The NIS2 Directive establishes a series of fundamental cybersecurity requirements for entities that fall within its scope. The following response outlines some of these key requirements.
Main cybersecurity requirements of the NIS2 Directive
- Risk management: Under the NIS2 Directive, Member States must ensure that entities designated as “essential” or “important” adopt technical, operational, and organizational measures to manage risks related to the cybersecurity of their information and network systems. This risk management approach applies both to the entities’ internal operations and to the provision of their services. Cybersecurity risk management measures must include, among other things:
- Risk analysis and information system security policies;
- Incident handling;
- Business continuity (e.g., backup management and disaster recovery) and crisis management;
- Supply chain security;
- Policies and procedures for the use of cryptography (and encryption, where applicable).
- Incident reporting: The NIS2 Directive requires entities to report “significant incidents” to the national Computer Security Incident Response Team (CSIRT) or the competent national authority “without undue delay.” A “significant incident” is defined as an event that “has caused or is capable of causing a substantial disruption in the provision of an essential service.” For NIS entities, the designation of the CSIRT contact person is one of the operational requirements that should not be overlooked.
- Supervisory measures: The competent authorities of each Member State are tasked with supervising the entities that fall within the scope of the NIS2 Directive. To this end, the Directive grants these authorities various supervisory tools, including:
- Regular and targeted audits;
- On-site and off-site checks;
- Requests for information; and
- Access to documents and other evidence.
- Enforcement: The NIS2 Directive harmonizes sanction regimes for entities that do not comply with their obligations. It establishes a minimum list of administrative sanctions for violations of risk management and incident reporting obligations. These sanctions include:
- Binding instructions;
- Orders to implement the recommendations of a security audit;
- Orders to bring security measures into compliance with the requirements of the NIS2 Directive; and
- Administrative fines.
Equivalence with sector-specific legal acts
It is important to note that the NIS2 Directive includes a principle of “equivalence” with current and future EU sector-specific legal acts that address cybersecurity.
- According to this principle, the cybersecurity provisions of the NIS2 Directive do not apply to entities already subject to sector-specific cybersecurity obligations under EU law, provided that the obligations in question are at least equivalent to those of the NIS2 Directive.
- To determine whether such sector-specific obligations are equivalent, it is necessary to assess whether they include measures that ensure the security of “network and information systems.” This term, as defined in the NIS2 Directive, is quite broad and includes:
- Electronic communications networks;
- Any device or group of interconnected or related devices, one or more of which, pursuant to a program, perform automatic processing of digital data; and
- Digital data that is stored, processed, retrieved, or transmitted through such networks or devices for the purposes of operation, use, protection, and maintenance.
- In determining equivalence, it is also important to consider whether the risk management measures of the sector-specific legal act take into account the physical and environmental security of network and information systems, protecting them from threats such as:
- System failures;
- Human error;
- Malicious actions; or
- Natural phenomena.
The European Commission has published guidelines clarifying how this principle of equivalence applies. For example, the Commission has stated that the sector-specific cybersecurity obligations in the Digital Operational Resilience Act (DORA) are equivalent to those of the NIS2 Directive and, consequently, the cybersecurity provisions of NIS2 do not apply to entities subject to DORA. However, Member States are still required to apply the provisions of the NIS2 Directive regarding:
- National cybersecurity incident and crisis response plans;
- EU-CyCLONe; and
- National cybersecurity strategies
to entities that fall within the scope of DORA.
Scope of the NIS2 Directive
The NIS2 Directive applies to both public and private entities. It covers entities in a wide range of sectors, including:
- Energy;
- Transport;
- Banking;
- Financial market infrastructures;
- Health (including the production of pharmaceuticals);
- Drinking water;
- Wastewater;
- Digital infrastructure;
- ICT service management;
- Public administration;
- Space;
- Postal and courier services;
- Waste management;
- Chemicals;
- Food;
- Manufacturing of medical devices, computers, electronics, machinery, equipment, motor vehicles, trailers and semi-trailers, and other transport equipment;
- Digital providers (including online marketplaces, online search engines, and social networking services); and
- Research organizations.
In general, only medium and large companies in these sectors will be covered by the NIS2 Directive. However, Member States have the discretion to apply the Directive’s obligations to smaller entities that present a high-risk profile. To understand whether your organization falls within the scope and what requirements are specifically needed, it is useful to also consult the information on ACN and the NIS2 list of obligated entities. Those who have already verified their inclusion can explore the compliance path with the NIS2 Directive compliance support offered by ISGroup.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
