Introduction to NIS2
understanding the nature and extent of cyber threats within the framework of the European Union (EU) is becoming increasingly crucial. As online activities grow,so does the importance of ensuring the protection of networks and information systems. The Directive on Security of Network and Information Systems (NIS Directive), now being updated (NIS2), aims to provide legal measures to boost the overall cybersecurity in the EU. The question is – are you in the scope of NIS2?
The Evolution from NIS to NIS2
Originally coming into effect in 2016, the NIS Directive was the first piece of EU-wide legislation on cybersecurity. It provided legal measures to boost the overall level of cybersecurity in the EU. However, due to the fast-evolving nature of digital threats and the realization that some sectors crucial for the economy and society were out of scope, the European Commission proposed a revised directive (NIS2) in December 2020.
Understanding the Scope of NIS2
The key element of understanding NIS2 is identifying its scope. according to the 2020 proposal,NIS2 applies to a wider range of ‘entities’. while the original NIS directive focused on operators of essential services (OES) and digital service providers (DSPs), NIS2 suggests expanding this scope to include crucial entities. The three classifications of entities in NIS2 are:
1. Essential and important entities: This incorporates sectors vital for the economy and society, including energy, transport, banking, financial market infrastructures, health sector, drinking water supply, digital infrastructure, and providers of public electronic communications networks.
2. Manufacturers, developers, and providers of certain ICT (information and Communications Technology) products, services, and processes: NIS2 brings under its ambit the digital supply chain facts, with a particular emphasis on software and hardware used in provision of vital services.
3. Medium and large-sized entities: As per the proposal, irrespective of their sector of operation, all medium and large-sized entities are under the microscope.
Entity Classification Checklist
Are you wondering whether you are within the scope of NIS2? The following questions can help you figure it out:
1. What is your business size? As per the NIS2 proposal, irrespective of your sector, all medium-sized (i.e., with 50-249 employees) and large-sized (i.e., 250 employees or more) entities fall within the scope.
2. What is your sector of operation? Entities operating in sectors deemed essential for the economy and society, such as transport, banking, health sector, digital infrastructure, etc., fall under the scope.
3. Are you a service provider? if you provide digital services, especially those linked to the essential sectors, you are considered within the scope of NIS2.
4. Are you part of the ICT chain? If you manufacture,develop or provide certain ICT-related products,services or processes,you are also in scope.
Preparing for NIS2
Compliance with NIS2 will largely focus on risk management, which requires entities to take appropriate technical and organizational measures to manage the risks that could effect the security of network and information systems. Also, entities should be aware of reporting incidents significantly impacting continuity of essential services to the relevant national authorities.
While the language in the NIS2 proposal might be broad, and the directive is still under discussion, one thing is certain – the EU is serious about strengthening cybersecurity. This indicates that entities should foster a culture of cybersecurity risk management, develop robust protocols, and ensure full compliance.
Conclusion
Staying updated with the evolving cybersecurity landscape and preparing for the new, extended scope of NIS2 are basic steps all entities, nonetheless of size or sector, should take to ensure their activities are carried out within a secure online environment. Compliance is not only about meeting regulations but also about ensuring the essential continuity of services in an evermore interconnected and digital economy and society.Are you ready for NIS2?































