RSS FeedsTwitterDeutsche Version

NIS2 NIS 2 Directive

NIS 2 Directive – Recitals

Recitals (1–50)

1Cybersecurity capacities, essential services, continuity of services2NIS Directive, progress, need for reform3Digital transformation, cyber threats, internal market4National differences, cross-border services, harmonisation5Minimum rules, cooperation, replacement of NIS16Extended scope, sectors, entities7Scope, size-cap rule, small enterprises8Public administration, security functions, exclusions9National security, exemptions, confidential information10Nuclear energy, national security, nuclear value chain11Trust services, security functions, closed systems12Postal services, courier services, postal delivery chain13Excluded entities, cybersecurity, equivalent measures14Data protection, privacy, supervisory authorities15Essential entities, important entities, differentiated supervision16Partner enterprises, linked enterprises, independence17Existing operators of essential services, classification18List of entities, registration, contact details19Entity counts, Commission, sector-specific information20Microenterprises, small enterprises, application guidance21Complex business models, scope, proportionality22Sector-specific acts, coherence, implementing acts23Sector-specific requirements, equivalence, precedence24Incident notifications, immediate access, single entry point25Sector-specific supervision, cooperation between authorities, access to information26Significant cyber threats, voluntary notification, situational awareness27Sectoral acts, definitions, enforcement28Financial sector, DORA, sector-specific rules29Aviation, security requirements, cooperation between authorities30Critical entities, CER Directive, physical security31Digital infrastructure, physical security, CER boundary32DNS services, TLD name registries, root name servers33Cloud computing, service models, deployment models34Edge computing, distributed cloud services, emerging models35Data centre services, cloud distinction, in-house data centres36Research organisations, applied research, commercial use37Sector interdependencies, cascading effects, cross-border risks38Competent authorities, national structures, supervision39Single point of contact, cross-border cooperation40Single points of contact, forwarding notifications, cross-sector cooperation41CSIRTs, technical capacities, functional separation42CSIRT infrastructure, staffing, confidentiality43Vulnerability scans, data protection, CSIRT support44CSIRT monitoring, internet-connected assets, vulnerabilities45International CSIRT networks, third countries, data exchange46Authority resources, CSIRT funding, performance of tasks47CSIRTs network, operational cooperation, trust48Cybersecurity strategy, objectives, priorities49Cyber hygiene, basic safeguards, ENISA assessment50Awareness, connected devices, cyber hygiene

Recitals (51–100)

51Artificial intelligence, research, data protection52Open source, open standards, security through transparency53Smart cities, connected utilities, cybersecurity strategy54Ransomware, attack models, national strategy55Public-private partnerships, knowledge sharing, crisis preparedness56SMEs, support, supply chain risks57Active cyber protection, prevention, defensive measures58Vulnerability handling, coordinated disclosure, remediation59International standards, best practices, risk management60Vulnerability research, disclosure policy, liability risks61Vulnerability disclosure, CSIRT coordinator, cooperation62European vulnerability database, disclosure, mitigation63ENISA database, CVE, international repositories64Cooperation Group, strategic cooperation, work programme65Cooperation Group, guidance, national experience66Cooperation Group, stakeholders, threat landscape67Staff exchanges, authorities, CSIRTs68EU crisis framework, cooperation networks, EU-CyCLONe69Large-scale incidents, cross-border impact, crisis coordination70Cyber crises, coordinated response, resilience71EU-CyCLONe, operational coordination, political decision-making72Union-wide crisis response, civil protection, situational awareness73International agreements, third countries, data protection74Third-country cooperation, information exchange, cyber exercises75Peer reviews, mutual trust, exchange of experience76Self-assessment, national capacities, Cooperation Group77Risk-management culture, entity responsibility, risk assessment78Risk management, incident handling, human factors79All-hazards approach, physical security, access control80Cybersecurity certification, ICT products, standards81Proportionality, state of the art, implementation costs82Risk exposure, criticality, societal impact83System responsibility, in-house IT, outsourced maintenance84Digital services, Union-wide harmonisation, implementing act85Supply chain security, suppliers, contractual arrangements86Managed security services, provider selection, supplier risks87Cybersecurity service providers, penetration testing, security audits88Trade secrets, research partners, external data processing89Cyber hygiene, zero trust, staff training90Critical supply chains, coordinated risk assessment, dependencies91Supply chain assessment, technical risks, non-technical factors92Electronic communications, trust services, replacement of sectoral duties93Trust services, eIDAS, security and reporting duties94Trust service supervision, authority cooperation, joint notification95Telecom supervision, existing guidance, security requirements96Messaging services, interpersonal communications, risk-based security97Public communications networks, submarine cables, incidents98End-to-end encryption, privacy, communications security99Secure routing, interoperability, internet integrity100DNS resilience, diversified resolution, European DNS service

Recitals (101–144)

101Significant incidents, phased reporting, initial assessment102Significant incidents, reporting deadlines, final report103Service recipients, cyber threats, protective information104Communications services, security by design, user information105Voluntary threat notifications, prevention, proactive approach106Single entry point, notification formats, administrative burden107Cybercrime, law enforcement, coordination between authorities108Personal data breaches, authority cooperation, information exchange109Domain registration data, WHOIS, data quality, access110Access to domain data, legitimate access seekers, justification111Domain registration data, verification procedures, contact validation112Publication of domain data, privacy, disclosure procedures113Jurisdiction, establishment, cross-border supervision114Main establishment, digital services, competent Member State115Recursive DNS services, internet access, jurisdiction116Third-country providers, representative in the Union, offering services117ENISA registry, digital providers, registration information118Classified information, sensitive information, confidentiality119Information sharing, cyber threats, vulnerabilities120Voluntary information sharing, arrangements, cooperation121Personal data, lawful bases, security purposes122Essential and important entities, ex ante and ex post supervision123Supervisory measures, business operations, limiting disruption124Risk-based supervision, prioritisation, supervisory methodologies125Supervisory staff, expertise, objective inspections126Urgent enforcement, significant cyber threats, immediate action127Enforcement powers, proportionality, procedural safeguards128Natural persons, liability, national rules129Administrative fines, competent authorities, enforcement130Concept of undertaking, calculation of fines, public entities131Criminal penalties, ne bis in idem, national law132National penalties, effectiveness, deterrence133Suspension of authorisations, management bans, last resort134Mutual assistance, cross-border supervision, Cooperation Group135Mutual assistance requests, supervisory measures, cross-border enforcement136Data protection infringements, cooperation between supervisory authorities137Management bodies, risk management, oversight138Delegated acts, certification requirements, consultation139Implementing acts, technical requirements, notification procedures140Review of the Directive, size criteria, sectors141ENISA, additional tasks, budget resources142Subsidiarity, proportionality, Union objective143Fundamental rights, privacy, effective judicial remedy144European Data Protection Supervisor, consultation, opinion

Document version

Official Journal version of 27 December 2022