Introduction to the Networks and Information Systems 2 (NIS2) Directive
摘要
The Networks and Information Systems 2 (NIS2) Directive has been published in 2022. It is the successor of its initial version (NIS Directive) of 2016. Its objective is to achieve a high common level of cybersecurity across the European Union, with a view to improving the functioning of the internal market. The previously existing legal framework was indeed revised to better address the increased digitization and an evolving cybersecurity threat landscape. New sectors and entities have been added to the scope of the regulation to improves the resilience and incident response capacities of public and private entities, competent authorities and the European Union as a whole. For this purpose, the NIS2 Directive introduces a list of “Sectors of high criticality” including Energy, Transport, Banking, Financial Market Infrastructures, Health, Drinking Water, Waste Water, Digital Infrastructure, ICT Service Management (Business-to-Business), Public Administration and Space. A set of measures is introduced for those sectors which will be further summarized in the present chapter. Additionally, with requirements of a lesser extent, “other critical Sectors” are defined including Postal and Courier Services, Waste Management, Manufacture, production and distribution of chemicals, Production, processing and distribution of food, Manufacturing, Digital Providers and Research. The application of the NIS2 Directive is limited to public or private entities being part of the list of “Sectors of high criticality” or the list of “other critical Sectors”. The requirements of the NIS2 Directive remain on a rather high level with the obligation for EU Member States to detail the implementation on a national level. According to NIS2 Article 41, by 17 October 2024, Member States shall adopt and publish the measures necessary to comply with the NIS2 Directive.