DIRECTIVE (EU) 2022/2555 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL
of 14 December 2022
on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive)
(Text with EEA relevance)
CHAPTER I
GENERAL PROVISIONS
Article 1
Subject matter
Article 2
Scope
Article 3
Essential and important entities
Article 4
Sector-specific Union legal acts
Article 5
Minimum harmonisation
Article 6
Definitions
CHAPTER II
COORDINATED CYBERSECURITY FRAMEWORKS
Article 7
National cybersecurity strategy
Article 8
Competent authorities and single points of contact
Article 9
National cyber crisis management frameworks
Article 10
Computer security incident response teams (CSIRTs)
Article 11
Requirements, technical capabilities and tasks of CSIRTs
Article 12
Coordinated vulnerability disclosure and a European vulnerability database
Article 13
Cooperation at national level
CHAPTER III
COOPERATION AT UNION AND INTERNATIONAL LEVEL
Article 14
Cooperation Group
Article 15
CSIRTs network
Article 16
European cyber crisis liaison organisation network (EU-CyCLONe)
Article 17
International cooperation
Article 18
Report on the state of cybersecurity in the Union
Article 19
Peer reviews
CHAPTER IV
CYBERSECURITY RISK-MANAGEMENT MEASURES AND REPORTING OBLIGATIONS
Article 20
Governance
Article 21
Cybersecurity risk-management measures
Article 22
Union level coordinated security risk assessments of critical supply chains
Article 23
Reporting obligations
Article 24
Use of European cybersecurity certification schemes
Article 25
Standardisation
CHAPTER V
JURISDICTION AND REGISTRATION
Article 26
Jurisdiction and territoriality
Article 27
Registry of entities
Article 28
Database of domain name registration data
CHAPTER VI
INFORMATION SHARING
Article 29
Cybersecurity information-sharing arrangements
Article 30
Voluntary notification of relevant information
CHAPTER VII
SUPERVISION AND ENFORCEMENT
Article 31
General aspects concerning supervision and enforcement
Article 32
Supervisory and enforcement measures in relation to essential entities
Article 33
Supervisory and enforcement measures in relation to important entities
Article 34
General conditions for imposing administrative fines on essential and important entities
Article 35
Infringements entailing a personal data breach
Article 36
Penalties
Article 37
Mutual assistance
CHAPTER VIII
DELEGATED AND IMPLEMENTING ACTS
Article 38
Exercise of the delegation
Article 39
Committee procedure
CHAPTER IX
FINAL PROVISIONS
Article 40
Review
Article 41
Transposition
Article 42
Amendment of Regulation (EU) No 910/2014
Article 43
Amendment of Directive (EU) 2018/1972
Article 44
Repeal
Article 45
Entry into force
Article 46
Addressees
ANNEX I
SECTORS OF HIGH CRITICALITY
Sector |
Subsector |
Type of entity |
||||||
|
|
|
||||||
|
||||||||
|
||||||||
|
||||||||
|
||||||||
|
|
|||||||
|
|
|||||||
|
||||||||
|
||||||||
|
|
|||||||
|
||||||||
|
||||||||
|
||||||||
|
||||||||
|
||||||||
|
||||||||
|
|
|||||||
|
|
|
||||||
|
||||||||
|
||||||||
|
|
|||||||
|
||||||||
|
|
|||||||
|
||||||||
|
||||||||
|
|
|||||||
|
||||||||
|
|
Credit institutions as defined in Article 4, point (1), of Regulation (EU) No 575/2013 of the European Parliament and of the Council(15) |
||||||
|
|
|
||||||
|
||||||||
|
|
|
||||||
|
||||||||
|
||||||||
|
|
Suppliers and distributors of water intended for human consumption as defined in Article 2, point (1)(a), of Directive (EU) 2020/2184 of the European Parliament and of the Council(22), excluding distributors for which distribution of water for human consumption is a non-essential part of their general activity of distributing other commodities and goods |
||||||
|
|
Undertakings collecting, disposing of or treating urban waste water, domestic waste water or industrial waste water as defined in Article 2, points (1), (2) and (3), of Council Directive 91/271/EEC(23), excluding undertakings for which collecting, disposing of or treating urban waste water, domestic waste water or industrial waste water is a non-essential part of their general activity |
||||||
|
|
|
||||||
|
||||||||
|
||||||||
|
||||||||
|
||||||||
|
||||||||
|
||||||||
|
||||||||
|
||||||||
|
|
|
||||||
|
|
|
||||||
|
||||||||
|
|
Operators of ground-based infrastructure, owned, managed and operated by Member States or by private parties, that support the provision of space-based services, excluding providers of public electronic communications networks |
ANNEX II
OTHER CRITICAL SECTORS
Sector |
Subsector |
Type of entity |
||||
|
|
Postal service providers as defined in Article 2, point (1a), of Directive 97/67/EC, including providers of courier services |
||||
|
|
Undertakings carrying out waste management as defined in Article 3, point (9), of Directive 2008/98/EC of the European Parliament and of the Council(1), excluding undertakings for whom waste management is not their principal economic activity |
||||
|
|
Undertakings carrying out the manufacture of substances and the distribution of substances or mixtures, as referred to in Article 3, points (9) and (14), of Regulation (EC) No 1907/2006 of the European Parliament and of the Council(2) and undertakings carrying out the production of articles, as defined in Article 3, point (3), of that Regulation, from substances or mixtures |
||||
|
|
Food businesses as defined in Article 3, point (2), of Regulation (EC) No 178/2002 of the European Parliament and of the Council(3) which are engaged in wholesale distribution and industrial production and processing |
||||
|
|
Entities manufacturing medical devices as defined in Article 2, point (1), of Regulation (EU) 2017/745 of the European Parliament and of the Council(4), and entities manufacturing in vitro diagnostic medical devices as defined in Article 2, point (2), of Regulation (EU) 2017/746 of the European Parliament and of the Council(5) with the exception of entities manufacturing medical devices referred to in Annex I, point 5, fifth indent, of this Directive |
||||
|
Undertakings carrying out any of the economic activities referred to in section C division 26 of NACE Rev. 2 |
|||||
|
Undertakings carrying out any of the economic activities referred to in section C division 27 of NACE Rev. 2 |
|||||
|
Undertakings carrying out any of the economic activities referred to in section C division 28 of NACE Rev. 2 |
|||||
|
Undertakings carrying out any of the economic activities referred to in section C division 29 of NACE Rev. 2 |
|||||
|
Undertakings carrying out any of the economic activities referred to in section C division 30 of NACE Rev. 2 |
|||||
|
|
|
||||
|
||||||
|
||||||
|
|
Research organisations |
ANNEX III
CORRELATION TABLE
Directive (EU) 2016/1148 |
This Directive |
Article 1(1) |
Article 1(1) |
Article 1(2) |
Article 1(2) |
Article 1(3) |
- |
Article 1(4) |
Article 2(12) |
Article 1(5) |
Article 2(13) |
Article 1(6) |
Article 2(6) and (11) |
Article 1(7) |
Article 4 |
Article 2 |
Article 2(14) |
Article 3 |
Article 5 |
Article 4 |
Article 6 |
Article 5 |
– |
Article 6 |
– |
Article 7(1) |
Article 7(1) and (2) |
Article 7(2) |
Article 7(4) |
Article 7(3) |
Article 7(3) |
Article 8(1) to (5) |
Article 8(1) to (5) |
Article 8(6) |
Article 13(4) |
Article 8(7) |
Article 8(6) |
Article 9(1), (2) and (3) |
Article 10(1), (2) and (3) |
Article 9(4) |
Article 10(9) |
Article 9(5) |
Article 10(10) |
Article 10(1), (2) and (3), first subparagraph |
Article 13(1), (2) and (3) |
Article 10(3), second subparagraph |
Article 23(9) |
Article 11(1) |
Article 14(1) and (2) |
Article 11(2) |
Article 14(3) |
Article 11(3) |
Article 14(4), first subparagraph, points (a) to (q) and (s), and paragraph (7) |
Article 11(4) |
Article 14(4), first subparagraph, point (r), and second subparagraph |
Article 11(5) |
Article 14(8) |
Article 12(1) to (5) |
Article 15(1) to (5) |
Article 13 |
Article 17 |
Article 14(1) and (2) |
Article 21(1) to (4) |
Article 14(3) |
Article 23(1) |
Article 14(4) |
Article 23(3) |
Article 14(5) |
Article 23(5), (6) and (8) |
Article 14(6) |
Article 23(7) |
Article 14(7) |
Article 23(11) |
Article 15(1) |
Article 31(1) |
Article 15(2), first subparagraph, point (a) |
Article 32(2), point (e) |
Article 15(2), first subparagraph, point (b) |
Article 32(2), point (g) |
Article 15(2), second subparagraph |
Article 32(3) |
Article 15(3) |
Article 32(4), point (b) |
Article 15(4) |
Article 31(3) |
Article 16(1) and (2) |
Article 21(1) to (4) |
Article 16(3) |
Article 23(1) |
Article 16(4) |
Article 23(3) |
Article 16(5) |
– |
Article 16(6) |
Article 23(6) |
Article 16(7) |
Article 23(7) |
Article 16(8) and (9) |
Article 21(5) and Article 23(11) |
Article 16(10) |
– |
Article 16(11) |
Article 2(1), (2) and (3) |
Article 17(1) |
Article 33(1) |
Article 17(2), point (a) |
Article 32(2), point (e) |
Article 17(2), point (b) |
Article 32(4), point (b) |
Article 17(3) |
Article 37(1), points (a) and (b) |
Article 18(1) |
Article 26(1), point (b), and paragraph (2) |
Article 18(2) |
Article 26(3) |
Article 18(3) |
Article 26(4) |
Article 19 |
Article 25 |
Article 20 |
Article 30 |
Article 21 |
Article 36 |
Article 22 |
Article 39 |
Article 23 |
Article 40 |
Article 24 |
– |
Article 25 |
Article 41 |
Article 26 |
Article 45 |
Article 27 |
Article 46 |
Annex I, point (1) |
Article 11(1) |
Annex I, points (2)(a)(i) to (iv) |
Article 11(2), points (a) to (d) |
Annex I, point (2)(a)(v) |
Article 11(2), point (f) |
Annex I, point (2)(b) |
Article 11(4) |
Annex I, points (2)(c)(i) and (ii) |
Article 11(5), point (a) |
Annex II |
Annex I |
Annex III, points (1) and (2) |
Annex II, point (6) |
Annex III, point (3) |
Annex I, point (8) |