The NIS2 Directive relies heavily on national competent authorities to implement and enforce its provisions, assigning them a series of responsibilities that cover various phases of the directive’s lifecycle. For organizations falling within the scope, understanding how this governance system works is the first step toward establishing a structured NIS2 compliance path.
1. Creation of the NIS2 Ecosystem
- Development of National Cybersecurity Strategies: Each Member State must adopt a comprehensive national cybersecurity strategy, defining strategic priorities, objectives, and governance frameworks for cybersecurity. These strategies must include mechanisms for cooperation and coordination among various relevant stakeholders, including competent authorities, Single Points of Contact (SPOCs), and Computer Security Incident Response Teams (CSIRT), as well as coordination with authorities responsible for Union sectoral legal acts.
- Designation of Key Entities: Member States play a fundamental role in identifying and designating entities that fall within the scope of NIS2. This includes:
- Essential and Important Entities: Determining which entities are classified as “essential” or “important” based on their potential impact on essential services and societal functions.
- Compilation of Entity Lists: Creating and maintaining lists of essential and important entities, as well as those providing domain name registration services. These lists are crucial for ensuring transparency, oversight, and ensuring that entities are aware of their obligations under NIS2. In Italy, ACN manages the list of NIS2 subjects and the related registration deadlines.
- Flexibility in Entity Designation: Member States have a certain level of discretion in designating smaller entities with high-risk profiles that may not meet general size thresholds but still merit inclusion in NIS2.
- Creation of National Structures: In addition to designating entities, Member States are responsible for creating essential national cybersecurity structures:
- Competent Authorities: Designating or establishing one or more competent authorities responsible for cybersecurity, including those tasked with overseeing the implementation of NIS2 and carrying out supervisory and enforcement actions.
- Single Points of Contact (SPOCs): Designating or establishing SPOCs as central contact points for cross-border cooperation with other Member States and for cross-sectoral cooperation within the Member State.
- Computer Security Incident Response Teams (CSIRTs): Designating or establishing CSIRTs to manage cybersecurity incidents and crises, cooperate with other CSIRTs, and provide support to entities within their jurisdiction. For NIS subjects, the directive also provides for a specific obligation to designate a CSIRT contact person.
2. Supervision and Enforcement
- Supervisory Powers: National competent authorities are equipped with a range of supervisory powers to ensure that entities comply with their obligations under NIS2. These powers include:
- Regular and Targeted Audits: Conducting audits to assess the adequacy and implementation of cybersecurity risk management measures.
- On-site and Off-site Checks: Carrying out checks, both on-site and remotely, to verify compliance.
- Requesting Information: Requesting information from entities regarding their cybersecurity practices, risk management policies, and incident response procedures.
- Access to Documents and Evidence: Obtaining access to relevant documents and evidence to verify the entity’s compliance with NIS2.
- Enforcement Measures: NIS2 provides competent authorities with a range of enforcement measures to address non-compliance:
- Binding Instructions: Issuing binding instructions to entities to correct identified deficiencies and ensure compliance.
- Security Audit Recommendations: Ordering entities to implement recommendations resulting from security audits.
- Alignment with NIS2 Requirements: Compelling entities to comply with the security measures required by NIS2.
- Administrative Sanctions: Imposing administrative fines for violations of cybersecurity risk management and incident reporting obligations. The directive establishes minimum thresholds for such sanctions, distinguishing between essential and important entities.
- Supplementary Measures: In cases of persistent non-compliance, competent authorities may impose additional measures, such as the temporary suspension of certificates or authorizations, or requiring the suspension of members of the company’s management.
- Factors Considered for Enforcement: When determining appropriate enforcement actions, competent authorities must consider the specific circumstances of each case. Relevant factors include the severity and duration of the violation, the intent behind the violation, the entity’s level of cooperation, and any previous history of compliance.
3. Facilitating Information Sharing and Cooperation
- Promoting Information Sharing Agreements: Member States must encourage information sharing among entities, including those that may not fall directly under NIS2. This implies facilitating the creation of information-sharing agreements and providing guidance on operational aspects.
- Support for Coordinated Vulnerability Disclosure: National authorities play a role in supporting coordinated vulnerability disclosure processes, facilitating communication between entities that discover vulnerabilities and the affected vendors or service providers.
- Sharing Information with Competent Authorities: Competent authorities must share relevant information, such as details of significant cybersecurity incidents, with other national authorities responsible for the protection of critical infrastructure (Directive (EU) 2022/2557) and the financial sector (Regulation (EU) 2022/2554). This exchange of information is essential to ensure a coordinated and comprehensive approach to cybersecurity across different sectors.
In summary, national competent authorities play a central role in translating the principles of NIS2 into concrete actions. They are responsible for creating the necessary national frameworks, overseeing the implementation of the directive’s provisions, taking enforcement measures when necessary, and promoting a culture of cybersecurity collaboration within and between Member States.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
