NIS2: Are there any exemptions or derogations?

Direttiva NIS2 Esenzioni Deroghe

Sources indicate several examples of exemptions and derogations that release an entity from having to comply with all or some of the provisions of the NIS2 Directive.

๐Ÿ”ด NIS2 compliance: identify hidden risks and strengthen your security with a focused assessment by ISGroup specialists.

NIS2: Specific sectoral legislation

The NIS2 Directive aims to establish a minimum standard for cybersecurity across a wide range of sectors. However, it recognizes that some sectors may already be subject to specific EU legislation that addresses cyber risks and incident reporting requirements. If the requirements of the specific sectoral legislation are at least as stringent as those provided for by the NIS2 Directive, the entities concerned will be exempted from the corresponding provisions of the NIS2 Directive. This exemption concerns provisions relating to cyber risk management measures and incident reporting obligations.

  • Equivalence: To determine whether a sectoral law is equivalent, it must meet one of two criteria:
  • The effects of the risk management measures of the sectoral legislation must be at least equivalent to Articles 21(1-2) of the NIS2 Directive.
  • The sectoral legislation must ensure immediate (and potentially automatic and direct) access to incident notifications sent by Computer Security Incident Response Teams (CSIRTs), competent authorities, or single points of contact. Furthermore, the obligations regarding the reporting of significant incidents in the sectoral legislation must be at least equivalent to those provided for by Articles 23(1-6) of the NIS2 Directive.
  • Partial coverage: If the sectoral legislation covers only a subset of entities within a sector that falls under the scope of the NIS2 Directive, the provisions of the directive will still apply to the remaining entities in that sector.

Sources cite the Digital Operational Resilience Act (DORA) as a specific example of sectoral legislation that exempts certain entities from the NIS2 Directive. DORA regulates the cybersecurity of the financial sector, and entities falling within its scope are not subject to the corresponding provisions of the NIS2 Directive. For organizations that instead fall fully within the NIS2 scope, initiating a structured path to directive compliance is the most effective way to manage obligations in an orderly manner.

Public administration and national security

The NIS2 Directive exempts certain public administration entities that operate in sectors related to national security, public security, defense, or law enforcement. This exemption applies to activities such as the prevention, investigation, detection, and prosecution of criminal offenses. Entities that exclusively provide services to these exempted public administrations may also be exempted from certain obligations of the NIS2 Directive, upon the decision of Member States.

  • Trust service providers: However, even if an entity is exempted due to its involvement in sectors related to national or public security, the NIS2 Directive still applies if the entity acts as a trust service provider.

NIS2: Other exemptions and derogations

The NIS2 Directive also provides for other exemptions and derogations, including:

  • Entities exempted from DORA: Entities that Member States have exempted from DORA pursuant to Article 2(4) of that regulation are also exempted from the NIS2 Directive.
  • Protection of essential interests: The obligations of the directive do not require entities to disclose information that would compromise the essential national security, public security, or defense interests of a Member State.
  • Confidentiality of information: Confidential information, such as trade secrets, protected by EU or national law, may be shared with the Commission and other competent authorities only if strictly necessary for the application of the directive.
  • Data protection: The processing of personal data under the NIS2 Directive must comply with the General Data Protection Regulation (GDPR). Providers of public electronic communications networks or publicly available electronic communications services must also comply with EU data protection and privacy legislation, including Directive 2002/58/EC.

Higher national standards

The NIS2 Directive sets minimum cybersecurity requirements across the EU. However, it does not prevent Member States from adopting or maintaining stricter provisions regarding cybersecurity. As long as such national provisions are compatible with EU law, they can coexist with the NIS2 Directive.

Commission guidelines

The European Commission is responsible for providing guidelines to clarify the application of these exemptions and derogations, particularly in situations involving specific sectoral legislation. The Commission also provides guidance on the information that Member States must transmit when notifying the Commission of the lists of essential and important entities covered by the directive.

It is important to note that the sources focus primarily on the exemptions and derogations explicitly mentioned in the NIS2 Directive. It is possible that national law or other EU regulations may affect the application of the directive in ways not explicitly covered in the provided text. For a complete picture of the obligations applicable to your organization, it is also useful to consult the list of NIS2 subjects published by ACN and the related compliance deadlines.

Frequently asked questions about NIS2 exemptions

  • How can an organization verify if it falls under an exemption from the NIS2 Directive?
  • The starting point is to verify whether the organization operates in a sector already governed by specific sectoral EU legislation โ€” such as DORA for the financial sector โ€” and whether that legislation meets the equivalence criteria provided by NIS2. In case of doubt, an analysis of the scope of application is advisable before assuming you are exempt.
  • Is an entity partially covered by DORA still subject to NIS2?
  • It depends on the scope of application. If DORA covers only certain activities or certain entities in a sector, the remaining entities or activities not covered remain subject to the NIS2 Directive. The exemption is neither automatic nor total: it must be verified on a case-by-case basis against the actual scope of each regulation.
  • Do stricter national standards also apply to entities that benefit from a NIS2 exemption?
  • The exemptions provided by NIS2 concern the obligations of the directive itself. Member States may adopt stricter national provisions that are compatible with EU law, and these can in principle also apply to subjects that are exempted from NIS2, depending on how the national legislator has transposed and delimited the exemptions.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In