• Login
    • Advanced search
    • Title
    • Channel
    • Module
  • Home
  • Industry
    •  

      • Aerospace, Defense, and Government Services
      • Automotive
      • Consumer
      • Manufacturing and Industrials
      • Education
      • Energy and Natural Resources
      • Financial Institutions
    •  

      • Insurance
      • Life Sciences and Health Care
      • Private Capital
      • Real Estate
      • Sports, Media and Entertainment
      • Technology and Telecoms
      • Transport and Logistics
  • Practice
    • Corporate & Finance

      • Banking and Loan Finance
      • Business Restructuring and Insolvency
      • Capital Markets
      • Corporate Governance and Public Company Representation
      • Digital Assets and Blockchain
      • Infrastructure, Energy, Resources, and Projects
      • Leveraged and Acquisition Finance
      • Mergers and Acquisitions
      • Pensions
      • Private Equity, Venture Capital and Investment Funds
      • Real Estate
      • Real Estate Investment Trusts (REITs)
      • Tax
      • Transfer Pricing
    • Global Regulatory

      • Administrative and Public Law
      • Antitrust and Competition
      • Communications, Internet, and Media
      • Education
      • Energy Regulatory
      • Environment and Natural Resources
      • Financial Services
      • Food Law
      • Gaming Law
      • Government Contracts and Public Procurement
      • Government Relations and Public Affairs
      • Health
      • Immigration
      • International Trade and Investment
      • Medical Device and Technology Regulatory
      • New Nuclear
      • Pharmaceuticals and Biotechnology Regulatory
      • Privacy and Cybersecurity
      • Space and Satellite
      • Strategic Operations, Agreements and Regulation
      • Transportation Regulatory
    • Intellectual Property

      • Copyright
      • Designs
      • Domain Names
      • IP and Technology Transactions
      • IP Enforcement
      • Patents
      • Trade Secrets and Confidential Know-how
      • Trademarks and Brands
      • Unfair Competition
    • Litigation, Arbitration, and Employment

      • Business and Human Rights
      • Construction and Engineering
      • Corporate and Securities Litigation
      • Employment
      • International Arbitration
      • Investigations, White Collar, and Fraud
      • Products Law
      • Risks, Disputes, and Litigation
  • Comparative guides
  • Engage Premium
  • Login
  • Register
Hogan Lovells Engage 5.7.7
      • Title
      • Channel
      • Module
    • Hit ENTER to search in content
    • Advanced search
    • Login
  • Home
  • Industry
    •  

      • Aerospace, Defense, and Government Services
      • Automotive
      • Consumer
      • Manufacturing and Industrials
      • Education
      • Energy and Natural Resources
      • Financial Institutions
    •  

      • Insurance
      • Life Sciences and Health Care
      • Private Capital
      • Real Estate
      • Sports, Media and Entertainment
      • Technology and Telecoms
      • Transport and Logistics
  • Practice
    • Corporate & Finance

      • Banking and Loan Finance
      • Business Restructuring and Insolvency
      • Capital Markets
      • Corporate Governance and Public Company Representation
      • Digital Assets and Blockchain
      • Infrastructure, Energy, Resources, and Projects
      • Leveraged and Acquisition Finance
      • Mergers and Acquisitions
      • Pensions
      • Private Equity, Venture Capital and Investment Funds
      • Real Estate
      • Real Estate Investment Trusts (REITs)
      • Tax
      • Transfer Pricing
    • Global Regulatory

      • Administrative and Public Law
      • Antitrust and Competition
      • Communications, Internet, and Media
      • Education
      • Energy Regulatory
      • Environment and Natural Resources
      • Financial Services
      • Food Law
      • Gaming Law
      • Government Contracts and Public Procurement
      • Government Relations and Public Affairs
      • Health
      • Immigration
      • International Trade and Investment
      • Medical Device and Technology Regulatory
      • New Nuclear
      • Pharmaceuticals and Biotechnology Regulatory
      • Privacy and Cybersecurity
      • Space and Satellite
      • Strategic Operations, Agreements and Regulation
      • Transportation Regulatory
    • Intellectual Property

      • Copyright
      • Designs
      • Domain Names
      • IP and Technology Transactions
      • IP Enforcement
      • Patents
      • Trade Secrets and Confidential Know-how
      • Trademarks and Brands
      • Unfair Competition
    • Litigation, Arbitration, and Employment

      • Business and Human Rights
      • Construction and Engineering
      • Corporate and Securities Litigation
      • Employment
      • International Arbitration
      • Investigations, White Collar, and Fraud
      • Products Law
      • Risks, Disputes, and Litigation
  • Comparative guides
  • Engage Premium
  • Login
  • Register
  1. News
  2. Council adopts NIS 2, a renovated framework on Cybersecurity

Council adopts NIS 2, a renovated framework on Cybersecurity

30 November 2022
    • Share by email
    • Share on
    • Twitter
    • LinkedIn
    • Get link
    • Get QR Code
    • Download
    • Print

The NIS 2 Directive ("Directive" or "NIS2") has been approved by the Council. The Directive will be published in the Official Journal of the European Union in the coming days and will enter into force on the twentieth day following its publication. Member States will have 21 months from the entry into force of the Directive to implement its provisions into their national law. The Directive addresses the shortcomings of NIS1 Directive, and sets forth a renovated framework for cybersecurity in EU.

In brief, the Directive includes

  • a much wider scope than that of NIS1 Directive. The existing difference between operators of essential services and relevant service providers will be superseded by the new categories of essential and important entities. The new scope is based both on size cap and sectors.  This entails that NIS2 will reach, notably, an extended amount of healthcare operators (including manufacturer of pharmaceuticals and medical devices), online marketplaces, online search engines, social networking social platforms, ICT service management, B2B service providers, public administrations, manufacturers, distributors and productors of chemicals, entities providing  data centre services, research organizations, etc.
  • a more detailed set of minimum compulsory security measures, including governance measures, internal organisation policies (for instance, internal procedures on incident handling, HR conducts, risk assessments and others);
  • a focus on supply chain compliance, with a specific attention to most critical providers;
  • an increase in the powers of competent authorities, particularly for essential entities, which will be subject to ex ante and ex post supervision;
  • increased sanctions, for essential entities up to 10M euro, or 2% of turnover, and for important entities up to 7M euro, or 1.4% of turnover;
  • criteria on jurisdiction, mostly based on main establishment (save from more detailed provisions for instance on electronic communication networks and services), alongside mutual cooperation procedures between authorities.

Next steps

What’s next for involved operators:

  • assessing whether your business falls into the scope of the Directive;
  • checking updates on sector-based act such as the Regulation on digital operational resilience for the financial sector (DORA) and the Directive on the resilience of critical entities (CER),
  • monitoring and verifying implementing acts on EU and national level;
  • reviewing and updating governance and procedures within your company;
  • assess your supplier's compliance, and strengthen contractual measures if needed;
  • train management staff and employees on cybersecurity internal policies.

 

Authored by Massimiliano Masnada, Giulia Mariuz, and Elisabetta Nunziante.

Contacts
Massimiliano Masnada
Partner
Rome
Giulia Mariuz
Counsel
Milan
Elisabetta Nunziante
Associate
Rome
Related Materials
Sanctions Navigator

Sanctions Navigator: Russia Sanctions

Keywords Cybersecurity, NIS2, privacy, risk assessment, manufacturers, health sector, digital providers
Languages English
Topics Artificial Intelligence, Digital Assets and Blockchain, Cloud Services, Data Centers, E-Commerce, Social Media, Software / Software as a Service / Enterprise Software, Technology Hardware and Infrastructure, Cybersecurity
Countries United States, Belgium, France, Germany, Hungary, Italy, Ireland, Luxembourg, Netherlands, Poland, Spain, United Kingdom
Delete Comment ?

Are you sure want to delete comment ?

Get link
Embed
Share by email
Get QR Code

Scan this QR Code to share this content

  • Contact us
  • Disclaimer
  • Privacy
  • Cookies
  • Legal Notices
  • Terms of Use

 

This website is operated by Hogan Lovells International LLP, whose registered office is at Atlantic House, Holborn Viaduct, London, EC1A 2FG. For further details of Hogan Lovells International LLP and the international legal practice that comprises Hogan Lovells International LLP, Hogan Lovells US LLP and their affiliated businesses ("Hogan Lovells"), please see our Legal Notices page. © 2022 Hogan Lovells.

Attorney advertising. Prior results do not guarantee a similar outcome.

Thomson Reuters HighQ Logo
© 2023 Hogan Lovells | Privacy Policy | Terms of Service