From NIS to NIS 2
A major step forward in protecting networks and information systems.
What is NIS 2?
NIS 2, or Network and Information Security 2, is the new version of the European directive aimed at strengthening the security of networks and information systems within the member states of the European Union, adopted on 10 November 2022.
A. What is a directive?
First of all, it is important to stress that NIS 2 is a directive and not a regulation. A regulation is meant to be uniform across countries and applies directly as soon as it has been adopted by the Council of the EU or the European Parliament and published in the Official Journal of the EU. The purpose of a directive, on the other hand, such as NIS 2 or Network and Information Security, version 2, is to promote the harmonisation of national laws by setting out general principles and objectives, while leaving member states a certain degree of freedom in how they apply the text. Each state is free to go beyond these principles. The directive must be transposed into national law through a vote in national parliaments, within the set deadlines. (1)
B. Background: the NIS Directive and its evolution into NIS 2
- July 2016 1st NIS adoption
- End of 2020 Impact assessment for the revision of NIS (the EU's obligation to assess the directive's impact)
- November 2022 Adoption of the NIS 2 Directive
Transposition of the directive into domestic law at national level must be completed within 21 months of its entry into force.
C. Why protecting networks and information systems matters
The digital transformation of European societies and the interconnection of member states have exposed the European market to new cyber threats.
says Yves Verhoeven, Deputy Director for Strategy at ANSSI.
This increased interconnectivity means that attacks and security flaws spread faster and more widely, endangering critical infrastructure, sensitive data and information systems across the European Union.
Faced with this reality, it is imperative that member states work together to ensure:
- adequate security conditions throughout the European Union;
- the identification of common vulnerabilities;
- the sharing of information on threats;
- the implementation of effective prevention and response measures.
For example, in February 2022, the European Union suffered a cyberattack on the KA-SAT satellite network, and then accused Russia of being behind it. (2) The attack deprived businesses, public institutions and also civilians of internet access. “This unacceptable cyberattack is a further example of the irresponsible activities Russia is conducting in cyberspace, and an essential component of its illegal and unjustified invasion of Ukraine,” the EU declared. (3)
- Businesses NO INTERNET ACCESS
- Public institutions NO INTERNET ACCESS
- Civilians NO INTERNET ACCESS
To fully understand the stakes and objectives of NIS 2, it is necessary to go back to the origins of this directive and understand why NIS (Network and Information Security) was introduced in 2016.
What is the NIS Directive?
A. Objectives of NIS 1
The main objective of NIS 1, introduced in 2016, was to raise the overall level of cybersecurity and cyber resilience within the European Union (4). To achieve this, the aim was to:
- create consistency in cybersecurity across member states, making sure they are properly protected against cyber threats and can benefit from other countries' best practices;
- optimise communication and information sharing while raising their awareness, in order to strengthen the collective capacity to counter attacks;
- enable some more advanced countries to promote a culture of cybersecurity, by leading by example and highlighting the importance of taking this dimension into account.
NIS 1 was therefore a strategy of collaboration and cooperation between EU member states. Some more advanced countries played a role in promoting a culture of cybersecurity, by leading by example and highlighting the importance of taking this dimension into account.
B. Overview of the main elements of the NIS 1 Directive
When the NIS Directive was introduced, two specific sectors were covered: operators of essential services (hereinafter “OES”) and digital service providers (hereinafter “DSP”).
OES (5) are entities operating in essential sectors such as energy, transport, health, banking, financial services and critical digital infrastructure. These operators are subject to stricter security obligations because of the importance of their services to the proper functioning of society and the economy.
By contrast, DSPs (6) cover a broader range of digital services, such as online services, cloud computing services, electronic payment services, search engines, online marketplaces, etc.
DSPs are subject to security requirements proportionate to the nature and importance of the digital services they provide.
- Energy
- Transport
- Health
- Banking services
- Financial services
- Critical digital infrastructure
- Online services
- Cloud computing
- Electronic payment
- Search engines
- Online marketplaces
- etc.
The introduction of NIS (the directive on the security of network and information systems) improved and consolidated the overall level of cybersecurity across Europe by helping to:
- reduce the risk of cyberattacks;
- better protect essential infrastructure and sensitive data;
- raise awareness of the importance of cybercrime issues;
- develop greater digital sovereignty.
The consultancy Wavestone carried out a study covering the 27 countries of the European Union plus Switzerland and the United Kingdom; 79% of these states had put in place a state supervision process. In addition, the directive established common security requirements, which makes cooperation and coordination between EU member states easier and makes these standards consistent. (7)
The directive provided for the creation of three entities:
- 01 STRATEGICNIS Cooperation Group Coordination between member states and stronger strategic cooperation
- 02 OPERATIONALCSIRT network The national teams that manage and coordinate the response to cybersecurity incidents
- 03 CRISIS MANAGEMENTEU-CyCLONe Cooperation between national cybersecurity crisis management authorities 2020 · FORMALISED IN JAN. 2023
1.NIS Cooperation Group (Network and Information Security Cooperation Group)
It enables coordination between the member states of the European Union on cybersecurity. Its main objective is to strengthen strategic cooperation between member states, in order to optimise information sharing and thereby raise the overall level of cybersecurity maturity. (8)
2.CSIRT network (Computer Security Incident Response Team)
It refers to a network of the Computer Security Incident Response Teams of EU member states. These teams are responsible for managing and coordinating the response to cybersecurity incidents at national level. The CSIRT network aims to “contribute to building trust between member states and [to] promote swift and effective operational cooperation”. (9)
3.EU-CyCLONe
It is a cooperation network between the national authorities responsible for cybersecurity crisis management in EU member states, launched in 2020 and formalised in January 2023 with NIS 2. It aims to foster information sharing and situational awareness, in collaboration with the European Union Agency for Cybersecurity. (10)
The objective of these three entities is to promote cooperation, coordination and information sharing on cybersecurity between EU member states.
The fundamental reasons behind the introduction of the NIS 2 Directive
On 17 June 2022, the Council of the European Union and the European Parliament jointly published the draft revision of NIS, prompted by its limitations, which included:
- a scope that was too narrow regarding the sectors required to comply with the directive;
- countries had too much freedom in implementing the directive at national level, which led to inconsistent application across Europe.
To address these problems, NIS 2 was developed with significant improvements and a broader scope, including:
- Inclusion of new sectors and entities
- Consideration of supply chain security
- Implementation of a security policy
- Carrying out risk analyses
- Introduction of monitoring measures
- Incident and risk management
- Harmonised and stronger penalties in all member states
These measures aim to ensure better coordination, a more effective response to cybersecurity incidents and stronger protection against cyber threats. NIS 2 seeks to establish more consistent cybersecurity standards across the European Union, thereby encouraging a collaborative approach and robust protection of networks and information systems.
The NIS 2 Directive also sets out two types of penalties (11) to ensure that cybersecurity obligations are met:
1.Heavy administrative fines with set amounts
Entities that fail to meet the security obligations laid down by the directive may face substantial administrative fines. These fines are set at a significant level, reaching up to €10 million or 2% of total worldwide annual turnover for essential entities, in order to deter negligent or non-compliant behaviour, and €7 million or 1.4% of total worldwide annual turnover for important entities.
2.Management liability
This means that executives and senior managers can be held liable for cybersecurity breaches, which encourages them to pay particular attention to implementing security measures and protecting networks and information systems.
Who does the NIS 2 Directive apply to?
NIS 2 introduces new players and criteria in order to optimise this directive and strengthen European cybersecurity. The previous definitions of operators of essential services (“OES”) (12) and digital service providers (“DSP”) are replaced respectively by the terms “essential entity” (hereinafter “EE”) and “important entity” (hereinafter “IE”), in order to adapt obligations to each entity.
- Energy
- Transport
- Banking
- Financial market infrastructure
- Health
- Drinking water and waste water
- Digital infrastructure (cloud computing service providers, data centres, DNS, etc.)
- ICT service management (business-to-business)
- Public administration
- Postal services
- Waste management
- Manufacture, production and distribution of chemicals
- Production, processing and distribution of food
- Manufacture of medical devices and in vitro diagnostic medical devices
- Manufacture of computer, electronic and optical products
To fall within the scope of the NIS 2 Directive, you must be a public or private entity, provide services or operate within the European Union, and your business sector must be included in the list of EEs or IEs. In addition, you must have at least 50 employees and annual turnover of €10 million or more. (13)
- Public or private entity
- Activity within the European Union
- Sector included in the EE or IE list
- At least 50 employees
- Annual turnover ≥ €10 million
The NIS 2 Directive timeline
A. Implementation timeline of the NIS 2 Directive
The NIS 2 Directive was published in the Official Journal of the European Union on 27 December 2022, and member states have 21 months from that date to transpose the directive into their national law. The transposition deadline is therefore set for October 2024.
However, it is important to stress that this deadline concerns transposition into national law by member states, not the compliance date for the entities subject to the NIS 2 Directive. These entities will very probably be given additional time to comply with the directive once it applies in their respective countries. (14)
The deadline concerns member states, not the compliance of entities.
B. Adaptation and transposition into national legislation
The NIS 2 project is part of the European Union's legislative efforts to regulate the growing importance of digital and IT tools. The NIS 2 Directive is designed in coordination with several other texts (15), namely:
-
The draft directive on the resilience of critical entities, which imposes obligations to ensure the continuity of essential services and their security against physical threats;
-
The draft DORA regulation (Digital Operational Resilience Act), which sets out specific cybersecurity obligations for financial sector players. This regulation also provides that the players concerned in this sector will be able to take part in the discussions of the NIS Cooperation Group and exchange with the CSIRTs (Computer Security Incident Response Teams);
-
The regulation currently being drafted, commonly known as “cyber resilience”. This regulation will build on the definitions of “incident” and “vulnerability” established by the NIS 2 Directive. In addition, certain categories of products will be defined as critical according to their use by entities qualifying as essential under the directive's criteria.
These various pieces of legislation are designed to strengthen the security and resilience of critical infrastructure, essential services and financial sector players against cyber threats, for a safer digital environment.
Summary
NIS 2 is the second version of the NIS project, which aims at improving and consolidating the overall level of cybersecurity across Europe, and widens the sectors concerned:
- Digital providers
- Waste management and waste water networks
- Public administration
- Postal and courier services
- Food
- Manufacture of chemicals and pharmaceuticals
- Space
It applies to entities that meet the following criteria:
- Operating within the European Union;
- Whose business sector is included in the list of EEs or IEs;
- With at least 50 employees or annual turnover of €10 million or more.
Compared with NIS 1, this new directive aims to strengthen incident response by introducing more appropriate security requirements for critical infrastructure, and also for their subcontractors.
In addition, companies that fail to comply with its cybersecurity provisions for their activities will be liable to financial penalties. For essential entities: up to €10 million or 2% of total worldwide annual turnover. For important entities: up to €7 million or 1.4% of total worldwide annual turnover.
The directive thus encourages member states to work together to promote cooperation, coordination and information sharing, and then to ensure:
- Adequate security conditions throughout the European Union;
- The identification of common vulnerabilities;
- The sharing of information on threats;
- The implementation of effective prevention and response measures.
This directive will be transposed from 17 October 2024 and will then involve more specific measures that the entities concerned will have to put in place in order to comply with the requirements.
Sources (15)
- (1) CYBER & COLLECTIVITÉS 2023 — NIS2, les objectifs de l'Union européenne en matière de cybersécurité (video, 17 April 2023)
- (2) Le Monde — M. Untersinger, Guerre en Ukraine : la Russie accusée d'être derrière la cyberattaque ayant visé le réseau du satellite KA-SAT (10 May 2022)
- (3) France 24 — Des milliers d'internautes en Europe privés d'internet suite à une probable cyberattaque (4 March 2022)
- (4) ANSSI — Adoption of the Network and Information Security (NIS) Directive: ANSSI leads the transposition in France
- (5) ANSSI — Operators of essential services (OES)
- (6) ANSSI — Digital service providers (DSP)
- (7) Wavestone RiskInsight — N. Lefebvre, European overview of the transposition of the NIS Directive by the member states (4 October 2021)
- (8) ANSSI — NIS: a European cooperation framework
- (9) CERT-FR — The CSIRTs network
- (10) Bing search — “cyclone cyber NIS”
- (11) Yogosha — NIS2 Directive: a step-by-step compliance guide (18 October 2022)
- (12) ANSSI — NIS: a cybersecurity framework for operators of essential services
- (13) Shift Avocats — The NIS 2 Directive: an overview
- (14) ANSSI — NIS 2 Directive: what will change for French businesses and public administration
- (15) Mathias Avocats — NIS 2: what are the stakes, obligations and penalties? (28 September 2022)
A platform and service that adapt to you
Our platform is designed for fine-tuned configuration and broad adaptability to your needs.