On January 16, 2023, the Directive on measures for a high common level of cybersecurity across the European Union (NIS2 Directive) entered into force. The NIS2 Directive repeals the current Directive (EU) 2016/1148 (NISD). The scope is extended to cover a larger part of the economy, thus ensuring the inclusion of key public and economic activities that are vital to the Union's internal market. The cybersecurity requirements imposed on entities providing economically important services or activities vary significantly between Member States. This Directive aims to remove these differences.
What is different about NIS2?
NIS2 applies to a wider range of sectors and services than those in the original directive. While NISD applies primarily to operators of essential services and digital service providers, NIS2 removes this distinction and introduces the broader concept of "essential" and "important" entities, effectively expanding the types of organizations that fall into these categories.
The essential subjects (e.g., energy companies, telecoms, and cloud service providers) will now be subject to comprehensive ex ante and ex post control by the competent authorities, because they carry out activities that are of greater importance and criticality to society. Important entities (e.g., postal and courier services, chemical and food manufacturers) will only be subject to follow-up supervision.
Which would fall within the scope of NIS2. every medium and large enterprise – companies with more than 50 employees or those with an annual turnover exceeding €10 million euros from the listed sectors.. This means that any company in these sectors with more than 50 employees will have to bring its activities into line with a set of technical, operational, and organizational measures.
В тази връзка, основното разграничаване между двете категории – съществени и важни субекти, е по отношение на надзорните и правоприлагащите мерки, както и на санкциите, които ще се прилагат към тях. Властите не са задължени да уведомяват организациите, дали попадат в обхвата на настоящата Директива. Те трябва сами да се оценят въз основа на критериите, които включват елементи на индустрията и съображения за размера. Управителните органи на основни и важни субекти също могат да бъдат държани отговорни за неспазване на разпоредбите на Директивата NIS2.
Какво следва?
Тъй като директивите на ЕС нямат пряко действие в държавите членки, те трябва да транспонират изискванията на Директивата NIS2 в националното законодателство, преди да станат приложими. Транспонирането трябва да бъде направено до 17 октомври 2024 г. и да бъдат публикувани съответните нормативни документи, които да започнат да се прилагат от 18 октомври 2024 г. Следете новините на нашата страница. Ще ви информираме за мерките, които трябва да предприемете. Можем да сме полезни и с оценката дали вашата организация попада в обхвата на NIS2, консултации относно мерки за общо ниво на киберсигурност, въвеждане на минимални изисквания за киберсигурност, провеждане на обучения и др.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
These cookies are needed for adding comments on this website.
You can find more information in our Cookies policy and .