The sources do not contain information on the specific requirements a company must meet to be considered a “critical entity” under the EU Cybersecurity Directive. However, the sources state that entities identified as critical are defined in Directive (EU) 2022/2557. To learn more about who falls within the scope, it is also useful to consult the list of NIS2 entities published by ACN.
The sources also list several requirements for “essential and important entities,” including:
- Adopt technical, operational, and organizational measures to manage risks to the security of network and information systems.
- Report any significant incident without undue delay to their Computer Security Incident Response Team (CSIRT) or the competent national authority.
- Use certified ICT products, services, and processes that have been certified under European cybersecurity certification schemes.
- Cooperate with competent authorities in the event of an investigation or incident.
- Designate or establish a CSIRT.
- Adopt a national cybersecurity strategy.
- Designate or establish one or more competent authorities responsible for managing large-scale cybersecurity incidents and crises.
The sources explain that, although the NIS2 directive covers a wide range of sectors and entities, some entities, such as those in the financial sector, may be subject to other EU regulations in addition to or instead of the NIS2 directive. For example, financial entities are covered by Regulation (EU) 2022/2554, which contains similar requirements regarding cybersecurity risk management and incident reporting as the NIS2 directive. However, the sources specify that financial entities are still subject to the articles of the NIS2 directive concerning national cybersecurity strategies, national cybersecurity incident and crisis response plans, and the European Cyber Crises Liaison Organisation Network (EU-CyCLONe). For organizations that need to verify their position regarding these obligations, the NIS2 directive compliance path offered by ISGroup can be a concrete starting point.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
