European Union: Implemented Network and Information Security Directive (NIS2) including data protection authority governance

Compare with different regulatory event:

Description

Implemented Network and Information Security Directive (NIS2) including data protection authority governance

On 18 October 2024, the Network and Information Security Directive (NIS2) was implemented. The NIS2 aims to ensure a higher level of cybersecurity at the EU level by coordinating national approaches to and Governance of cybersecurity. The Member States had until 17 October 2024 to transpose the Directive into national law. Under the Directive, the Member States must adopt a national security strategy and define their strategic objectives and the regulatory measures they intend to take to achieve an adequate level of cyber security harmonisation. Each Member State is required to designate one or more competent national authorities to manage large-scale crises or incidents and supervise the application of the Directive at the national level, and establish single points of contact and Computer Security Incident Response Teams (CSIRTs), which will act as trusted intermediaries to facilitate interaction between the various entities involved and will be linked by a network of national CSIRTs. A cooperation group composed of representatives from each member state, the Commission and the European Union Agency for Cybersecurity (ENISA) is also established to conduct cyber risk assessments and issue security standards. The European Cyber Crises Liaison Organisation Network (EU - CyCLONe), consisting of representatives of each member state, the Commission and ENISA, will also be established to coordinate large-scale cybersecurity NIS2 in each member state.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection authority governance
Regulated Economic Activity
cross-cutting
Implementation Level
supranational
Government Branch
legislature
Government Body
parliament

Complete timeline of this policy change

Hide details
2020-12-16
under deliberation

On 16 December 2020, the European Commission presented the Proposal for a Directive of the European…

2022-05-13
under deliberation

On 13 May 2022, the European Parliament and the Council of the European Union reached a political a…

2022-11-10
under deliberation

On 10 November 2022, the European Parliament passed the Network and Information Security Directive …

2022-11-28
adopted

On 28 November 2022, the Council of the European Union adopted the Network and Information Security…

2023-01-16
in grace period

On 16 January 2023, the Network and Information Security Directive (NIS2) enters into force with gr…

2024-10-18
in force

On 18 October 2024, the Network and Information Security Directive (NIS2) was implemented. The NIS2…