PageSourceSearch

https://nis-2-directive.com/

html nis-2-directive.com collected 2026-10-02 04:08:54 UTC 126,346 bytes, 1,377 lines download raw bytes

1<!DOCTYPE html>
2<html lang="en">
3<head>
4	
5	
6
7	
8	
9	
10	
11	
12	
13<meta charset="utf-8">
14<meta http-equiv="X-UA-Compatible" content="IE=edge">
15<meta name="viewport" content="width=device-width, initial-scale=1">
16<!-- The above 3 meta tags *must* come first in the head; any other head content must come *after* these tags -->
17
18	
19<title>The NIS 2 Directive | Updates, Compliance, Training</title>
20	
21 <meta name="description" content="Uncover the critical components of the NIS 2 Directive. Access expert-led compliance insights to navigate regulatory requirements effectively. Earn your online certification, providing independent evidence of your quantifiable understanding of the subject matter.">
22		
23<meta name="keywords" content="nis2 directive, nis 2 directive, nis2, nis, nis 2, nis-2, nis directive, nis2 compliance, nis 2 compliance, what is nis2, nis2 directive pdf, nis2 requirements, directive (eu) 2022/2555, eu nis2, eu nis 2, nis 2.0, 2022/2555, nis2 eu, nis2 regulation, nis 2 directive pdf, nis2 certification, nis 2 certification, nis2 cybersecurity, nis ii, directive nis 2, nis2 training, nis 2 training, nis2 text, nis 2 text, nis2 pdf, nis2 scope, network and information security directive, nis2 directive eu">
24	
25	
26	
27	
28	
29	
29<script type="application/ld+json">
30{
31  "@context": "https://schema.org",
32  "@type": "BreadcrumbList",
33  "itemListElement": [
34    {
35      "@type": "ListItem",
36      "position": 1,
37      "name": "Index",
38      "item": " https://www.nis-2-directive.com"
39    },
40    {
41      "@type": "ListItem",
42      "position": 2,
43      "name": "NIS 2 Directive Trained Professional (NIS2DTP)",
44      "item": " https://www.nis-2-directive.com/NIS_2_Directive_Trained_Professional_(NIS2DTP).html"
45    },
46    {
47      "@type": "ListItem",
48      "position": 3,
49      "name": " NIS 2 Directive (Final Text)",
50      "item": "https://www.nis-2-directive.com/NIS_2_Directive_Articles.html"
51    },
52    {
53      "@type": "ListItem",
54      "position": 4,
55      "name": " NIS 2 Directive Links",
56      "item": "https://www.nis-2-directive.com/Links.html"
57    },
58    {
59      "@type": "ListItem",
60      "position": 5,
61      "name": "Cyber Risk GmbH",
62      "item": "https://www.cyber-risk-gmbh.com"
63    }
64  ]
65}
66</script>
66
67
68
69<script type="application/ld+json">
70{
71  "@context": "https://schema.org",
72  "@type": "Organization",
73  "name": "Cyber Risk GmbH",
74  "url": "https://www.cyber-risk-gmbh.com",
75  "logo": "https://www.cyber-risk-gmbh.com/Cyber_Risk_GmbH_Logo.jpg",
76  "sameAs": [
77    "https://www.linkedin.com/company/71474270/admin/page-posts/published/",
78    "https://x.com/Cyber_Risk_GmbH"
79  ],
80  "contactPoint": {
81    "@type": "ContactPoint",
82    "telephone": "+41-79-5058960",
83    "contactType": "Customer Service",
84    "areaServed": "Worldwide",
85    "availableLanguage": "English"
86  },
87  "founder": {
88    "@type": "Person",
89    "name": "George Lekatis"
90  },
91  "description": "Cyber Risk GmbH is a leading provider of NIS 2 Training in Switzerland and worldwide.",
92  "address": {
93    "@type": "PostalAddress",
94    "streetAddress": "Dammstrasse 16",
95    "addressLocality": "Horgen",
96    "addressRegion": "Canton of Zürich",
97    "postalCode": "8810",
98    "addressCountry": "CH"
99  }
100}
101</script>
101
102
103	
104	
105	
106	
107	
108	
109	
110	
111	<link rel="apple-touch-icon" sizes="180x180" href="apple-touch-icon.png">
112    <link rel="icon" type="image/png" sizes="32x32" href="favicon-32x32.png">
113    <link rel="icon" type="image/png" sizes="16x16" href="favicon-16x16.png">
114    <link rel="shortcut icon" type="image/x-icon" href="favicon.ico">
115    <link rel="manifest" href="manifest.json">
116    <meta name="msapplication-TileImage" content="mstile-150x150.png">
117    <meta name="theme-color" content="#ffffff">
118
119
120<!-- Bootstrap -->
121<link href="css/bootstrap.min.css" rel="stylesheet">
122<link href="css/style.css" rel="stylesheet">
123<!--font-awesome-->
124<link href="https://stackpath.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css" rel="stylesheet">
125<link href="https://fonts.googleapis.com/css2?family=Montserrat:wght@100;200;300;400;500;600;700;800;900&display=swap" rel="stylesheet">
126
127<!-- Owl Stylesheets -->
128<link rel="stylesheet" href="css/owl.carousel.css">
129<link rel="stylesheet" href="css/owl.theme.default.css">
130
131<!-- javascript -->
132<script src="js/jquery.min.js"></script>
vendor: 2 bytes, line 132
132
133<script src="js/owl.carousel.js"></script>
133
134
135<!-- HTML5 shim and Respond.js for IE8 support of HTML5 elements and media queries -->
136<!-- WARNING: Respond.js doesn't work if you view the page via file:// -->
137<!--[if lt IE 9]>
138      
138<script src="https://oss.maxcdn.com/html5shiv/3.7.3/html5shiv.min.js"></script>
138
139      
139<script src="https://oss.maxcdn.com/respond/1.4.2/respond.min.js"></script>
139
140    <![endif]-->
141	
142	<meta name="google-site-verification" content="I0CDxLn5hun_Esd7Gf8jIPUBQ1eIIcVNsUQQ9d4Dq8Q">
143	<style>
144.wrapper-banner {
145  background: url("NIS_2_Directive.jpg");
146  background-size: cover;
147  background-position: center;
148}
149
150</style>
151	<meta name="msvalidate.01" content="3992470AA0B488CE9CF07B1CD73A76D7">
152	
153	<link rel="stylesheet" href="./style2.css">	
154	
155	
156	<style>
157body {
158  color: black;
159}
160</style>
161
162<style>
163a:link {
164  color: blue;
165  background-color: transparent;
166  text-decoration: none;
167}
168a:visited {
169  color: blue;
170  background-color: transparent;
171  text-decoration: none;
172}
173a:hover {
174  color: red;
175  background-color: transparent;
176  text-decoration: underline;
177}
178a:active {
179  color: blue;
180  background-color: transparent;
181  text-decoration: underline;
182}
183</style>
184
185
186	
187	
188<link rel="canonical" href="https://www.nis-2-directive.com" />	
189	
190	
191	
192</head>
193	
194<body>
195	
196
197<!-- Fixed navbar -->
198
199<div class="wrapper-menu">
200  <nav id="header" class="navbar navbar-fixed-top">
201    <div id="header-container" class="container navbar-container">
202      <div class="navbar-header">
203        <button type="button" class="navbar-toggle collapsed" data-toggle="collapse" data-target="#navbar" aria-expanded="false" aria-controls="navbar"> <span class="sr-only">Toggle navigation</span> <span class="icon-bar"></span> <span class="icon-bar"></span> <span class="icon-bar"></span> </button>
204        <a id="brand" class="navbar-brand" href="https://www.disinformation.ch/">
205        <!--<img src="images/logo-black.png"  alt="" class="shrink-logo"> -->
206        
207        </a> </div>
208      <div id="navbar" class="collapse navbar-collapse">
209        <ul class="nav navbar-nav">
210			
211			
212	<li><a href="https://www.nis-2-directive.com" target="_blank" >Index</a></li>
213
214
215<li><a href="https://www.nis-2-directive.com/NIS_2_Directive_Trained_Professional_(NIS2DTP).html" target="_blank" >NIS 2 Online Training</a></li>
216
217			
218<li><a href="https://www.nis-2-directive.com/NIS_2_Directive_Training.html" target="_blank" >NIS 2 Training</a></li>
219			
220		
221<li><a href="https://www.nis-2-directive.com/NIS_2_Directive_Board_of_Directors_Training.html" target="_blank" >NIS 2 Board Training</a></li>			
222			
223			
224<li><a href="https://www.nis-2-directive.com/NIS_2_Directive_Articles.html" target="_blank" >Articles NIS 2 Directive</a></li>
225			
226			
227<li><a href="https://www.nis-2-directive.com/NIS_2_Directive_Articles_(Proposal_16.12.2020).html" target="_blank" >Articles NIS 2 Directive (Proposal)</a></li>			
228			
229			
230<li><a href="https://www.nis-2-directive.com/Links.html" target="_blank" >NIS 2 Directive Links</a></li>			
231<li><a href="https://www.nis-2-directive.com/NIS_2_Directive_Transposition.html" target="_blank" >NIS 2 Transposition</a></li>					
232			
233<li><a href="https://www.cyber-risk-gmbh.com" target="_blank">Cyber Risk GmbH</a></li>
234
235          
236<li><a href="https://www.cyber-risk-gmbh.com/Impressum.html" target="_blank">Impressum</a></li>
237		
238			
239			
240			
241			
242			
243			
244			
245			
246			
247        </ul>
248      </div>
249      <!-- /.nav-collapse --> 
250    </div>
251    <!-- /.container --> 
252  </nav>
253  <!-- /.navbar --> 
254  
255</div>
256<div class="container-fluid wrapper-banner">
257  <div class="container">
258    <div class="top-banner">
259      
260      
261		
262      
263    </div>
264  </div>
265</div>
266	
267	
268	
269<div class="container-fluid projects-wrapper">
270  <div class="container">
271    <div class="row">
272      <div class="section-title">
273		  
274		  
275		  
276	<h1 style="font-family: Georgia, 'Times New Roman', Times, serif;">The NIS 2 Directive | Updates, Compliance</h1>  	  
277		  
278		  
279		  
280		
281<br>
282		  
283		  
284		   <h2 style="text-align: left; font-size: 25px; font-family: Georgia, 'Times New Roman', Times, serif;">What is the NIS 2 Directive?</h2>
285
286		  
287		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The NIS 2 (Directive (EU) 2022/2555) establishes the European Union's updated cybersecurity framework, replacing the original NIS (Directive (EU) 2016/1148). Its objective is to achieve a high common level of cybersecurity across the Union by strengthening the security of network and information systems. </p>
288			  
289			  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The NIS 2 Directive significantly expands the scope of the original NIS, and covers a broader range of sectors and entities, while introducing more stringent governance, cybersecurity risk management, incident reporting, and supervisory requirements. It also grants national competent authorities enhanced 
289supervisory and enforcement powers, including the authority to impose substantial administrative fines for non compliance.</p>
290			  
291			  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Under NIS 2, essential and important entities are required to implement appropriate and proportionate technical, operational, and organisational measures to manage the risks in network and information systems. These measures are intended to protect the entities' own operations, but also to prevent or minimise the impact of incidents on service recipients and on interconnected network and information systems.</p>
292			  
293			  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The Directive further adopts an all-hazards approach, requiring organisations to prepare for a broad spectrum of risks. The objective is to strengthen operational resilience and ensure the continuity of essential and important services.</p>
294		  
295		 <hr>
296		  
297		   <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>26 May 2026 - The NIS2 Cooperation Group adopted common templates for incident reporting</b></p>  
298		  
299		  
300		   <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The adoption took place during the 39th Plenary meeting in Cyprus. These templates provide a <b> clear, uniform format for reporting cyber incidents. </b>This major simplification measure will reduce the administrative burden of companies.</p> 
301		  
302		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The common templates align with the broader EU efforts, including the proposed single entry point for incident reporting under the Digital Omnibus.</p> 
303		  
304		   <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>Next Step:</b>The European Commission will adopt these templates through an <b>implementing act, making them mandatory for all Member States.</b> </p> 
305		  
306		  
307		  
308		  <hr>
309		  
310		 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>16 March 2026 Update - Stop calling it a failure because of the missed deadline. Why NIS 2 is the world’s biggest cybersecurity success (Opinion | Legal Intelligence).</b></p>  
311		  
312		  
313		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> The widespread habit of describing NIS 2 as a failure merely because several Member States did not complete transposition by 17 October 2024, calls for a more careful and balanced evaluation. It mistakes punctuality for substance and confuses delay in legislative completion with failure of regulatory transformation. </p>
314		  
315		   <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">In Union law, a missed transposition deadline is indeed a breach of obligation and may trigger enforcement consequences, but it does not mean that the legislative project itself is unsuccessful. That conclusion becomes even less sustainable <b>when one examines what NIS 2 actually required: </b> The reconstruction of national cybersecurity law, national supervisory architecture, incident reporting systems, public-private compliance structures, and board level accountability across the legal orders of twenty seven Member States at the same time, accompanied by the unprecedented expansion of the regulatory perimeter to include hundreds of thousands of entities required to comply with cybersecurity obligations and the new reporting obligations for the first time. </p>
316		  
317		   <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>The first dramatic change </b>was conceptual. NIS 2 establishes a Union-wide strategic governance framework for cybersecurity and digital resilience, a legal framework covering important and critical entities across the European Union.  This means that the transposition required changes affecting energy, transport, banking, financial market infrastru
317ctures, health, drinking water, wastewater, digital infrastructure, ICT services, public administration, space, postal services, waste management, chemicals, food, manufacturing, research, and other critical parts of the economy. </p>
318		  
319		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> Once the directive is understood in those terms, <b>the narrative of “failure because of delay” collapses.</b> We cannot evaluate the success of a civil code, a banking union measure, or a major constitutional reform by asking only whether every implementing act appeared on time. We must ask whether the reform altered the legal order in the intended direction. NIS 2 unquestionably did that.</p>
320		  
321		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b> The second dramatic change </b>was institutional. A directive of this kind could not be transposed by copying and pasting Union text into national statute books. It required Member States to designate or establish competent authorities, single points of contact, incident response capacity, supervision models, reporting channels, sanctions frameworks, registration mechanisms, and cross border cooperation arrangements. </p>
322		  
323		   <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Each Member State had to decide which ministry, regulator, cyber authority, sectoral supervisor, or combined structure would exercise powers over essential and important entities. How these powers would interact with preexisting sectoral laws. How confidential reporting would be handled. How information would be exchanged with ENISA and peer authorities. How national constitutional and administrative law constraints would be respected. </p>
324		  
325		  
326		   <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>The third dramatic change </b>was the move from selective coverage to systemic coverage. Under NIS 1, the legal architecture depended heavily on national discretion, which produced significant divergence. NIS 2 was intended to remove those divergences and to ensure a higher, more uniform level of resilience across the internal market. That objective alone made transposition difficult, because national legislators had to <b>revisit prior assumptions </b>about what counts as essential, which sectors merit public-law obligations, and how thresholds are set. </p>
327		  
328		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> The Directive’s distinction between essential entities and important entities is central. It required a systematic methodology for identifying entities, classifying them, subjecting them to differentiated supervisory treatment, and integrating them into a coherent compliance universe. This is a question of replacing a fragmented legal map with a more disciplined Union wide taxonomy of criticality. </p>
329		  
330		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> <b>The fourth dramatic change</b> was normative intensity. NIS 2 mandates concrete strategy, governance, and cybersecurity risk management measures based <b>on an all-hazards approach. </b> This includes policies, incident handling, business continuity including backup management and disaster recovery, crisis management, supply chain security, secure acquisition and development, vulnerability handling, effectiveness assessment, cyber hygiene and training, cryptography and encryption, access control, human resources security, asset management, and much more. </p>
331		  
332		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> This is a decisive shift from cybersecurity as a technical function to cybersecurity as a structured strategic compliance obligation. National transposition demanded sector sensitive legislative language, definitions aligned with domestic law, implementing or secondary legislation, supervisory guidance, and administrative readiness to assess compliance against these standards. A legislature can transpose a narrow duty quickly, but it cannot absorb and domesticate an all-hazards risk regime of this breadth without substantial legal work. The dramatic reality is that NIS 2 required Member States to legislate for resilience, continuity, and accountability at an unprecedented level of granularity.</p>
333		  
334		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> <b>The fifth dramatic change </b>was the elevation of management body responsibility. This element alone marks NIS 2 as a landmark in global cyber regulation. The Directive requires Member States to ensure that management bodies of essential and important entities approve the cybersecurity risk management measures, oversee their implementation, and can be held liable for infringements by the entities. It further requires training for members of management bodies. This is a major development. </p>
335		  
336		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> Such a transformation cannot be transposed mechanically. National lawmakers had to decide how to articulate liability, which corporate bodies were covered under domestic company law, how the rule would interact with directors’ duties, public sector governance models, regulated industry governance rules, labour law, and administrative sanction regimes. In many jurisdictions this meant building a bridge between cybersecurity law and corporate governance law that had not previously existed in a fully explicit form. That alone is a historic success. </p>
337		  
338		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> <b>The sixth dramatic change </b>was procedural acceleration. NIS 2 created a reporting architecture that is materially more demanding and operationally more mature than many legacy notification frameworks. Significant incidents require an early warning within 24 hours of becoming aware, a fuller incident notification within 72 hours, and subsequent reporting as the matter develops. The regime includes cross border impact analysis and communication with affected recipients of services. </p>
339		  
340		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> This is a major legal and operational shift, because incident notification is not simply the sending of a notice. It presupposes internal detection capability, legal tri
340age, management escalation, recordkeeping, interaction with CSIRTs or competent authorities, harmonisation with data protection reporting where personal data are involved, and defensible internal procedures for assessing materiality and significance. To transpose such obligations, states had to create receiving authorities, legal standards, sanctions, procedural channels, and in many cases secure national portals and coordination rules. The resulting apparatus is evidence that the Union moved beyond rhetorical cybersecurity policy into enforceable operational law. It is analytically perverse to reduce that achievement to the calendar question alone.</p>
341		  
342		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> <b>The seventh dramatic change </b>was the treatment of supply chain dependency. NIS 2 expressly requires consideration of supply chain security and the security related aspects of relationships between entities and their direct suppliers or service providers. It also links national compliance to Union level coordinated security risk assessments of critical supply chains. This is a profound recognition of modern cyber reality. Vulnerability often enters through outsourcing, software dependencies, managed service providers, cloud arrangements, maintenance chains, and procurement architectures rather than through a direct frontal assault on the target itself. </p>
343		  
344		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> Legally, that means Member States had to build a framework in which regulated entities assess external dependencies, contractual risk allocation, secure development procedures, supplier quality, and vulnerabilities embedded outside the formal perimeter of the enterprise. This is not easy legislation. It requires translating a theory of risk into enforceable obligations without collapsing into vagueness or disproportion. The fact that Europe attempted to do so, across a full Union framework, is a success of extraordinary significance.</p>
345		  
346		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> <b>The eighth dramatic change </b>was cultural. NIS 2 treats cyber hygiene, awareness, and training as part of the compliance fabric. The Directive explicitly references basic cyber hygiene practices and cybersecurity training among the required measures and also reflects a broader concern with user awareness, phishing, social engineering, updates, configuration, segmentation, and access management. </p>
347		  
348		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> In other words, the Directive rejects the false legal imagination that all cybersecurity problems can be solved through specialised technology while the wider organisation remains passive. It recognises that resilience depends on behaviour, culture, procurement, governance, business continuity, and internal discipline. National transposition required more than the enactment of technical norms. It required the legal normalisation of cyber preparedness as a routine expectation of organisational conduct. </p>
349		  
350		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> <b>The ninth dramatic change</b> was the integration of cyber resilience with critical entity resilience under the Critical Entities Resilience Directive (CER). This matters because NIS 2 was never operating in isolation. The CER Directive required Member States, by the same 17 October 2024 deadline, to adopt and publish the measures necessary to comply. </p>
351		  
352		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> CER was itself a major shift away from a narrow infrastructure protection paradigm toward a broader resilience framework, recognising that critical entities provide essential services indispensable to vital societal functions and economic activities, and that interdependencies can produce cascading and long term effects. It sought harmonised minimum rules, identification of critical entities, support and supervision measures, and a more coherent approach across sectors. <b>The major legal trouble lies precisely here. </b> Member States were transposing two demanding  directives the same time. Europe was attempting simultaneous cyber governance and resilience governance reconstruction.</p>
353		  
354		 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">  <b>The missed deadline should be treated as a serious but secondary phenomenon. </b>It is serious because Union directives bind as to the result to be achieved, and timely transposition is part of compliance. But it is secondary because the proper measure of NIS 2’s significance lies in its transformative legal effects. It replaced a narrow fragmented predecessor with a broad and more disciplined framework. NIS 2 is the largest coordinated legal reconstruction of cybersecurity governance ever attempted anywhere in the world.</p>
355		  
356		 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> NIS 2 succeeded precisely because it forced Europe to confront realities that could no longer be postponed. It compelled governments to admit that fragmented standards were no longer tolerable. It compelled boards to enter the realm of cyber accountability. It compelled regulators to build supervisory capacity. It compelled essential and important entities to move from vague awareness to concrete risk management. And because it did all this across an integrated economic and political union, its significance is global. By scale, by ambition, by depth of organisational impact, and by the breadth of the sectors covered, NIS 2 is the most consequential cybersecurity law in the world.</p>
357		  
358		  <br>
359		  
360		 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> <b> Case study: NIS 2 and Germany</b></p>
361		  
362		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> The German case demonstrates with clarity that the transposition of the NIS 2 Directive required profou
362nd structural changes in national law, administrative competence, constitutional balance, and regulatory supervision. </p>
363		  
364		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> The German legislature had to redesign the architecture of cybersecurity governance in a federal constitutional system in which legislative competence, administrative authority, and sectoral regulation are distributed across multiple layers of government. When the scale of those changes is properly examined, the delay in formal transposition becomes far less significant than the magnitude of the legal transformation that was underway.</p>
365		  
366		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> Germany had already implemented the original NIS framework through amendments to the IT Security Act and the provisions incorporated into the Act on the Federal Office for Information Security (BSIG – Gesetz über das Bundesamt für Sicherheit in der Informationstechnik). These earlier reforms created obligations for operators of critical infrastructures and strengthened the supervisory powers of the Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik, BSI). </p>
367		  
368		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> NIS 2 fundamentally altered the scale and philosophy of the regulatory system. It did not focus on a relatively narrow group of critical infrastructure operators. It introduced a <b>much broader concept of regulated entities, dividing them into essential entities and important entities </b>across numerous sectors. The consequence for Germany was dramatic. The number of organizations falling within the cybersecurity compliance regime was expected to increase several fold, expanding from roughly a few thousand entities under the previous framework to tens of thousands under the new regime.</p>
369		  
370		 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> Under the previous German regime, the focus was primarily on entities designated as operators of critical infrastructures under sector specific thresholds. NIS 2, by contrast, relies heavily on size based criteria combined with sectoral classification, which means that many medium sized enterprises suddenly became subject to cybersecurity risk management obligations and incident reporting requirements. </p>
371		  
372		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> German legislators had to construct an entirely new identification and registration framework to determine which companies would fall under the definitions of essential or important entities. This involved legal drafting and administrative preparation, because supervisory authorities must be able to identify regulated entities, communicate obligations, and monitor compliance across a vastly expanded population of organizations.</p>
373		  
374		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> <b>The federal constitutional structure </b>of Germany added a further layer of complexity. Germany is not a unitary state but a federal system in which legislative and administrative competences are divided between the Federation (Bund) and the Länder. Cybersecurity governance intersects with numerous policy areas, including internal security, telecommunications, energy regulation, health services, and public administration, many of which involve mixed or shared competences. The transposition of NIS 2 raised delicate constitutional questions regarding which level of government should exercise supervisory authority over the newly regulated entities and how federal and Länder competences should be reconciled.</p>
375		  
376		 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">  One of the central institutional questions was about the role of the Federal Office for Information Security. The BSI had already become Germany’s central cybersecurity authority under the earlier IT Security Acts, but <b>NIS 2 required a significant expansion of supervisory powers and responsibilities. </b>The Directive expects Member States to establish competent authorities capable of supervising both essential and important entities, conducting inspections, imposing sanctions, and coordinating with European counterparts. In the German constitutional order, <b>the expansion of federal supervisory authority </b>is never purely administrative, it must be justified within the framework of the Basic Law (Grundgesetz), which carefully distributes powers between the Federation and the Länder. As a result, the legislative process involved <b>extensive debate about the permissible scope of federal intervention, </b>the relationship between federal cybersecurity supervision and Länder administrative competences, and the legal basis for federal enforcement powers over private sector entities operating within sectors traditionally regulated at the regional level.</p>
377		  
378		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> The sectoral dimension of the reform created further complexity. Germany’s regulatory landscape is characterized by <b>strong sector specific regulators with established supervisory traditions.</b>
378 Telecommunications and digital infrastructure fall within the competence of the Federal Network Agency (Bundesnetzagentur). Financial institutions are supervised by the Federal Financial Supervisory Authority (BaFin). Energy infrastructure is subject to energy regulatory authorities. Health systems involve federal and regional oversight structures. The NIS 2 framework required the creation of a coherent cybersecurity supervision model capable of interacting with these existing regulators without duplicating or undermining their functions. German legislators had to determine whether the BSI should act as the primary cybersecurity supervisor across all sectors, whether sectoral regulators should retain partial authority, or whether a hybrid model should be established in which the BSI coordinates with sector-specific authorities.</p>
379		  
380		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> These questions go to the heart of administrative law and regulatory legitimacy. <b>A cybersecurity authority that suddenly acquires oversight over tens of thousands of entities</b> across multiple sectors must possess both legal authority and operational capacity. This requires clearly defined investigative powers, access to information, the ability to conduct audits or inspections, and the authority to impose sanctions. Each of these powers must be anchored in national administrative law and must respect constitutional guarantees such as proportionality, due process, and the protection of economic freedoms. In Germany’s legal tradition, which places great emphasis on the rule of law and judicial review, the design of supervisory powers must be carefully calibrated to ensure that enforcement measures are legally defensible and procedurally fair.</p>
381		  
382		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> Another dramatic element of the German transposition debate is <b> management responsibility. </b> NIS 2 explicitly requires Member States to ensure that management bodies approve cybersecurity risk management measures and oversee their implementation. It also requires that management bodies may be held liable for infringements. <b>Integrating this requirement into the German legal system raised complex questions </b>about the relationship between cybersecurity obligations and existing corporate governance rules under German company law. Directors of German corporations already owe duties of care and diligence under corporate law, but the explicit linkage between cybersecurity compliance and management liability introduced a new dimension. Legislators and legal scholars had to consider how this responsibility should interact with the established framework of board duties, supervisory board oversight, and the business judgment rule.</p>
383		  
384		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> <b>The reporting regime </b>introduced by NIS 2 also required significant adaptation in the German context. The Directive imposes strict timelines for incident notification and requires entities to provide early warnings, detailed incident reports, and follow up information to competent authorities. Implementing such a regime requires statutory provisions and operational infrastructure, including secure reporting channels, coordination procedures between authorities, and mechanisms for handling sensitive information. Germany needed to develop administrative processes that allow the BSI and other relevant authorities to receive and process large volumes of incident reports while ensuring confidentiality and effective response.</p>
385		  
386		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> Furthermore, the German implementation had to address <b> supply chain security.</b>  NIS 2 requires regulated entities to assess cybersecurity risks arising from their relationships with suppliers and service providers. In a highly industrialized economy such as Germany’s, where manufacturing and industrial supply chains are deeply integrated across national borders, this obligation has far reaching implications. Companies must evaluate the cybersecurity posture of suppliers, integrate contractual security requirements, and establish monitoring mechanisms for third-party risk. Legislators had to ensure that the national legal framework supports these obligations while remaining compatible with existing commercial law and procurement practices.</p>
387		  
388		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> When all these elements are considered together, the German example illustrates why the narrative of “failure to implement on time” is fundamentally misleading. Germany was redesigning the legal architecture of cybersecurity governance within a complex federal system, expanding regulatory coverage to an unprecedented number of entities, reconciling cybersecurity supervision with sector specific regulatory structures, integrating new management liability concepts into corporate governance law, and building operational mechanisms capable of supporting a dramatically expanded compliance regime.</p>
389		  
390		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> <b>The German experience reveals the true nature of NIS 2. </b>The Directive forces Member States to rethink how critical sectors are protected, how companies manage digital risk, how supervisory authorities exercise oversight, and how public and private actors cooperate in the face of cyber threats. In Germany, as in many other Member States, the transposition process required careful legal engineering precisely because the Directive is so ambitious. The delays that occurred are therefore better understood as the natural consequence of implementing one of the most far reaching cybersecurity reforms ever attempted within a democratic legal order.</p>
391		  
392		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
392Germany’s experience reinforces the central thesis that <b>NIS 2 is a historic regulatory success. </b>The Directive compelled one of Europe’s largest and most legally sophisticated economies to expand its cybersecurity regime from a relatively narrow critical infrastructure framework to a comprehensive system covering a vast portion of the national economy. It forced constitutional reflection, institutional redesign, and sectoral coordination. Such changes do not occur without legal debate, legislative refinement, and administrative preparation. </p>
393		  
394		  
395		  
396		  
397		  
398		  <br>
399		  <hr>
400		  
401		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>20 January, 2026 - Proposal for a Cybersecurity Act 2, affecting the NIS 2 Directive.</b></p>
402		  
403		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">This is one of the clearest EU texts so far that <b>explicitly treats cybersecurity as part of hybrid conflict.</b></p>
404		  
405		  
406		 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">According to the proposal, supply chain incidents, whether caused by criminals for financial gain or by State actors for disruption, espionage, disinformation or warfare have intensified. <b>As part of a wider hybrid strategy, </b>incidents resulting from malicious cyber activities and system failures ripple outward, disrupting essential services, undermining trust in institutions, and affecting the Union’s societal and defence readiness. Such incidents have proved their potential to impact economic activity, financial stability and people’s lives.  </p>
407		  
408		  
409		  
410		  
411		  
412		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">"The proposal will have an immense impact on the cybersecurity in the Union as it
413tackles number of areas such as the needed reinforcement of the European Union
414Agency for Cybersecurity, strengthens the support for the implementation of the EU
415law, introduces reforms for smooth implementation of the European certification
416framework, supports the Union’s joint understanding of the cyber threats and
417addresses the mitigation of cybersecurity risks according to the geopolitical reality."</p>
418		  
419		 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The framework will also address <b>non technical risks in sectors of high criticality </b>and other critical sectors as referred in Directive (EU) 2022/2555. </p>
420		  
421		<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">CSA-2 will strengthen, operationalise, and simplify NIS 2.</p>
422
423      
424		  
425		  
426		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The proposal for a Cybersecurity Act 2:</p>
427		  
428		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><a href="https://digital-strategy.ec.europa.eu/en/library/proposal-regulation-eu-cybersecurity-act" target="_blank">https://digital-strategy.ec.europa.eu/en/library/proposal-regulation-eu-cybersecurity-act</a></p>
429		  
430		   <hr>
431		  
432		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>21 November 2024: Assessing the impact of the current EU cybersecurity framework, and particularly the NIS 2 Directive, from the European Union Agency for Cybersecurity (ENISA).</b></p>
433		  
434		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">This report aims at providing policy makers with evidence to assess the effectiveness of the existing EU cybersecurity framework specifically through data on how the NIS Directive has
435influenced cybersecurity investments and overall maturity of organisations in scope. As 2024 is
436the year of the transposition of NIS 2, this report also intends to capture a pre-implementation
437snapshot of the relevant metrics for new sectors and entities in scope of NIS 2 to help
438future assessments of the impact of NIS 2.</p>
439		  
440		  
441
442		  
443		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Information security now represents 9% of EU IT investments, a significant increase of 1.9 percentage points from 2022, marking the second consecutive year of growth in cybersecurity investment post-pandemic. </p>
444		  
445		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The report provides insights into the readiness of entities to comply with new requirements introduced by key horizontal (e.g. CRA) and sectorial (e.g. DORA, NCCS) legislation, while also exploring the challenges they face. </p>
446		  
447		  
448		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The report:</p>
449		  
450		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><a href="https://www.enisa.europa.eu/publications/nis-investments-2024" target="_blank">https://www.enisa.europa.eu/publications/nis-investments-2024</a></p>
451		  
452		  
453		  
454		<hr>
455		  
456		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>Confusion and questions after the new EU Cyber Solidarity Act (Regulation (EU) 2025/38). </b></p>
457		  
458		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b> Must we comply with the Cyber Solidarity Act, NIS 2, DORA, or the Cyber Resilience Act?    </b></p>
459		  
460		<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">While the EU has been steadily strengthening its cybersecurity posture through regulations like  <b>NIS 2, DORA, and the Cyber Resilience Act,  </b>the Cyber Solidarity Act serves a different purpose: The collective preparedness, rapid response, and pan-European cyber defense capabilities. This is a new dimension in collective cyber resilience.</p>
461		  
462		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Despite the existing cybersecurity regulations,  <b>the EU identified a gap  </b>in real-time incident response, cross-border solidarity, and coordinated cyber defense. The Cyber Solidarity Act fills this gap. This Act reflects a new era of collective defense in cyberspace, ensuring that cyberattacks are not just a national problem but an EU-wide responsibility.</p>
463
464<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> <b>The NIS 2 Directive (Directive (EU) 2022/2555)  </b>is the EU’s baseline framework for cybersecurity risk management and incident reporting for essential and important entities. It expands the scope of the original NIS Directive, making cybersecurity obligations mandatory for a broader range of sectors.</p>
465		  
466<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The  <b>key difference  </b>is that while NIS 2 imposes cybersecurity obligations on essential and important entities, the Cyber Solidarity Act establishes EU-wide cyber emergency response and preparedness mechanisms. Unlike NIS 2, which requires organizations to implement cybersecurity risk management and report incidents, the Cyber Solidarity Act focuses on operational response at the EU level through initiatives like the Cybersecurity Emergency Mechanism and the EU Cybersecurity Reserve.</p>
467
468<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The Cyber Solidarity Act creates a European Cybersecurity Alert System for real-time monitoring and intelligence sharing, something that NIS 2 does not mandate. While NIS 2 promotes cooperation, it focuses on compliance within organizations, whereas the Cyber Solidarity Act enhances cross-border solidarity, ensuring that EU nations can assist each other in case of large-scale cyber incidents.		  </p>
469
470
471<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> <b>The Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) </b> is specifically tailored to the financial sector, aiming to enhance ICT risk management for banks, insurance companies, and investment firms. It establishes strict cybersecurity and resilience requirements for financial institutions, as well as reporting and testing obligations for third-party ICT service providers.</p>
472
473<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> <b>Unlike DORA,  </b>which applies only to financial institutions, the Cyber Solidarity Act extends to all sectors, providing a structured, EU-wide emergency response framework. While DORA mandates individual firms to secure their operations and report incidents, the Cyber Solidarity Act builds a collective crisis management structure that mobilizes resources across the EU in case of a large-scale attack.</p>
474
475<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Another key difference is in threat intelligence sharing. DORA introduces sector-specific risk-sharing measures for financial institutions, whereas the Cyber Solidarity Act establishes a real-time European Cybersecurity Alert System that benef
475its all industries and member states. Furthermore, while DORA imposes strict regulatory enforcement, the Cyber Solidarity Act primarily facilitates support mechanisms, ensuring that member states can assist each other during crises.		  </p>
476		  
477		  
478		  
479<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> <b>The Cyber Resilience Act (Regulation (EU) 2024/2847)  </b>aims to ensure that digital products, including hardware and software, meet minimum cybersecurity requirements. It focuses on product security rather than operational response.</p>
480
481<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> <b>The fundamental difference  </b>is that the Cyber Resilience Act is preventive, setting security-by-design obligations for manufacturers of digital products, while the Cyber Solidarity Act is dealing with large-scale cyberattacks and emergency response. The Cyber Resilience Act ensures that connected devices, software, and IoT products are more secure, while the Cyber Solidarity Act establishes mechanisms to mitigate and respond to major cybersecurity crises. The Cyber Solidarity Act is about crisis response and operational cooperation.</p>
482
483
484<br>
485	 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b> Lex Specialis (special law) vs. Lex Generalis (general law) in EU Cybersecurity Law.    </b></p>	  
486		  
487		  
488
489<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">In EU law, the principle of <b>lex specialis derogat legi generali </b> means that when two legal norms apply to the same situation, <b>the more specific rule takes precedence over the general rule.</b> A law is considered lex specialis if it narrows down the scope of a broader regulation by introducing more precise rules for particular situations.</p>	
490
491<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Applying this principle to the Cyber Solidarity Act, we must assess whether it introduces more specific rules that override or take precedence over existing cybersecurity laws.</p>	
492
493<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>Cyber Solidarity Act vs. NIS 2 Directive</b></p>	
494
495<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The Cyber Solidarity Act is lex specialis in relation to NIS 2 because it introduces specific emergency response mechanisms that NIS 2 lacks. While NIS 2 mandates that organizations manage their own cybersecurity risks and report incidents, the Cyber Solidarity Act creates an operational response framework at the EU level, including the Cybersecurity Emergency Mechanism, the EU Cybersecurity Reserve, and the European Cybersecurity Alert System.</p>	
496		  
497<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Since these provisions go beyond NIS 2’s risk management and compliance approach, the Cyber Solidarity Act takes precedence in matters of large-scale cyber incident response, making it a lex specialis for cybersecurity emergency management.</p>	
498
499<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b> Cyber Solidarity Act vs. Digital Operational Resilience Act (DORA)</b></p>	
500		  
501<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The Cyber Solidarity Act is not lex specialis in relation to DORA, because DORA remains sector-specific, while the Cyber Solidarity Act applies across all industries and governments. DORA mandates individual risk management and resilience measures for financial institutions, whereas the Cyber Solidarity Act provides a collective EU response framework. DORA remains lex specialis for financial sector cybersecurity, and the Cyber Solidarity Act is complementary rather than overriding.</p>	
502
503<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>Cyber Solidarity Act vs. Cyber Resilience Act.</b></p>	
504		  
505<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The Cyber Solidarity Act is not lex specialis in relation to the Cyber Resilience Act because these regulations cover entirely different domains: The Cyber Resilience Act governs product security and software integrity. The Cyber Solidarity Act focuses on operational cybersecurity, crisis response, and collective EU defense mechanisms.</p>	
506		  
507<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Since there is no direct conflict between these two laws, the Cyber Resilience Act remains lex specialis for digital product security, while the Cyber Solidarity Act remains lex specialis for cyber crisis response.		  </p>	
508		  
509		  
510		  
511		  
512		  
513		  
514
515		  
516		  
517		  
518		  <hr>
519		  
520		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>7 November 2024: Commission Implementing Regulation (EU) 2024/2690 of 17 October is published at the Official Journal of the European Union</b></p>
521		  
522		  
523		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>Full name: </b>COMMISSION IMPLEMENTING REGULATION (EU) 2024/2690 of 17 October 2024 laying down rules for the application of Directive (EU) 2022/2555 as regards technical and methodological requirements of cybersecurity risk-management measures and further specification of the cases in which <b>an incident is considered to be significant </b>with regard to DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, providers of online market places, of online search engines and of social networking services platforms, and trust service providers.</p>
524		  
525		  
526		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">According to <b>Article 1 (Subject matter), </b>this Regulation, with regard to DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, providers of online market places, of online search engines and of social networking services platforms, and trust service providers (the relevant entities) lays down the technical and the methodological requirements of the measures referred to in Article 21(2) of Directive (EU) 2022/2555 and <b>further specifies the cases in which an incident shall be considered to be significant </b>as referred to in Article 23(3) of Directive (EU) 2022/2555.</p>
527		  
528		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">According to <b>Article 16 (Entry into force and application),</b> this Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.</p>
529		  
530		  
531		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The official text:</p>
532		  
533		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><a href="https://eur-lex.europa.eu/eli/reg_impl/2024/2690/oj" target="_blank">https://eur-lex.europa.eu/eli/reg_impl/2024/2690/oj</a></p>
534		  
535		  
536		  <br>
537		  
538		  
539		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>7 November 2024: ENISA is inviting industry stakeholders to provide comments on Commission Implementing Regulation (EU) 2024/2690 of 17 October</b></p>
540		  
541		  
542		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">ENISA is developing technical guidance to support EU Member States and entities with the implementation of the technical and methodological requirements of the NIS 2 cybersecurity risk-management measures outlined in the Commission Implementing Regulation (EU) 2024/2690 of 17.10.2024.  </p>
543
544<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">ENISA develops this technical guidance to provide: </p>
545
546<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> - Additional advice and tips on what to consider when implementing a requirement and further explanation about concepts and terms used in the legal text;  </p>
547	
548<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> - Examples of evidence, which could be used to asses if a requirement has been met;  </p>
549	
550<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> - Tables, mapping the security requirements in the Implementing Regulation to European and international standards, as well as national frameworks. </p>
551	
552<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The draft of the technical guidance is now available for industry consultation: </p>
553		  
554		<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><a href="https://www.enisa.europa.eu/publications/implementation-guidance-on-nis-2-security-measures" target="_blank">https://www.enisa.europa.eu/publications/implementation-guidance-on-nis-2-security-measures</a></p>  
555		  
556		  <hr>
557		  
558		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>17 October 2024: The Commission adopted the first implementing regulation on NIS 2 Directive. </b></p>
559		  
560		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The implementing regulation will apply to specific categories of companies providing digital services, such as cloud computing service providers, data centre service providers, online marketplaces, online search engines and social networking platforms, to name a few. For each category of service providers, the implementing act also specifies when an incident is considered significant.</p>
561		  
562		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The full name is:</p>
563			  
564			  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">COMMISSION IMPLEMENTING REGULATION (EU) of 17.10.2024 laying down rules for the application of Directive (EU) 2022/2555 as regards technical and methodological requirements of cybersecurity risk-management measures and further specification of the cases in which an incident is considered to be significant with regard to DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, providers of online market places, of online search engines and of social networking services platforms, and trust service providers.</p>
565
566<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>Next Steps: </b> The implementing regulation will be published in the Official Journal in due course and enter into force 20 days thereafter.</p>
567		  
568		  
569		  
570		 
571		  
572	 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><a href="https://digital-strategy.ec.europa.eu/en/library/nis2-commission-implementing-regulation " target="_blank">https://digital-strategy.ec.europa.eu/en/library/nis2-commission-implementing-regulation</a></p>		  
573
574
575<hr>
576		  
577		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>17 October 2024: NIS 2 Directive, Deadline for EU Member States</b></p>
578		  
579		  
580<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Under Article 41 (Transposition) of the NIS 2 Directive, by 17 October 2024, all EU Member States are required to adopt and publish the national measures necessary to ensure compliance with the directive. These measures are critical for aligning national legislation with the enhanced cybersecurity requirements introduced by NIS 2.</p>
581
582<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Following the adoption, these measures must be enforced starting from 18 October 2024, marking the beginning of a new era in cybersecurity across the EU.</p>
583
584<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Many Member States have faced delays in transposing the directive into national law. This has raised concerns about the uniform implementation of the directive’s provisions and the readiness of essential and important sectors to comply with enhanced cybersecurity requirements.</p>
585
586
587		  
588		  
589		   <hr>
590		  
591		 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>December 2022 - the NIS 2 Directive was published in the Official Journal of the European Union as Directive (EU) 2022/2555. </b></p>
592		  
593		<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> <b>Full name: </b>The full name is "Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive)".</p>
594		  
595		  <br>
596		  
597		 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> <b> Which is correct? NIS 2 or NIS2?</b></p>
598		  
599		<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">  <b>NIS 2 </b>is the correct name, as this is the name published at the Official Journal of the European Union.</p>
600		  
601		  <br>
602		  
603		  <img src="NIS2_or_NIS_2.JPG" alt="NIS 2 or NIS2?" width="885" height="314" class="img-responsive">
604		  
605		  
606		  
607		  <br>
608		  
609		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">  The name NIS2 has also been used in official documents.</p>
610		  
611		  
612		   <br>
613		  
614	    <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> <b>Deadlines: </b> By <b>17 October 2024,</b> Member States must adopt and publish the measures necessary to comply with the NIS 2 Directive. </p>
615
616        <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">  They shall apply those measures from <b>18 October 2024.</b></p>
617		  
618		 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> Directive (EU) 2016/1148 (the NIS Directive) is repealed with effect from <b> 18 October 2024.</b></p>
619		  
620		  
621
622<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">By <b>17 July 2024 </b>and every 18 months thereafter, EU-CyCLONe shall submit to the European Parliament and to the Council a report assessing its work.</p>
623
624
625
626<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">By <b>17 October 2024, </b>the Commission shall adopt implementing acts laying down the technical and the methodological requirements of the measures with regard to DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, providers of online market places, of online search engines and of social networking services platforms, and trust service providers.</p>
627
628
629<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
629The Cooperation Group shall, on <b>17 January 2025, </b>establish, with the assistance of the Commission and ENISA, and, where relevant, the CSIRTs network, the methodology and organisational aspects of peer reviews with a view to learning from shared experiences, strengthening mutual trust, achieving a high common level of cybersecurity, as well as enhancing Member States’ cybersecurity capabilities and policies necessary to implement this Directive. Participation in peer reviews is voluntary. The peer reviews shall be carried out by cybersecurity experts. The cybersecurity experts shall be designated by at least two Member States, different from the Member State being reviewed.</p>
630
631
632
633<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">By <b>17 April 2025, </b>Member States shall establish a list of essential and important entities as well as entities providing domain name registration services. Member States shall review and, where appropriate, update that list on a regular basis and at least every two years thereafter.</p>
634
635<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">By <b>17 April 2025 </b>and every two years thereafter, the competent authorities shall notify the Commission and the Cooperation Group of the number of essential and important entities for each sector.</p>
636
637<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">By <b>17 October 2027 </b>and every 36 months thereafter, the Commission shall review the functioning of this Directive, and report to the European Parliament and to the Council. </p>
638		  
639		  <br>
640		  
641	<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>Important obligations: </b>According to Article 20 (Governance), the <b>management bodies </b>of essential and important entities must approve the cybersecurity risk-management measures taken by those entities, oversee its implementation and <b>"can be held liable for infringements."</b>
642
643    <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> According to Article 20, Member States shall ensure that the <b>"members of the management bodies of essential and important entities are required to follow training," </b>and shall encourage essential and important entities to offer similar training to their employees on a regular basis, in order that they gain sufficient knowledge and skills to enable them to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the entity.</p>
644
645<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> According to Article 21 (Cybersecurity risk-management measures), essential and important entities must take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services, and to prevent or minimise the impact of incidents on recipients of their services and on other services.</p>
646
647<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> Taking into account the <b>"state-of-the-art" </b>and, where applicable, relevant European and international standards, as well as the cost of implementation, the measures referred shall ensure a level of security of network and information systems appropriate to the risks posed. When assessing the proportionality of those measures, due account shall be taken of the degree of the entity’s exposure to risks, the entity’s size and the likelihood of occurrence of incidents and their severity, including their societal and economic impact.</p>
648
649<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> The measures shall be based on an <b>"all-hazards approach"</b> that aims to protect network and information systems and the physical environment of those systems from incidents, and shall include <b>"at least" </b>the following:</p>
650
651<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> (a) policies on risk analysis and information system security;</p>
652
653<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> (b) incident handling;</p>
654
655<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> (c) business continuity, such as backup management and disaster recovery, and crisis management;</p>
656
657<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
657 (d) supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers;</p>
658
659<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> (e) security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure;</p>
660
661<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> (f) policies and procedures to assess the effectiveness of cybersecurity risk-management measures;</p>
662
663<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> (g) basic cyber hygiene practices and cybersecurity training;</p>
664
665<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> (h) policies and procedures regarding the use of cryptography and, where appropriate, encryption;</p>
666
667<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> (i) human resources security, access control policies and asset management;</p>
668
669<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> (j) the use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the entity, where appropriate.</p>
670		  
671		   <br>
672		  
673		  
674	<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>Important note for Non-EU entities:</b> Under Article 26 (Jurisdiction and territoriality), if an entity referred to in paragraph 26.1.(b) ("DNS service providers, TLD name registries, entities providing domain name registration services, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, as well as providers of online marketplaces, of online search engines or of social networking services platforms") is <b>not established in the EU, but offers services within the EU, </b>it shall designate a representative in the EU. The representative shall be established in one of those Member States where the services are offered. Such an entity shall be considered to fall under the jurisdiction of the Member State where the representative is established. In the <b>absence</b> of a representative, <b>any Member State in which the entity provides services may take legal actions against the entity for the infringement </b>of this Directive.	 </p>
675		
676		
677		 <hr>
678		
679		
680	<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>July 24, 2024 – The first report on the cybersecurity and resilience of Europe’s telecommunications and electricity sectors. </b></p>	
681		
682		<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
682The Council, in its Conclusions on the development of the European Union’s cyber posture of 23 May 2022, invited the Commission, the High Representative and the <b>NIS Cooperation Group, </b>in coordination with relevant civilian and military bodies and agencies and established networks, including the <b>EU CyCLONe, </b>to conduct a risk evaluation and build <b>risk scenarios from a cybersecurity perspective </b>in a situation of threat or possible attack against Member States or partner countries and present them to the relevant Council bodies.</p>
683		
684		
685		<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The report puts forward a number of recommendations across 4 areas for improvement, including the recommendation that Member States conduct further self-assessments for the sectors as per the <b>NIS 2 Directive and CER Directive.</b></p>
686		
687		<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The scenarios are very interesting, in a Europe that is preparing for hybrid warfare. Below we can read one of these scenarios in the report:</p>
688
689<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>Risk Scenario</b></p>
690		
691<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>Context</b></p>
692	
693<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">In the context of ongoing military operations, a state sponsored cyberwarfare group is engaged in
694the delivery of targeted simultaneous attacks against several power plants connected on a
695country’s power grid leveraging a recently developed wiper and a range of zero-days
696vulnerabilities and backdoors in wind turbines, solar panels and electric cars.</p>
697		
698<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>Technical</b></p>
699	
700<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The cyberwarfare group was able to leverage a zero-day vulnerability in a product used by multiple
701power plants in the EU to gain foothold to their IT environments. From there, the group leveraged
702the lack of adequate IT/OT network segregation wherever applicable, to move laterally to OT
703networks where it deployed its custom-made wiper malware. </p>
704		
705		<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">At the same time, the well-resourced group exacerbates the attack by targeting back-up options.</p>
706			
707<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">At first, all wind turbines are being shut off during windy conditions by leveraging a backdoor in a
708critical component that was manufactured in a third country that (indirectly) supports the
709cyberwarfare group’s cause. The same then happens for solar panels produced within the third
710country. Finally, some electric cars start drawing more from the grid than they should, further
711increasing the load on the grid.</p>
712	
713	
714<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>Impact</b></p>
715	
716	
717<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">As a result of the activity of the wiper on the affected power plants, several OT systems are
718rendered unavailable. This keeps much of the generation off-the-grid, thus impacting the
719management and operation of the energy system by the transmission network operator of the
720country. This results in forced rolling blackouts which are worsened by the unavailability of backup
721generation from wind farms.</p>
722	
723<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The resetting and commissioning of the affected OT systems lasts up to two weeks, by when the
724situation is fully back to normal. Additionally, though most or all Member States were affected,
725those who are heavily dependent on wind or solar energy as a secondary source might have to
726request support from other Member States while they are dealing with their own situation. This
727requires effective cooperation at EU level.</p>
728	
729<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The rolling blackouts may also cause additional multi-sectoral cascading effects and potentially
730black starts in several countries. Public rail and road systems (e.g., bus and rail schedules, train
731operations, signalling systems or track switches) that are successfully disrupted, would be in some
732cases paralysed. Public administration would likely cease most of its operations for the days of
733the total blackout, except for emergency services. </p>
734	
735	<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The impact of the power outages on the health
736system would be far-reaching and result in an increased need for emergency care. With limited
737power and reliance on generators, hospital services are immediately reduced and healthcare
738facilities are often not able to provide basic services. Payment systems would also be severely
739affected, with significant consequences for the retail sector where particularly access to food could
740pose a major problem.</p>
741
742		
743		
744		
745		 <hr>
746		
747		
748		
749		
750		 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>July 12, 2024 – The Artificial Intelligence Act was published in the Official Journal of the European Union. </b></p>
751		
752		
753
754 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>The AI Act is very important for experts implementing the NIS 2 Directive and the Critical Entities Resilience Directive (CER, Directive (EU) 2022/2557).</b></p>
755	 
756 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">According to Article 9.10 of the AI Act: “For providers of high-risk AI systems that are subject to requirements regarding internal risk management processes <b>under other relevant provisions of Union law, </b>the aspects provided in paragraphs 1 to 9 may be part of, or combined with, the risk management procedures established pursuant to that law.”</p>
757	 
758	 <br>
759
760 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>NIS 2 and the AI Act, common implementation examples:</b></p>
761
762 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>a. Risk Management. </b> NIS 2 emphasizes risk management processes, requiring organizations to implement measures to prevent and mitigate cybersecurity incidents. The AI Act focuses on risk management for AI systems, including cybersecurity, testing, documentation, and mitigation strategies.</p>
763	 
764	 
765<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>b. Incident Reporting and Response. </b>NIS 2 requires entities to report significant cybersecurity incidents within 24 hours. The AI Act includes provisions for monitoring and reporting cybersecurity incidents related to AI systems. </p>
766
767 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>c. Governance and Accountability. </b>NIS 2 establishes clear responsibilities for senior management in ensuring compliance with cybersecurity measures and reporting. The AI Act asks for robust governance frameworks, including accountability mechanisms and documentation practices to demonstrate compliance.</p>
768
769 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>d. Data Protection and Security. </b>NIS 2 stresses the importance of securing network and information systems to protect data integrity, availability, and confidentiality. The AI Act requires high-risk AI systems to incorporate measures ensuring data quality and data governance.</p>
770
771 	 
772	 <br>
773	 
774	 
775	<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>
775 Is data poisoning (as described in the Artificial Intelligence Act) an important challenge for experts implementing the NIS 2 Directive too?</b></p>
776	 
777	 
778<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Data poisoning is a form of attack on machine learning (ML) systems where  adversaries intentionally manipulate the training data to influence a model's behavior.</p>
779	
780<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Backdoor Attacks are data poisoning attacks where adversaries manipulate the training data to embed a hidden backdoor within the model. This backdoor remains dormant during normal operations but activates in the presence of a specific trigger, leading to malicious behavior. </p>
781	
782	<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>Example 1: AI-based spam filters </b>are advanced systems designed to detect and block unwanted email messages, using artificial intelligence and machine learning techniques. These filters analyze various attributes and patterns within emails to determine their likelihood of being spam or unwanted. By poisoning the training data of spam filters and introducing specific words or patterns as safe, adversaries can bypass detection and conduct phishing attacks or deliver malware. </p>
783		
784		
785		
786<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>Example 2: AI-based Intrusion Detection Systems (IDS) </b>are designed to identify and respond to potential security threats within a network by analyzing data and recognizing patterns indicative of malicious activities. If an AI-based IDS is trained with mislabeled data (poisoned data), and actual threats are labeled as safe, the IDS would fail to detect and alert on real attacks, allowing cybercriminals to bypass defenses.</p>
787	 
788	<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>Example 3: AI-based surveillance systems </b> utilize AI and machine learning technologies to monitor, analyze, and interpret data from various sensors and cameras. These systems are designed to detect and respond to potential security threats in real-time by automatically recognizing patterns, identifying anomalies, and alerting security personnel to suspicious activities.</p>
789		
790		<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">In AI data poisoning attacks, adversaries alter sensor data in AI-based surveillance systems to hide certain activities. Data poisoning corrupts the learning process of machine learning models by introducing poisoned data during the training phase. This causes the models to learn incorrect patterns, leading to faulty decision-making during real-time surveillance. By disabling alerts when certain patterns are detected, attackers can bypass systems and exfiltrate data without raising alarms.</p>
791	 
792		
793	<br>
794	 
795	
796	<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">In cases where <b>AI systems are used in sectors covered by NIS 2 </b>(e.g., healthcare, energy etc.), entities must comply with both, NIS 2 and the AI Act. They must leverage cybersecurity measures to support AI risk management and vice versa. These entities need a holistic approach to compliance, integrating cybersecurity and AI risk management practices. </p>
797	
798<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">We have developed the Artificial Intelligence Act Trained Professional (AIActTPro) program. You can find all the details about the program at: <a href=" https://www.artificial-intelligence-act.com/Artificial_Intelligence_Act_Trained_Professional_(AIActTPro).html" target="_blank"> https://www.artificial-intelligence-act.com/Artificial_Intelligence_Act_Trained_Professional_(AIActTPro).html </a>. </p>		
799
800
801		
802		
803		 <hr>
804		  
805			
806		<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>16 April 2024 – The European Systemic Risk Board (ESRB) published the paper “Advancing macroprudential tools for cyber resilience – Operational policy tools, April 2024.” </b></p>
807			
808<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">According to the paper, the pan-European systemic cyber incident coordination framework (EU-SCICF) should build on the Digital Operational Resilience Act (DORA) for the financial sector and should complement existing frameworks (e.g. financial and cyber incident) as well as the Network and Information Security (NIS2) Directive and the Resilience of Critical Entities Directive (CER). </p>
809	
810<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Read the paper at: 
811	<a href="https://www.esrb.europa.eu/pub/pdf/reports/esrb.report202404_advancingmacroprudentialtools~ca44cf0c8a.en.pdf?a59d39c66e7046ba099e5119d79cb3ea" target="_blank" >Advancing macroprudential tools for cyber resilience – Operational policy tools, April 2024</a></p>
812		  
813		  <br>
814		  
815		  <img src="NIS2_DORA_CER.JPG" alt="NIS2 DORA CER" width="603" height="322" class="img-responsive">
816		  
817		  <br>
818
819		  
820		  
821
822		
823		
824		
825		<hr>
826		
827<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>18 September 2023 - Commission Guidelines about the relationship between the NIS 2 Directive and the Digital Operational Resilience Act (DORA).</b></p>
828
829
830<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The Commission Guidelines on the application of Article 4 (1) and (2) of the NIS 2 Directive, that was published at the Official Journal of the European Union the 18th of September 2023, covers some of the major areas of concern for entities that try to understand if they must comply with the NIS 2 Directive, or the Digital Operational Resilience Act (DORA) and other <b>sector-specific </b>Union legal acts.</p>
831
832<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Article 4(1) of the NIS 2 Directive provides that, where <b>sector-specific </b>Union legal acts (like DORA, that applies in the financial sector) require essential or important entities to adopt cybersecurity risk-management measures or to notify significant incidents, and where those requirements are at least equivalent in effect to the obligations laid down in the NIS 2 Directive, the relevant provisions of the NIS 2 Directive shall <b>not apply </b>to such entities. The sector-specific provisions will apply.</p>
833
834<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">That provision further provides that where <b>sector-specific </b>Union legal acts <b> do not cover all entities in a specific sector </b>falling within the scope of the NIS 2 Directive, the relevant provisions of the NIS 2 Directive shall continue to apply to the entities not covered by those sector-specific Union legal acts. </p>
835
836<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Article 4(2)(a) of the NIS 2 Directive provides that cybersecurity risk-management measures that essential or important entities are required to adopt under <b>sector-specific </b> Union legal acts shall be considered to be equivalent in effect to the obligations laid down in the NIS 2 Directive, where those measure are at least equivalent in effect to those laid down in Article 21(1) and (2) of the NIS 2 Directive. </p>
837
838<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">When assessing whether the requirements in a sector-specific Union legal act on cybersecurity risk-management measures are at least equivalent in effect to those laid down in Article 21(1) and (2) of the NIS 2 Directive, the requirements in that sector-specific Union legal act should, at a minimum, correspond to the requirements of those provisions or go beyond them, meaning that the sector-specific provisions may be more granular on substance compared to the corresponding provisions of the NIS 2 Directive.</p>
839
840<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">An important consideration when assessing the equivalence of a sector-specific Union legal act with the requirements of Article 21(1) and (2) of the NIS 2 Directive is that the cybersecurity risk-management measures required by the sector-specific Union legal act should be based on an <b>‘all-hazard approach’. </b></p>
841
842<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Since threats to the security of network and information systems could have different origins, <b>any type of event </b>can have a negative impact on the network information systems of the entity and potentially lead to an incident. Therefore, the cybersecurity risk-management measures taken by the entity should protect not only the entity’s network and information systems, but also the <b>physical environment </b>of those systems from any event such as <b>sabotage, theft, fire, flood, telecommunication or power failures, or unauthorised physical access </b>that are capable of compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems. </p>
843
844<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Consequently, the cybersecurity risk-management measures required by a <b>sector-specific </b>Union legal act should specifically address the physical and environmental security of network and information systems from systems failure, human error, malicious acts, or natural phenomena.</p>
845
846<br>
847
848
849
850<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>NIS 2 and DORA.</b></p>
851		
852<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
852The Commission Guidelines about the relationship between the NIS 2 Directive and the Digital Operational Resilience Act (DORA) of 18 September 2023, further explain the following in the Appendix:</p>		
853
854<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Article 1(2) of DORA provides that, in relation to financial entities covered by the NIS 2 Directive and its corresponding national transposition rules, <b>DORA shall be considered a sector-specific </b>Union legal act for the purposes of Article 4 of the NIS 2 Directive.  </p>
855
856<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">This statement is mirrored in recital (28) of the preamble to the NIS 2 Directive, which says that DORA should be considered a sector-specific Union legal act in relation to the NIS 2 Directive with regard to financial entities. </p>
857
858<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Consequently, <b>the provisions of DORA </b>relating to information and communication technology (ICT) risk management (Article 6 et seq.), management of ICT-related incidents and, in particular, major ICT-related incident reporting (Article 17 et seq.), as well as on digital operational resilience testing, (Art 24 et seq.) information-sharing arrangements (Article 25) and ICT third-party risk (Article 28 et seq.) <b>shall apply instead of those provided for in the NIS 2 Directive. </b></p>
859
860<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Member States <b>should therefore not apply </b>the provisions of the NIS 2 Directive on cybersecurity risk-management and reporting obligations, and supervision and enforcement, <b>to financial entities covered by DORA.</b></p>
861
862
863		  
864		  
865		  
866		  
867		  <hr>
868		  
869		 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>November 28, 2022 - the Council adopts the NIS 2 Directive.  </b></p>
870
871<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The NIS 2 Directive replaces and repeals the NIS Directive (Directive 2016/1148/EC). NIS 2 will improve cybersecurity risk management and will introduce reporting obligations across sectors such as energy, transport, health and digital infrastructure.</p>  
872		  
873		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>Next step: </b>The directive will be published in the Official Journal of the European Union in the coming days, and will enter into force on the twentieth day following this publication.</p>
874
875<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Member states must incorporate the provisions of the NIS 2 Directive into national law in <b>21 months</b> from the entry into force of the directive. </p>
876		  
877		  
878		  
879		  
880		  
881		   <hr>
882		  
883		<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>November 10, 2022 - the European Parliament adopts the NIS 2 Directive.  </b></p>
884
885<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The NIS 2 Directive replaces and repeals the NIS Directive (Directive 2016/1148/EC).</p>  
886		  
887		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>Next step:</b> The Council of the European Union must formally adopt the text of the NIS 2 Directive.</p> 
888			  
889			  
890			  
891		  
892		  
893		  
894		  
895		  <hr>
896		  
897		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>May 13, 2022 - Strengthening EU-wide cybersecurity and resilience – provisional agreement by the Council and the European Parliament</b></p>
898
899<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
899The Council and the European Parliament agreed on measures for a high common level of cybersecurity across the Union, to further improve the resilience and incident response capacities of both the public and private sector and the EU as a whole.</p>
900
901<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Once adopted, the new directive, called ‘NIS2’, will replace the current directive on security of network and information systems (the NIS directive).</p>
902
903<br>
904
905<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>Stronger risk and incident management and cooperation</b></p>
906
907
908
909<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">NIS2 will set the baseline for cybersecurity risk management measures and reporting obligations across all sectors that are covered by the directive, such as energy, transport, health and digital infrastructure.</p>
910
911<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The revised directive aims to remove divergences in cybersecurity requirements and in implementation of cybersecurity measures in different member states. To achieve this, it sets out minimum rules for a regulatory framework and lays down mechanisms for effective cooperation among relevant authorities in each member state. It updates the list of sectors and activities subject to cybersecurity obligations, and provides for remedies and sanctions to ensure enforcement.</p>
912
913<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The directive will formally establish the European Cyber Crises Liaison Organisation Network, EU-CyCLONe, which will support the coordinated management of large-scale cybersecurity incidents.</p>
914
915<br>
916
917<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>Widening of the scope of the rules</b></p>
918
919
920
921<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">While under the old NIS directive member states were responsible for determining which entities would meet the criteria to qualify as operators of essential services, the new NIS2 directive introduces a size-cap rule. This means that all medium-sized and large entities operating within the sectors or providing services covered by the directive will fall within its scope.</p>
922
923<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">While the agreement between the European Parliament and the Council maintains this general rule, the provisionally agreed text includes additional provisions to ensure proportionality, a higher level of risk management and clear-cut criticality criteria for determining the entities covered.</p>
924
925<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The text also clarifies that the directive will not apply to entities carrying out activities in areas such as defence or national security, public security, law enforcement and the judiciary. Parliaments and central banks are also excluded from the scope.</p>
926
927<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">As public administrations are also often targets of cyberattacks, NIS2 will apply to public administration entities at central and regional level. In addition, member states may decide that it applies to such entities at  local level too.</p>
928
929
930<br>
931
932<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>Other changes introduced by the co-legislators</b></p>
933
934
935
936<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The European Parliament and the Council have aligned the text with sector-specific legislation, in particular the regulation on digital operational resilience for the financial sector (DORA) and the directive on the resilience of critical entities (CER), to provide legal clarity and ensure coherence between NIS2 and these acts.</p>
937
938<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">A voluntary peer-learning mechanism will increase mutual trust and learning from good practices and experiences, thereby contributing to achieving a high common level of cybersecurity.</p>
939
940<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The two co-legislators have also streamlined the reporting obligations in order to avoid causing over-reporting and creating an excessive burden on the entities covered.</p>
941
942<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Member states will have 21 months from the entry into force of the directive in 
942which to incorporate the provisions into their national law.</p>
943
944<br>
945
946<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>Next steps</b></p>
947
948
949
950<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The provisional agreement concluded today is now subject to approval by the Council and the European Parliament.</p>
951
952<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">On the Council’s side, the French presidency intends to submit the agreement to the Council’s Permanent Representatives Committee for approval soon.</p>
953		  
954		  
955	<hr>
956		  
957		 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>A revised Directive on Security of Network and Information Systems (NIS 2 Directive).</b></p>
958		  
959		  
960	<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> 16.12.2020 - The European Commission adopted a proposal for a revised Directive on Security of Network and Information Systems (NIS 2 Directive).</p>
961
962<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
963In spite of its notable achievements, the Directive on the security of network and information systems (NIS Directive), has by now also proven its limitations. The digital transformation of society (intensified by the COVID-19 crisis) has expanded the threat landscape and is bringing about new challenges, which require adapted and innovative responses.</p>
964	
965	
966	<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
967Now any disruption, even one initially confined to one entity or one sector, can have cascading effects more broadly, potentially resulting in far-reaching and long-lasting negative impacts in the delivery of services across the whole internal market.</p>
968		
969		
970		<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
971
972To address these challenges, as announced in the Communication on Shaping Europe’s Digital Future, the Commission accelerated the Directive’s review to the end of 2020, carried out an impact assessment and presented a new legislative proposal.   </p>
973		  
974		  
975		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">This proposal is part of a package of measures to improve further the resilience and incident response capacities of public and private entities, competent authorities and the Union as a whole in the field of cybersecurity and critical infrastructure protection. It is in line with the 
976Commission’s priorities to make Europe fit for the digital age and to build a future-ready 
977economy that works for the people. </p>
978			  
979			  
980			  
981			   <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Cybersecurity is a priority in the Commission’s response 
982to the COVID-19 crisis. The package includes a new Strategy on Cybersecurity with the aim 
983of strengthening the Union’s strategic autonomy to improve its resilience and collective 
984response and to build an open and global internet. Finally, the package contains a proposal for 
985a directive on the resilience of critical operators of essential services, which aims to mitigate physical threats against such operators.</p>
986			  
987			  
988			   <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
989This proposal builds on and repeals Directive (EU) 2016/1148 on security of network and 
990information systems (NIS Directive), which is the first piece of EU-wide legislation on 
991cybersecurity and provides legal measures to boost the overall level of cybersecurity in the 
992Union. The NIS Directive has:</p>
993				   
994				   
995				    <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">(1) contributed to improving cybersecurity capabilities at 
996national level by requiring Member States to adopt national cybersecurity strategies and to 
997appoint cybersecurity authorities; </p>
998						
999						
1000						 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">(2) increased cooperation between Member States at Union 
1001level by setting up various fora facilitating the exchange of strategic and operational 
1002information; and </p>
1003							 
1004							  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">(3) improved the cyber resilience of public and private entities in seven 
1005specific sectors (energy, transport, banking, financial market infrastru
1005ctures, healthcare, 
1006drinking water supply and distribution, and digital infrastructures) and across three digital 
1007services (online marketplaces, online search engines and cloud computing services) by 
1008requiring Member States to ensure that operators of essential services and digital service 
1009providers put in place cybersecurity requirements and report incidents.</p>
1010								  
1011
1012 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">								  
1013The proposal modernises the existing legal framework taking account of the increased 
1014digitisation of the internal market in recent years and an evolving cybersecurity threat 
1015landscape. Both developments have been further amplified since the onset of the COVID-19 
1016crisis. The proposal also addresses several weaknesses that prevented the NIS Directive from 
1017unlocking its full potential.</p>
1018
1019	 
1020	 
1021	  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">Notwithstanding its notable achievements, the NIS Directive, which paved the way for a 
1022significant change in mind-set, in relation to the institutional and regulatory approach to 
1023cybersecurity in many Member States, has also proven its limitations. The digital 
1024transformation of society (intensified by the COVID-19 crisis) has expanded the threat 
1025landscape and is bringing about new challenges which require adapted and innovative 
1026responses. The number of cyber -attacks continues to rise, with increasingly sophisticated 
1027attacks coming from a wide range of sources inside and outside the EU. </p>
1028
1029		  
1030		  
1031		   <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">The evaluation on the functioning of the NIS Directive, conducted for the purposes of the 
1032Impact Assessment, identified the following issues: </p>
1033			   
1034			   
1035			    <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">(1) the low level of cyber resilience of 
1036businesses operating in the EU; </p>
1037					
1038					
1039					 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">(2) the inconsistent resilience across Member States and 
1040sectors; and </p>
1041						 
1042						 
1043						  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">(3) the low level of joint situational awareness and lack of joint crisis response. 
1044For example, certain major hospitals in a Member State do not fall within the scope of the 
1045NIS Directive and hence are not required to implement the resulting security measures, while 
1046in another Member State almost every single healthcare provider in the country is covered by 
1047the NIS security requirements.</p>
1048							  
1049							  
1050<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">							  
1051Being an initiative within the Regulatory Fitness Programme (REFIT), the proposal aims at 
1052reducing the regulatory burden for competent authorities and compliance costs for public and 
1053private entities. Most notably, this is achieved by abolishing the obligation of competent 
1054authorities to identify operators of essential services and by increasing the level of 
1055harmonisation of security and reporting requirements to facilitate regulatory compliance for 
1056entities providing cross-border services. At the same time, competent authorities will also be 
1057given a number of new tasks, including the supervision of entities in sectors so far not covered 
1058by the NIS Directive.		</p>					  
1059							  
1060							  
1061							  
1062							  
1063    
1064		  
1065		  
1066		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> 16.12.2020 - <a href="https://www.nis-2-directive.com/Proposal_for_a_directive_on_measures_for_a_high_common_level_of_cybersecurity_across_the_Union.pdf" target="_blank">The Proposal for a directive on measures for a high common level of cybersecurity across the Union, repealing Directive (EU) 2016/1148</a>   </p>
1067		  
1068		  
1069		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> 16.12.2020 - <a href="https://www.nis-2-directive.com/Annexes_to_the_Proposal_for_a_directive_on_measures_for_a_high_common_level_of_cybersecurity_across_the_Union.pdf" target="_blank">Annexes to the Proposal for a directive on measures for a high common level of cybersecurity across the Union, repealing Directive (EU) 2016/1148</a>   </p>
1070		  
1071		  
1072		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> <a href="https://www.nis-2-directive.com/European_Parliament_A_high_common_level_of_cybersecurity_in_the_EU.pdf" target="_blank">The NIS 2 Directive, European Parliament, A high common level of cybersecurity in the EU</a>   </p>
1073		  
1074		  <br>
1075		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b>European Council - Strengthening EU-wide cybersecurity and resilience.   </b></p>
1076		  
1077		  
1078		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">  NIS 2 will set the baseline for cybersecurity risk management measures and reporting obligations across all sectors that are covered by the directive, such as energy, transport, health and digital infrastructure.</p>
1079
1080		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
1081The revised directive aims to remove divergences in cybersecurity requirements and in implementation of cybersecurity measures in different member states. To achieve this, it sets out minimum rules for a regulatory framework and lays down mechanisms for effective cooperation among relevant authorities in each member state. It updates the list of sectors and activities subject to cybersecurity obligations, and provides for remedies and sanctions to ensure enforcement.</p>
1082
1083		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
1084The directive will formally establish the European Cyber Crises Liaison Organisation Network, EU-CyCLONe, which will support the coordinated management of large-scale cybersecurity incidents.  </p>
1085		  
1086		  
1087		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> While under the old NIS directive member states were responsible for determining which entities would meet the criteria to qualify as operators of essential services, the new NIS2 directive introduces a size-cap rule. This means that all medium-sized and large entities operating within the sectors or providing services covered by the directive will fall within its scope.</p>
1088
1089			  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
1090While the Council’s position maintains this general rule, it includes additional provisions to ensure proportionality, a higher level of risk management and clear-cut criticality criteria for determining the entities covered.</p>
1091
1092				  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
1093The Council text also clarifies that the directive will not apply to entities carrying out activities in areas such as defence or national security, public security, law enforcement and the judiciary. Parliaments and central banks are also excluded from the scope.</p>
1094
1095					  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
1096As public administrations are also often targets of cyberattacks, NIS2 will apply to public administration entities of central governments. In addition, member states may decide that it applies to such entities at regional and local level too.   </p>
1097		  
1098		  
1099		  <hr>
1100		  
1101		  
1102		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b> The first NIS directive, main elements.          </b>    </p>
1103		  
1104		  
1105		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> The NIS Directive provides legal measures to boost the overall level of cybersecurity in the EU, in order to contribute to the overall functioning of the internal market. It is based on 3 main pillars:</p>
1106
1107			  
1108			  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
11091. In order to achieve a high level of preparedness of Member States, the NIS Directive requires Member States to adopt a national strategy on the security of network and information systems. Member States are also required to designate national Computer Security Incident Response Teams (CSIRTs), who are responsible for risk and incident handling, a competent national NIS authority, and a single point of contact (SPOC). The SPOC has to exercise a liaison function to ensure cross-border cooperation between the Member State authorities with the relevant authorities in other Member States and with the NIS Cooperation Group.</p>
1110
1111				  
1112				  
1113				  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
11142. The NIS Directive establishes the NIS Cooperation Group to support and facilitate strategic cooperation and the exchange of information among Member States, and the CSIRTs 
1114Network, which promotes swift and effective operational cooperation between national CSIRTs.</p>
1115
1116					  
1117					  
1118					  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
11193. The NIS Directive ensures that cybersecurity measures are taken across seven sectors, which are vital for our economy and society and which rely heavily on ICT, such as energy, transport, banking, financial market infrastructures, drinking water, healthcare and digital infrastructure.</p>
1120
1121						  
1122						  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
1123Public and private entities identified by the Member States as operators of essential services (OES) in these sectors are required to undertake a cybersecurity risk assessment and put in place appropriate and proportionate security measures. They are required to notify serious incidents to the relevant authorities. And, providers of key digital services (digital service providers or DSPs), such as search engines, cloud computing services and online marketplaces, have to comply with the security and notification requirements under the Directive. At the same time, the latter are subject to a so-called ‘light-touch’ regulatory regime, which entails, among other measures, that they are under the jurisdiction of one Member State for the whole EU and are not subjected to ex-ante supervisory measures.   </p>
1124		  
1125		  <hr>
1126		  
1127		  <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"><b> The new  NIS 2 directive, main elements.          </b>    </p>
1128		
1129		
1130		 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;"> The new Commission proposal aims to address the deficiencies of the previous NIS Directive, to adapt it to the current needs and make it future-proof. </p>
1131
1132			 
1133			 
1134			 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
1135To this end, the Commission proposal expands the scope of the current NIS Directive by adding new sectors based on their how crucial they are for the economy and society, and by introducing a clear size cap — meaning that all medium and large companies in selected sectors will be included in the scope. At the same time, it leaves some flexibility for Member States to identify smaller entities with a high security risk profile. </p>
1136
1137				 
1138				 
1139				 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
1140The proposal also eliminates the distinction between operators of essential services and digital service providers. Entities would be classified based on their importance, and divided into essential and important categories, which will be subjected to different supervisory regimes. </p>
1141
1142					 
1143					 
1144					 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
1145The proposal strengthens and streamlines security and reporting requirements for companies by imposing a risk management approach, which provides a minimum list of basic security elements that have to be applied. The proposal introduces more precise provisions on the process for incident reporting, content of the reports and timelines. </p>
1146
1147						 
1148						 
1149						 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
1150Furthermore, the Commission proposes to address security of supply chains and supplier relationships by requiring individual companies to address cybersecurity risks in supply chains and supplier relationships. At European level, the proposal strengthens supply chain cybersecurity for key information and communication technologies. Member States in cooperation with the Commission and ENISA, may carry out coordinated risk assessments of critical supply chains, building on the successful approach taken in the context of the Commission Recommendation on Cybersecurity of 5G networks. </p>
1151
1152							 
1153							 
1154							 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
1155The proposal introduces more stringent supervisory measures for national authorities, stricter enforcement requirements and aims at harmonising sanctions regimes across Member States. </p>
1156
1157								 
1158								 
1159								 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
1160The proposal also enhances the role of the Cooperation Group in shaping strategic policy decisions and increases information sharing and cooperation between Member State authorities. It also enhances operational cooperation including on cyber crisis management. </p>
1161
1162									 
1163									 
1164									 <p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px;">
1165The Commission proposal also establishes a basic framework with responsible key actors on coordinated vulnerability disclosure for newly discovered vulnerabilities across the EU and creates EU registry in this area, operated by the EU agency for cybersecurity (ENISA).   </p>
1166		  
1167		  
1168		  
1169		  
1170		  
1171		  
1172		  
1173		  
1174		  <hr>
1175<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px; color: black;"><img src="George_lekatis_61.jpg" alt="George Lekatis" class="alignleft img-responsive" style="width: 150px; float: right; margin: 15px;"></p>
1176<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px; color: black;">This website is developed and maintained by Cyber Risk GmbH as part of its professional activities in the fields of risk management and regulatory compliance. </p>
1177<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px; color: black;">Cyber Risk GmbH specializes in supporting organizations in understanding, navigating, and implementing complex European, U.S., and international risk related regulatory frameworks. </p>
1178<p class="text-left" style="font-family: Georgia, 'Times New Roman', Times, serif; font-size: 18px; color: black;">Content is produced and maintained under the professional responsibility of George Lekatis, General Manager of Cyber Risk GmbH, a well known expert in risk management and compliance. He also serves as General Manager of Compliance LLC, a company incorporated in Wilmington, NC, with offices in Washington, DC, providing risk and compliance training in 58 countries. </p>
1179
1180		  
1181
1182
1183	
1184
1185<div class="container-fluid projects-wrapper">
1186  <div class="container">
1187    <div class="row">
1188      <div class="section-title">
1189		  
1190		  
1191	<h2 style="text-align: left; font-size: 25px; font-family: Georgia, 'Times New Roman', Times, serif;">Cyber Risk GmbH, some of our clients</h2>
1192	  
1193		  
1194		  
1195		  
1196        	  
1197		  <br>	 
1198<div class="logos">
1199<div class="logos-slide">
1200
1201<img src="Logos/XMA8.png" alt="" >
1202<img src="Logos/SYGNIA5.jpg" alt="" >	
1203<img src="Logos/DELL3.jpg" alt="" > 
1204<img src="Logos/VW.jpg" alt="" >
1205<img src="Logos/Bosch9.png" alt="" >	
1206<img src="Logos/Swisslife3.JPG" alt="" >
1207<img src="Logos/ATLAS8.png" alt="" >
1208<img src="Logos/INSIG8.png" alt="" >	
1209<img src="Logos/SANT8.png" alt="" >	
1210<img src="Logos/NTT38.png" alt="" >	
1211<img src="Logos/EIB15.PNG" alt="" >		  
1212<img src="Logos/SC8.JPG" alt="" >	
1213<img src="Logos/schindler.jpg" alt="" >	
1214<img src="Logos/AO9.png" alt="" >
1215<img src="Logos/GS300.JPG" alt="" >			  
1216<img src="Logos/DB8.png" alt="" >
1217<img src="Logos/TM8.png" alt="" >
1218<img src="Logos/OK8.png" alt="" >		  
1219<img src="Logos/PWC5.JPG" alt="" >	
1220<img src="Logos/Fujitsu.png" alt="" >
1221<img src="Logos/HO5.JPG" alt="" >
1222<img src="Logos/FIN22.png" alt="" >	
1223<img src="Logos/SAN8.png" alt="" >
1224<img src="Logos/BAH9.png" alt="" >		  
1225<img src="Logos/AT32.png" alt="" >	
1226<img src="Logos/WINS25.png" alt="" >		
1227<img src="Logos/SKY12.png" alt="" >
1228<img src="Logos/RB78.png" alt="" >	
1229<img src="Logos/WU8.png" alt="" >			  
1230<img src="Logos/TDC.JPG" alt="" >		  
1231<img src="Logos/BH18.png" alt="" >
1232<img src="Logos/DeepSec_Conference7.png" alt="" >	
1233<img src="Logos/DC12.png" alt="" >	
1234<img src="Logos/BROAD8.png" alt="" >
1235<img src="Logos/LEMON8.PNG" alt="" >	
1236<img src="Logos/SIK8.PNG" alt="" >	
1237<img src="Logos/KUMO8.PNG" alt="" >	
1238<img src="Logos/VEST8.PNG" alt="" >	
1239<img src="Logos/MOXA8.PNG" alt="" >		
1240<img src="Logos/TIET8.PNG" alt="" >	
1241<img src="Logos/UNI8.PNG" alt="" >	
1242<img src="Logos/BCC11.PNG" alt="" >	
1243<img src="Logos/SN8.PNG" alt="" >
1244<img src="Logos/KYN8.PNG" alt="" >
1245<img src="Logos/PG8.PNG" alt="" >
1246<img src="Logos/MER8.PNG" alt="" >	
1247<img src="Logos/LIB8.PNG" alt="" >
1248<img src="Logos/ALI8.PNG" alt="" >	
1249<img src="Logos/USA8.PNG" alt="" >
1250<img src="Logos/MAR8.PNG" alt="" >		
1251<img src="Logos/ABB8.PNG" alt="" >	
1252<img src="Logos/INSI8.PNG" alt="" >	
1253
1254
1255
1256      </div>
1257    </div>
1258    
1258<script>
1259      var copy = document.querySelector(".logos-slide").cloneNode(true);
1260      document.querySelector(".logos").appendChild(copy);
1261    </script>
1261
1262 
1263	  
1264		  
1265		  
1266		  
1267		  
1268		  
1269		  
1270		  
1271		  
1272		  
1273		  
1274		  
1275		  
1276		  
1277		  
1278		  
1279		  
1280                            
1281		  
1282		  
1283</div>
1284          </div>
1285        </div>
1286        
1287        
1288      </div>
1289    
1290  
1291
1292	
1293	
1294<div class="container-fluid projects-wrapper">
1295  <div class="container">
1296    <div class="row">
1297      <div class="section-title">
1298        
1299      </div>
1300    </div>
1301  </div>
1302</div>
1303	
1304	 
1305	
1306	
1307	
1308
1309
1310	
1311
1312<!--
1312<script src="https://ajax.googleapis.com/ajax/libs/jquery/1.12.4/jquery.min.js"></script>
1312 --> 
1313<script src="js/bootstrap.js"></script>
1313 
1314<script>
1315
1316			$(document).ready(function() {
1317              var owl = $('.cliend-logo');
1318              owl.owlCarousel({
1319                margin: 20,
1320                nav: true,
1321                loop: true,
1322				autoplay:true,
1323    autoplayTimeout:4000,
1324
1325                responsive: {
1326                  0: {
1327                    items: 1
1328                  },
1329                  600: {
1330                    items: 6
1331                  },
1332                  1000: {
1333                    items: 6
1334                  }
1335                }
1336              })
1337            })
1338			
1339		$(document).ready(function() {
1340              var owl = $('.testimonialstext');
1341              owl.owlCarousel({
1342                margin: 20,
1343                nav: true,
1344                loop: true,
1345				autoplay:true,
1346    autoplayTimeout:4000,
1347
1348                responsive: {
1349                  0: {
1350                    items: 1
1351                  },
1352                  600: {
1353                    items: 1
1354                  },
1355                  1000: {
1356                    items: 1
1357                  }
1358                }
1359              })
1360            })	
1361	
1362          </script>
1362 
1363<script>
1364 $(window).scroll(function() {
1365  if ($(document).scrollTop() > 50) {
1366    $('nav').addClass('shrink');
1367    $('.add').hide();
1368  } else {
1369    $('nav').removeClass('shrink');
1370    $('.add').show();
1371    
1372  }
1373});
1374 
1375 </script>
1375
1376</body>
1377</html>

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.