The future law, the result of an informal agreement between the European Parliament and the Council on December 7, must still be approved by the plenary session of the European Parliament and by the Council.
The new directive to achieve a higher common level of security for networks and information systems across the European Union (known as NIS) aims to end the current fragmentation of the 28 national cybersecurity systems by establishing a list of critical service sectors or companies that will be required to take special measures to withstand future cyberattacks. They will also be obligated to report any serious security breaches they receive to national authorities.
"Parliament has pushed hard for the harmonized identification of critical sectors such as energy, transport, health, and banking, which will have to comply with the new rules and report major cyber incidents. Member States will also have to cooperate more on cybersecurity, measures that are even more important in light of recent security attacks in Europe," explained German spokesperson Andreas Schwab (EPP) after reaching an agreement last month on the NIS directive.
List of "essential services"
EU Member States will have to identify those "essential service operators" in each of the fields mentioned using the same criteria: whether the service is fundamental to society and the economy, whether it depends on other network and information systems, or whether an incident could have significant detrimental effects on service provision or public safety.
Some digital service providers, such as well-known online retailers like eBay and Amazon, search engines (e.g., Google), and cloud storage providers, will also have to take measures to ensure the security of their infrastructure and will be required to report serious incidents to national authorities. Digital SMEs will be excluded from the directive.
EU-wide cooperation mechanisms
: To ensure a higher level of security across the EU and to build trust among EU Member States, the draft law provides for a strategic "cooperation group" dedicated to exchanging information and best practices, developing guidelines, and helping countries increase their cybersecurity capabilities. Each Member State will be required to adopt its own national NIS strategy.
Each EU Member State will also have to establish a “Computer Security Incident Response Team (CSIRT) network” to handle incidents and risks, discuss cross-border security issues, and identify potential coordinated responses. The European Union Agency for Cybersecurity (ENISA) will also play a key role in implementing the directive.
The need to respect the protection of personal data is a topic repeatedly addressed in the draft law.
Next steps:
The draft NIS Directive will now be reviewed by legal linguists before being approved by the Council and the full Parliament. It will then be published in the Official Journal of the EU and will enter into force twenty days after its publication. Member States will have a further 21 months to transpose the directive into their national laws and an additional six months to identify the operators of essential services.
Note: Information systems, critical networks, and services, such as online banking, power grids, or airport security, can be affected by security incidents caused by human error, technical failures, or malicious attacks. ENISA estimates that these incidents result in annual losses of between €260 billion and €340 billion..
