- Details
NIS2 Directive
The Directive 2022/2555 of the European Parliament and of the Council, known as NIS2, is the cybersecurity legislation adopted for the entire European Union. It provides legal measures to increase the overall level of cybersecurity in the EU and the resilience of critical infrastructures and digital services in Europe. It sets out cybersecurity, oversight and enforcement obligations for Member States, risk management measures and notification obligations for entities in its scope (Annexes I and II) and concerning the exchange of cybersecurity information.
The directive entered into force in January 2023 and should have been transposed before October 17, 2024.
Consultation service
The National Cryptologic Centre has set up a service to help entities comply with the technical, operational and organisational measures of the NIS2. They can send their queries to the mailbox:
Frequently asked questions (FAQ)
Directive (EU) 2022/2555 of 14 December 2022 (NIS2 Directive), which will update and repeal Directive (EU) 2016/1148 of 6 July 2016, known as the NIS1 Directive, is a European legal norm that aims to establish a regulatory framework to ensure a high level of security in network and information systems across the European Union, with the objective of achieving a high common level of cybersecurity.
To this end, obligations are established to be adopted by those entities included in its scope of application. These obligations take the form of obligations to notify and exchange information on incidents and appropriate technical, operational and organisational security measures, established to manage the cybersecurity risks of the information systems and networks used by these entities in their operations or in the provision of their services.
In order to better adapt the cybersecurity requirements applicable to entities within its scope, the NIS2 Directive distinguishes between critical and important entities. In any case, the 10 groupings of security measures set out in Article 21 will apply to both types of entities, although with a higher level of requirements for critical entities.
The NIS2 Directive was published in the Official Journal of the EU (OJEU) on 27th December 2022, after its formal approval, having entered into force twenty days later. However, as with any European Directive, each Member State will transpose the NIS2 Directive into its national legal system, in a similar way to what was done in Spain with its predecessor, the NIS1 Directive, through the enactment of Royal Decree-Law 12/2018, of 7th September, on the security of networks and information systems.
According to Article 41 of the NIS2 Directive, it must be transposed in all Member States, including Spain, by 17th October 2024 at the latest, with implementation on 18th October 2024.
Directiva NIS2
1) The NIS2 Directive concerns entities belonging to high criticality sectors (see Annex I of the Directive) and other critical sectors (Annex II), both in the public and private sector that are considered medium-sized or large enterprises (according to Recommendation 2003/361/EC a medium-sized enterprise has between 50 and 250 employees, a turnover not exceeding EUR 50 million and an annual balance sheet total not exceeding EUR 43 million).
2) Regardless of their size, the NIS2 Directive also affects:
- Entities belonging to high criticality sectors or other critical sectors, when they are:
- Providers of public networks or publicly available electronic communications services.
- Trusted Service Providers, Top Level Domain Name Registries and DNS service providers.
- Where the entity is the sole provider in a Member State of a service essential for the maintenance of critical social or economic activities.
- When a disruption of the service provided by the entity could have a significant impact on public safety, public order or public health.
- Where a disruption of the service provided by the institution could induce significant systemic risks, in particular for sectors where such a disruption could have cross-border implications.
- Where the entity is critical in the light of its specific importance at national or regional level for the particular sector or type of service or for other interdependent sectors in the Member State.
- Central or regional public sector entities: In accordance with national law, entities of the central or regional public administration, which provide services whose disruption could have a significant impact on critical social or economic activities.
- At the discretion of each Member State: In addition, Member States may incorporate:
- To educational establishments, where they carry out critical research activities.
- Local public administration.
- Critical entities according to another European Directive: Entities identified as critical as defined in Article 2.1 of Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities.
Public administration entities are identified in Annex I of the Directive as high criticality sectors, excluding the judiciary, parliaments and central banks. In this Annex, reference is made only to central and regional (autonomous) public administration. However, it is noted that Member States may provide that this Directive applies to public administration entities at local level and to educational establishments, in particular when they carry out critical research activities.
Furthermore, this Directive does not apply to public administration bodies carrying out their activities in the fields of national security, public safety, defence or law enforcement, including the prevention, investigation, detection and prosecution of criminal offences.
The Article 3 of the NIS2 Directive distinguishes between critical and important institutions, depending on the degree of criticality of the sector to which they belong, the services they provide and their size.
The directive considers high criticality sectors (Annex I) and other critical sectors (Annex II). It also considers a large enterprise to be one that exceeds the thresholds for a medium-sized enterprise (according to Recommendation 2003/361/EC a medium-sized enterprise has between 50 and 250 employees, a turnover not exceeding EUR 50 million and an annual balance sheet total not exceeding EUR 43 million).
1) The NIS2 Directive considers as essential entities:
- The central public administration as defined by each Member State in accordance with national law.
- Large companies in any of the highly critical sectors.
- Qualified Trust Service Providers, Top Level Domain Name Registries and DNS service providers.
- Entities identified as critical under Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities, currently in the process of transposition.
- Entities identified by each Member State before 16 January 2023 as operators of essential services in accordance with Directive (EU) 2016/1148 (NIS1) or according to its national law, if that Member State so considers.
2) The NIS2 Directive considers important entities:
- Any entity belonging to high criticality sectors or other critical sectors (as set out in Annexes I and II of the NIS2 Directive) and which cannot be considered as a critical entity.
3) In the process of transposition of the NIS2 Directive, each Member State may additionally qualify other institutions as critical or important, at its own discretion, when irrespective of their size:
- The entity is the sole provider in a Member State of a service essential for the maintenance of critical social or economic activities.
- A disruption of the service provided by the entity could have a significant impact on public safety, public order or public health.
- A disruption of the service provided by the institution could induce significant systemic risks, in particular for sectors where such a disruption could have cross-border implications.
- The entity is critical in the light of its specific importance at national or regional level for the specific sector or type of service or for other interdependent sectors in the Member State.
To this end, Member States shall establish a list of key and important entities by 17/04/2025, which shall be regularly updated at least every 2 years.
Directiva NIS2
As stated in Article 21 of the NIS2 Directive, critical and important institutions shall manage the risks regarding the security of networks and information systems they use in their operations or for the provision of their services, while minimising the impact of potential security incidents that may occur.
The measures should be according to the risk taking into consideration the degree of exposure of the institution to the risks, the size of the institution and the likelihood and severity of incidents, including the social and economic impact.
The aforementioned Article 21 of the NIS2 Directive sets out in general terms ten (10) groupings of minimum-security requirements or measures that each entity must implement.
In Spain we have Royal Decree 311/2022, of 3rd May, which regulates the National Security Framework (ENS), which includes all the requirements of the NIS2 Directive. The ENS is mandatory in Spain for the entire public sector (state, regional and local), for providers that provide solutions or services and, on a voluntary basis, for any organisation that wishes to improve its cybersecurity. In addition, it is a certifiable legal standard, which provides evidence of compliance.
In addition, the NIS2 Directive obliges critical and important entities to report any significant incident to their reference Computer Security Incident Response Team (CSIRT).
The Article 33 on security incident response capability of RD 311/2022 regulating the ENS, in accordance with the provisions of Article 11 of Royal Decree-Law 12/2018 of 7th September on the security of networks and information systems (Transposition of the NIS Directive1), states:
- The structure called CCN-CERT of the National Cryptologic Centre, attached to the National Intelligence Centre and dependent on the Ministry of Defence, will exercise the national coordination of the technical response of the computer security incident response teams (CSIRTs) of the public sector in Spain, in the field of network and information systems security, also exercising the liaison function to ensure cross-border cooperation of the CSIRTs of the public administrations with the international CSIRTs.
- The structure called INCIBE-CERT attached to the S.M.E. Instituto Nacional de Ciberseguridad de España M.P., S.A., dependent on the Ministry of Economic Affairs and Digital Transformation, will act as the reference security incident response centre for citizens and private law entities in Spain.
- The structure known as ESPDEF-CERT of the Joint Cyberspace Command (MCCE), attached to the Ministry of Defence, will act as the reference security incident response capability for the national defence area, intervening whenever an operator suffers an incident that, due to its scope, could have an impact on the functioning of the Ministry of Defence or on the operability of the Armed Forces.
- Finally, the Security Coordination Office (OCC) of the Ministry of the Interior (Home Affairs) will also participate in the coordination of incident response for critical operators, as determined by Law 8/2011, of 28th April, which establishes measures for the protection of critical infrastructures (LPIC) and Royal Decree 704/2011, of 20th May, which approves the Regulation for the protection of these infrastructures.
This is without prejudice to the future transposition of the NIS2 Directive when it enters into force following its publication in the Official State Gazette (BOE).
A non-exhaustive list derived from Annex I of the NIS2 Directive is presented:
- Energy
- Electricity (electricity companies, distribution system operators, transmission system operators, producers, designated electricity market operators, energy aggregation or storage services, operators in charge of the management and operation of a recharging point)
- Operators of district heating and cooling systems.
- Crude oil (Pipeline operators, production operators, refining and processing facilities, storage and transportation, central storage entities).
- Gas (Gas supply companies, distribution network operators, transmission network operators, storage operators, LNG network operators, natural gas companies, operators of natural gas refining and treatment facilities).
- Hydrogen (Production, storage and transport operators).
- Transport
- Air transport (airlines, airport managing bodies, airports, entities operating ancillary facilities within airport premises, traffic management control operators providing air traffic control services).
- Rail transport (infrastructure managers, railway undertakings).
- Maritime and inland waterway transport (Maritime, inland waterway and coastal shipping companies, both passenger and freight, managing bodies of ports including their port facilities and entities operating works and equipment located in ports, vessel traffic services (VTS) operators).
- Road transport (Various authorities responsible for traffic management control, excluding public entities for which traffic management or ITS operation is a non-essential part of their general activity, ITS operators).
- Banking
- Credit institutions.
- Financial market infrastructures
- Trading venue managers.
- Central counterparties (CCPs).
- Health sector
- Health care providers.
- EU Reference Laboratories.
- Medicines (Entities that carry out research and development of medicines, entities that manufacture basic and speciality pharmaceuticals, entities that manufacture medical devices that are considered essential in public health emergencies).
- Drinking water
- Suppliers and distributors of water intended for human consumption (excluding distributors for whom the distribution of water intended for human consumption is a non-essential part of their general activity of distribution of other goods and commodities).
- Waste water
- Enterprises engaged in the collection, disposal or treatment of urban, domestic or industrial waste water (excluding enterprises for which the collection, disposal or treatment of urban, domestic or industrial waste water is a non-essential part of their overall activity).
- Digital infrastructure
- Providers (of internet exchange points, DNS services excluding root server operators, top level domain names, cloud computing services, data centre services, content delivery networks, trust services, public electronic communications networks, publicly available electronic communications services).
- B2B (business to business) ICT service management
- Managed service providers.
- Managed security service providers.
- Public administration entities, excluding the judiciary, parliaments and central banks
- Central government entities (as defined in the Member State in accordance with the provisions of national law).
- Public administration entities at regional level (as defined in the Member State in accordance with the provisions of national law).
- Space
- Ground-based infrastructure operators (owned, managed and operated by Member States or private entities, supporting the provision of space services, except providers of public electronic communications networks).
Directiva NIS2
A non-exhaustive list derived from Annex II of the NIS2 Directive is presented:
- Postal services
- Postal service providers (including courier service providers).
- Waste management
- Waste management companies (except those for which waste management is not their main economic activity).
- Manufacture, production and distribution of chemical substances and mixtures
- Undertakings engaged in the manufacture of substances and distribution of substances or mixtures (including undertakings engaged in the production of articles from substances and mixtures.
- Food production, processing and distribution
- Food companies (involved in wholesale distribution and industrial production and processing).
- Manufacturing
- Manufacture of medical devices and in-vitro diagnostic medical devices (Entities manufacturing medical devices and entities manufacturing in vitro diagnostic medical devices, with some exceptions).
- Manufacture of computer, electronic and optical products.
- Manufacture of electrical equipment.
- Manufacture of machinery and equipment not elsewhere specified.
- Manufacture of motor vehicles, trailers and semi-trailers.
- Manufacture of other transport equipment.
- Digital service providers
- Online marketplace providers.
- Online search engine providers.
- Social media service platform providers.
- Research
- Research organisations.
Public transport is not explicitly covered by the NIS2. However, in its Article 2 (3), it is stated that the Directive applies to entities that are identified as critical entities under Directive 2022/2557 (EWC Directive). The latter Directive covers under the ‘Transport’ sector (2), the ‘Public Transport’ subsector (e) and more specifically ‘public service operators as defined in Article 2(d) of Regulation (EC) No 1370/2007 of the European Parliament and of the Council (13)’.
Therefore, all entities in the public transport sector, identified under the EWC Directive, will automatically fall under the scope of the NIS2.
Among the critical sectors that fall within the scope of NIS2 is the ‘production, processing and distribution of food’ carried out by ‘food businesses’ as defined in Regulation (EC) 178/2002 (‘any undertaking, whether for profit or not for profit, public or private, carrying out any of the activities related to any stage of production, processing and distribution of food’).
However, the NIS2 Directive itself limits this sector to those undertakings ‘engaged in wholesale distribution and industrial production and processing’.
The purpose of the co-legislator is to limit the broad definition of food businesses by removing retailing and small-scale food production and processing from its application.
Yes, Article 6 (39) of the NIS2 defines a managed service provider as an entity that provides services related to the installation, management, operation or maintenance of ICT products, networks, infrastructures or applications or any other network and information systems [...]. The definition explicitly refers to activities carried out at the customer's premises or remotely.
Each of these tasks (installation, management, operation and maintenance) are not mutually exclusive and an entity may undertake one or more of them.
The managed security services provider, as part of cybersecurity risk management measures, can provide incident management services in case of an emergency.
As stated in Article 6 (40) of the NIS2, a managed security service provider is a provider that ‘performs or assists in the performance of activities relating to cybersecurity risk management’. Examples of such services can be found in Article 21 (2) which encompasses several cybersecurity risk management measures such as risk analysis, incident management, supply chain security or continuity plans.
Article 6, point (20)(b) of the NIS2 Directive defines DNS service providers as ‘an entity that provides: (a) publicly available recursive domain name resolution services for Internet end-users, or (b) authoritative domain name resolution services for use by third parties, with the exception of root servers’.
In the latter case, authoritative domain name resolution services for use by third parties are considered to be provided when these services are provided to legal or natural persons other than the entity itself. This is the case when the authoritative name servers of a domain are not operated by the registrant of this domain, but this service is provided by another entity.
Providers of web hosting services are not listed as such in either Annex I (digital infrastructure refers to providers of DNS services, domain name registries, cloud computing services, data centre services, content delivery networks, trust services, public electronic communications networks, publicly available electronic communications) or Annex II (digital service providers) and would therefore not be within the scope of the NIS2 Directive. However, in many cases, there will be entities that will be within the scope of NIS2 by providing other types of services (such as cloud hosting services, data centre services or authoritative domain name resolution services) and also provide web hosting services.
Article 20(1) and (2) of the NIS Directive2 specifically refers to the obligations of management bodies and their members. Recital 137 explains that the Directive ‘should aim to ensure a high level of accountability for cybersecurity risk management measures and reporting obligations at the level of critical and important entities’. The recital adds for this reason that ‘the management bodies of critical and important institutions should approve cybersecurity risk management measures and oversee their implementation’.
Therefore, if institutions were to delegate the responsibilities referred to in Article 20 to other members of their staff, the objective of the Article would not be adequately fulfilled. Therefore, such delegation should not be allowed.





