NIS2 Directive: How will it be evaluated?

Direttiva NIS2 Come Sarà Valutata

The NIS2 Directive imposes new standards for cybersecurity, but how will the involved entities be evaluated? Companies will have to comply with stricter criteria, but what will the control parameters be? Understanding the evaluation process is essential to prepare for the new rules and avoid sanctions. For organizations that are structuring a NIS2 compliance roadmap, knowing the control mechanisms provided by the directive is the first concrete step.

🔴 NIS2 compliance: identify hidden risks and strengthen your security with a focused assessment by ISGroup specialists.

NIS2 Directive: The European Commission’s periodic review

The European Commission is tasked with reviewing the functioning of the directive and submitting a report to the European Parliament and the Council. The first review is scheduled for October 17, 2027, with subsequent reviews every 36 months. This review will assess the impact of the directive, identify areas for improvement, and consider the potential need for legislative proposals.

  • Peer review: The NIS2 Directive establishes a voluntary peer review mechanism among Member States. These reviews aim to assess and improve the cybersecurity capabilities of Member States and the policies related to the implementation of the directive. The Cooperation Group, with the support of the Commission and ENISA, defines the methodology and organizational aspects of such reviews.
    • Peer reviews focus on various aspects, including the implementation of cyber risk management measures, incident reporting processes, the capabilities of competent authorities and CSIRTs, mutual assistance agreements, information-sharing agreements, and cross-border or cross-sectoral issues.
    • The results of these reviews will provide insights into the effectiveness of the directive’s implementation across Member States and identify potential areas for improvement.
  • Cooperation Group reports: The Cooperation Group is composed of representatives from Member States, the Commission, and ENISA. It is responsible for preparing reports based on experiences gained at the strategic level and from peer reviews. These reports will be sent to the Commission, the European Parliament, and the Council, contributing to the overall assessment of the directive’s effectiveness.
  • State of cybersecurity reports: ENISA, in collaboration with the Commission and the Cooperation Group, is required to publish a biennial report on the state of cybersecurity in the EU. This report will assess various aspects of cybersecurity, including:
    • Cybersecurity risks at the EU level, taking into account the cyber threat landscape.
    • Development of cybersecurity capabilities in the public and private sectors.
    • Awareness of citizens and entities regarding cybersecurity and cyber hygiene.
    • Aggregated results of peer reviews.
    • Aggregated level of maturity of cybersecurity capabilities and resources in the EU, including specific sectors, and the level of alignment of Member States’ national cybersecurity strategies.
    These reports will provide valuable data and insights into the overall state of the EU’s cybersecurity posture and the impact of the NIS2 Directive.
  • CSIRT Network reports: The CSIRT Network, responsible for operational cooperation between national CSIRTs, is required to assess progress in operational cooperation and produce a report every two years. The report will be conducted starting from January 17, 2025. This report, sent to the Cooperation Group, will assess progress based on the peer reviews of national CSIRTs and will include conclusions and recommendations. The report will contribute to understanding the effectiveness of the operational cooperation and incident response mechanisms established by the directive.
  • EU-CyCLONe evaluation report: EU-CyCLONe, established to support the coordinated management of large-scale cybersecurity incidents and crises, will submit an evaluation report to the European Parliament and the Council. The first report is scheduled for July 17, 2024, with subsequent reports every 18 months. This report will provide insights into the effectiveness of cyber crisis management mechanisms at the EU level.

By combining data and insights from these various sources, the EU intends to comprehensively assess the effectiveness of the NIS2 Directive in achieving its goals of improving cybersecurity throughout the Union.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In