The Cooperation Group is established by the NIS2 Directive to support and facilitate strategic cooperation and information sharing between Member States in the field of cybersecurity.
The main objective is to build trust and improve cybersecurity capabilities and policies across the EU. Understanding how this body works is useful for organizations evaluating their NIS2 Directive compliance journey: the strategic guidance produced by the Group directly influences the measures that Member States require from essential and important entities.
Composition:
- Representatives of each Member State.
- Representatives of the European Commission.
- Representatives of ENISA (European Union Agency for Cybersecurity).
- The European External Action Service (EEAS) participates as an observer.
- European Supervisory Authorities (ESAs) and competent authorities under the Digital Operational Resilience Act (DORA) may also participate.
NIS2: Functions
The Cooperation Group has a broad mandate that includes strategic guidance, policy development, information exchange, and capacity building. Below are its main functions:
Strategic guidance and policy development
- Provides guidance to competent authorities on the implementation of the NIS2 Directive.
- Offers guidance on the development and implementation of policies for coordinated vulnerability disclosure.
- Collaborates with the Commission on new cybersecurity initiatives and on the alignment of sectoral cybersecurity regulations.
- Provides input to the Commission on proposed delegated or implementing acts under the NIS2 Directive.
Information exchange and cooperation
- Facilitates the exchange of best practices and information on the implementation of the NIS2 Directive. This includes information on cyber threats, incidents, vulnerabilities, near-misses, awareness-raising initiatives, training activities, exercises, capacity building, standards and technical specifications, as well as the identification of essential and important entities.
- Shares best practices and information with EU institutions, bodies, offices, and agencies.
- Exchanges views on the implementation of EU sectoral legal acts with cybersecurity provisions.
- Discusses peer review reports and develops conclusions and recommendations.
- Periodically assesses the progress of cyber threats or incidents, such as ransomware.
- Holds regular meetings with private sector stakeholders to discuss the Group’s activities and gather input on emerging strategic challenges.
NIS2: Cyber crisis management
- Provides strategic guidance to the CSIRTs network (Computer Security Incident Response Teams) and EU-CyCLONe on specific emerging issues.
- Exchanges views on policies for actions taken following large-scale cyber incidents and crises, based on lessons learned from the CSIRTs network and EU-CyCLONe.
- Discusses cases of mutual assistance, including experiences and results of cross-border joint supervisory actions.
- Addresses specific requests for mutual assistance at the request of one or more Member States.
NIS2: Other responsibilities
Reports:
The Cooperation Group submits reports on the experience gained at the strategic level and from peer reviews to the Commission, the European Parliament, and the Council.
Operating procedures:
- The Cooperation Group operates on the basis of biennial work programs.
- The Commission may adopt implementing acts establishing the procedural arrangements necessary for the functioning of the Group.
- Member States are responsible for ensuring the effective, efficient, and secure collaboration of their representatives in the Cooperation Group.
- The Group may request technical reports from the CSIRTs network on selected topics.
The Cooperation Group plays a crucial role in promoting collaboration and the harmonization of cybersecurity efforts across the EU. Through its diverse functions, it contributes to achieving a high common level of cybersecurity in the Union, in line with the main objective of the NIS2 Directive.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
