Art.1(1)Subject matter — high common level of cybersecurity
This Directive lays down measures that aim to achieve a high common level of cybersecurity across the Union, with a view to improving the functioning of the internal market.
Loading…
Authority: EU · Version: 2022/2555 · 2022-12-14 ·
NIS2 Direktifi (2022/2555), AB genelinde enerji, ulaşım, finans, sağlık ve dijital altyapı gibi kritik sektörlerde siber güvenlik olgunluğunu ve zorunlu olay raporlama mekanizmalarını güçlendiren bağlayıcı bir düzenlemedir. Platform, NIS2 kapsamındaki güvenlik önlemleriyle örtüşen baseline ve playbook içerikleriyle üye devletlerde faaliyet gösteren kuruluşların uyum hazırlığına katkı sunar.
This Directive lays down measures that aim to achieve a high common level of cybersecurity across the Union, with a view to improving the functioning of the internal market.
To that end, this Directive lays down: (a) obligations that require Member States to adopt national cybersecurity strategies and to designate or establish competent authorities, cyber crisis management authorities, single points of contact on cybersecurity (single points of contact) and computer security incident response teams (CSIRTs); (b) cybersecurity risk-management measures and reporting obligations for entities of a type referred to in Annex I or II as well as for entities identified as critical entities under Directive (EU) 2022/2557; (c) rules and obligations on cybersecurity information sharing; (d) supervisory and enforcement obligations on Member States.
For the purposes of this Directive, the following entities shall be considered to be essential entities: (a) entities of a type referred to in Annex I that exceed the ceilings for medium-sized enterprises provided for in Article 2(1) of the Annex to Recommendation 2003/361/EC; (b) qualified trust service providers and top-level domain name registries as well as DNS service providers, regardless of their size; (c) providers of public electronic communications networks or providers of publicly available electronic communications services that qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC; (d) public administration entities of central government as defined by a Member State in accordance with national law; (e) any other entities of a type referred to in Annex I or II that are identified as essential entities by Member States; (f) entities identified as critical entities under Directive (EU) 2022/2557; (g) entities that the Member States, before 16 January 2023, had identified under national measures implementing Directive (EU) 2016/1148 as operators of essential services.
Entities of a type referred to in Annex I or II that do not qualify as essential entities pursuant to paragraph 1 shall be considered to be important entities. Important entities shall also include entities identified as such by Member States pursuant to Article 2(2)(b) or (d).
Member States shall ensure that the management bodies of essential and important entities approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation and can be held liable for infringements by the entities of that Article.
Member States shall ensure that the members of the management bodies of essential and important entities are required to follow training, and shall encourage essential and important entities to offer similar training to their employees on a regular basis, in order that they gain sufficient knowledge and skills to enable them to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the entity.
Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services, and to prevent or minimise the impact of incidents on recipients of their services and on other services. Taking into account the state-of-the-art and, where applicable, relevant European and international standards, as well as the cost of implementation, those measures shall ensure a level of security of network and information systems appropriate to the risks posed.
policies on risk analysis and information system security
incident handling
business continuity, such as backup management and disaster recovery, and crisis management
supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers
security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure
policies and procedures to assess the effectiveness of cybersecurity risk-management measures
basic cyber hygiene practices and cybersecurity training
policies and procedures regarding the use of cryptography and, where appropriate, encryption
human resources security, access control policies and asset management
the use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the entity, where appropriate
Member States shall ensure that, when considering which measures referred to in paragraph 2, point (d), are appropriate, entities take into account the vulnerabilities specific to each direct supplier and service provider and the overall quality of products and cybersecurity practices of their suppliers and service providers, including their secure development procedures. Member States shall also ensure that, when considering which measures referred to in that point are appropriate, entities are required to take into account the results of the coordinated security risk assessments of critical supply chains carried out in accordance with Article 22(1).
Member States shall ensure that, where an entity finds that it does not comply with the measures provided for in paragraph 2, it takes, without undue delay, all necessary, appropriate and proportionate corrective measures.
Each Member State shall ensure that essential and important entities notify, without undue delay, its CSIRT or, where applicable, its competent authority in accordance with paragraph 4 of any incident that has a significant impact on the provision of their services as referred to in paragraph 3 (significant incident). Where appropriate, entities concerned shall notify, without undue delay, the recipients of their services of significant incidents that are likely to adversely affect the provision of those services. Each Member State shall ensure that those entities report, inter alia, any information enabling the CSIRT or, where applicable, the competent authority to determine any cross-border impact of the incident. The mere act of notification shall not subject the notifying entity to increased liability.
Where applicable, Member States shall ensure that essential and important entities communicate, without undue delay, to the recipients of their services that are potentially affected by a significant cyber threat any measures or remedies that those recipients are able to take in response to that threat. Where appropriate, the entities shall also inform those recipients of the significant cyber threat itself.
An incident shall be considered to be significant if: (a) it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned; (b) it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage.
Member States shall ensure that, for the purpose of notification under paragraph 1, the entities concerned submit to the CSIRT or, where applicable, the competent authority: (a) without undue delay and in any event within 24 hours of becoming aware of the significant incident, an early warning, which, where applicable, shall indicate whether the significant incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact; (b) without undue delay and in any event within 72 hours of becoming aware of the significant incident, an incident notification, which, where applicable, shall update the information referred to in point (a) and indicate an initial assessment of the significant incident, including its severity and impact, as well as, where available, the indicators of compromise; (c) upon the request of a CSIRT or, where applicable, the competent authority, an intermediate report on relevant status updates; (d) a final report not later than one month after the submission of the incident notification under point (b), including the following: (i) a detailed description of the incident, including its severity and impact; (ii) the type of threat or root cause that is likely to have triggered the incident; (iii) applied and ongoing mitigation measures; (iv) where applicable, the cross-border impact of the incident.
In order to demonstrate compliance with particular requirements of Article 21, Member States may require essential and important entities to use particular ICT products, ICT services and ICT processes, developed by the essential or important entity or procured from third parties, that are certified under European cybersecurity certification schemes adopted pursuant to Article 49 of Regulation (EU) 2019/881. Furthermore, Member States shall encourage essential and important entities to use qualified trust services.
The Commission is empowered to adopt delegated acts, in accordance with Article 38, to supplement this Directive by specifying which categories of essential and important entities are to be required to use certain certified ICT products, ICT services and ICT processes or obtain a certificate under a European cybersecurity certification scheme adopted pursuant to Article 49 of Regulation (EU) 2019/881. Those delegated acts shall be adopted where insufficient levels of cybersecurity have been identified and shall include an implementation period.
Where no appropriate European cybersecurity certification scheme for the purposes of paragraph 2 of this Article is available, the Commission may, after consulting the Cooperation Group and the European Cybersecurity Certification Group, request ENISA to prepare a candidate scheme pursuant to Article 48(2) of Regulation (EU) 2019/881.
In order to promote the convergent implementation of Article 21(1) and (2), Member States shall, without imposing or discriminating in favour of the use of a particular type of technology, encourage the use of European and international standards and technical specifications relevant to the security of network and information systems.
ENISA, in cooperation with Member States, and, where appropriate, after consulting relevant stakeholders, shall draw up advice and guidelines regarding the technical areas to be considered in relation to paragraph 1 as well as regarding already existing standards, including national standards, which would allow for those areas to be covered.
Entities falling within the scope of this Directive shall be considered to fall under the jurisdiction of the Member State in which they are established, except in the case of: (a) providers of public electronic communications networks or providers of publicly available electronic communications services, which shall be considered to fall under the jurisdiction of the Member State in which they provide their services; (b) DNS service providers, TLD name registries, entities providing domain name registration services, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, as well as providers of online marketplaces, of online search engines or of social networking services platforms, which shall be considered to fall under the jurisdiction of the Member State in which they have their main establishment in the Union; (c) public administration entities, which shall be considered to fall under the jurisdiction of the Member State which established them.
Where an entity referred to in paragraph 1, point (b), is not established in the Union but offers services within the Union, it shall designate a representative in the Union. The entity shall be considered to fall under the jurisdiction of the Member State in which the representative is established. In the absence of a representative designated in the Union pursuant to this paragraph, any Member State in which the entity provides services may take legal actions against the entity for infringements of this Directive.
Member States shall ensure that the supervisory and enforcement measures imposed on essential entities are effective, proportionate and dissuasive. Competent authorities shall have the power to conduct on-site inspections and off-site supervision, including random checks; regular and targeted security audits; ad hoc audits following a significant incident; security scans; and requests for information concerning cybersecurity risk-management measures. Enforcement measures include issuing warnings, binding instructions, orders to cease infringing conduct, and administrative fines pursuant to Article 34.
Member States shall ensure that the supervisory and enforcement measures imposed on important entities are effective, proportionate and dissuasive. Competent authorities shall have the power to conduct on-site inspections and off-site ex post supervision; targeted security audits carried out by an independent body or competent authority; and requests for information concerning cybersecurity risk-management measures. Enforcement measures include issuing warnings, adopting binding instructions, ordering entities to cease infringing conduct, and imposing administrative fines pursuant to Article 34.
Our content SUPPORTS technical controls; it does not produce audit evidence/opinion. Formal compliance requires an accredited body. ·