategies and designation of competent authorities) and 27 (registry of entities) in cases where an entity’s activities or services fall exclusively within the specified exempted categories.
- However, Article 2, Paragraph 9, clarifies that Paragraphs 7 and 8, regarding exemptions, do not apply when an entity acts as a trust service provider. This implies that public administration entities acting as trust service providers must comply with NIS2, even if their activities relate to national security or other exempted areas.
- Article 2, Paragraph 7, states that the directive does not apply to public administration entities operating in areas such as:
- Supervision and Enforcement: The sources address aspects related to the supervision and enforcement of NIS2 regarding public administration entities:
- Article 31, Paragraph 5, clarifies that the enforcement measures provided for in Article 32, Paragraph 5 (regarding violations of Article 21 by entities providing domain name registration services) are not applicable to public administration entities. This suggests that while exemptions from specific obligations are possible, other provisions of NIS2, including those related to supervision and enforcement, generally apply.
- Article 34, Paragraph 7, grants Member States the flexibility to establish rules determining the extent of administrative fines to be imposed on public administration entities for NIS2 violations. This indicates recognition of the specific nature of public administration and the need for tailored enforcement mechanisms.
Key Points:
- The NIS2 Directive covers a broad spectrum of public administration entities at various levels of governance.
- The directive recognizes the unique role of public administration by providing specific provisions regarding definitions, exemptions, and enforcement.
- Although there are exemptions for entities engaged in sensitive sectors such as national security and defense, the general intent is to include public administration entities within the scope of NIS2 to strengthen cybersecurity across the EU. For entities falling within the perimeter, starting a structured NIS2 Directive compliance path is the concrete step to meet the required obligations. To verify if your organization is already included in the list of NIS2 subjects managed by ACN and the related deadlines, it is useful to consult the operational guidelines published by the competent national authority. The full text of the regulation is available in the official NIS2 Directive document.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
