Please find here information on:
- Procedures for notifying security measures applicable to supervised entities
- Securing your organisation in line with the best practices published by the NISS
Please find here information on:
Essential entities are subject to ex ante and ex post supervision and must submit annually [1] :
Important entities are subject to ex post supervision and are exempt from the regular submission of these deliverables, unless there is evidence, indications, or information suggesting that they are not complying with the NIS 2 Act.
[1] Deadlines and other technical details regarding deliverables are specified in the ILR regulations.
[2] The analysis of key cyber risk scenarios serves as a streamlined oversight tool, limited to a set of predefined scenarios. It does not exempt the entity from conducting its own risk analysis, in accordance with Article 12 of the NIS 2 Act, to identify and address all risks affecting the security of its networks and information systems. The choice of an appropriate risk analysis method is the responsibility of the entity. As part of its supervisory duties, the ILR may request that an entity submit its detailed risk analysis along with evidence demonstrating its effective implementation.
| Supervision/Obligation | Essential entities | Important entities | Entities not subject to supervision under NIS 2 |
|---|---|---|---|
| Supervision | Ex-ante & ex post | Ex-post | ✗ |
| Reporting of security measures | ✓ | Not required | On a voluntary basis |
| Reporting of significant incidents | ✓ | ✓ | On a voluntary basis |
| Reporting of non-significant incidents | On a voluntary basis | On a voluntary basis | On a voluntary basis |
| Reporting of near-miss incidents | On a voluntary basis | On a voluntary basis | On a voluntary basis |
| Reporting of cyber threats | On a voluntary basis | On a voluntary basis | On a voluntary basis |
Check out the latest publications available
Check our latest news
The NISS department ensures that legislation on network and information system security is properly enforced across a range of sectors.