Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July ... (32016L1148)
Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July ... (32016L1148)
DIRECTIVE (EU) 2016/1148 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL
of 6 July 2016
concerning measures for a high common level of security of network and information systems across the Union
CHAPTER I
GENERAL PROVISIONS
Article 1
Subject matter and scope
Article 2
Processing of personal data
Article 3
Minimum harmonisation
Article 4
Definitions
Article 5
Identification of operators of essential services
Article 6
Significant disruptive effect
CHAPTER II
NATIONAL FRAMEWORKS ON THE SECURITY OF NETWORK AND INFORMATION SYSTEMS
Article 7
National strategy on the security of network and information systems
Article 8
National competent authorities and single point of contact
Article 9
Computer security incident response teams (CSIRTs)
Article 10
Cooperation at national level
CHAPTER III
COOPERATION
Article 11
Cooperation Group
Article 12
CSIRTs network
Article 13
International cooperation
CHAPTER IV
SECURITY OF THE NETWORK AND INFORMATION SYSTEMS OF OPERATORS OF ESSENTIAL SERVICES
Article 14
Security requirements and incident notification
Article 15
Implementation and enforcement
CHAPTER V
SECURITY OF THE NETWORK AND INFORMATION SYSTEMS OF DIGITAL SERVICE PROVIDERS
Article 16
Security requirements and incident notification
Article 17
Implementation and enforcement
Article 18
Jurisdiction and territoriality
CHAPTER VI
STANDARDISATION AND VOLUNTARY NOTIFICATION
Article 19
Standardisation
Article 20
Voluntary notification
CHAPTER VII
FINAL PROVISIONS
Article 21
Penalties
Article 22
Committee procedure
Article 23
Review
Article 24
Transitional measures
Article 25
Transposition
Article 26
Entry into force
Article 27
Addressees
ANNEX I
REQUIREMENTS AND TASKS OF COMPUTER SECURITY INCIDENT RESPONSE TEAMS (CSIRTs)
ANNEX II
TYPES OF ENTITIES FOR THE PURPOSES OF POINT (4) OF ARTICLE 4
|
Sector |
Subsector |
Type of entity |
||||||
|
|
|
||||||
|
||||||||
|
||||||||
|
|
|||||||
|
||||||||
|
|
|||||||
|
||||||||
|
||||||||
|
||||||||
|
||||||||
|
||||||||
|
||||||||
|
|
|
||||||
|
||||||||
|
||||||||
|
|
|||||||
|
||||||||
|
|
|||||||
|
||||||||
|
||||||||
|
|
|||||||
|
||||||||
|
|
Credit institutions as defined in point (1) of Article 4 of Regulation (EU) No 575/2013 of the European Parliament and of the Council(13) |
||||||
|
|
|
||||||
|
||||||||
|
Health care settings (including hospitals and private clinics) |
Healthcare providers as defined in point (g) of Article 3 of Directive 2011/24/EU of the European Parliament and of the Council(16) |
||||||
|
|
Suppliers and distributors of water intended for human consumption as defined in point (1)(a) of Article 2 of Council Directive 98/83/EC(17) but excluding distributors for whom distribution of water for human consumption is only part of their general activity of distributing other commodities and goods which are not considered essential services |
||||||
|
|
|
||||||
|
||||||||
|