Please find here information on:

  • Procedures for notifying security measures applicable to supervised entities
  • Securing your organisation in line with the best practices published by the NISS

Notification of the security measures:

Essential entities are subject to ex ante and ex post supervision and must submit annually [1] :

  • An analysis of the main cyber risk scenarios [2] , in the form of a multiple-choice questionnaire
  • Their security objectives, reflecting the cybersecurity measures in place
  • An action plan detailing the measures planned to ensure a high level of cybersecurity

Important entities are subject to ex post supervision and are exempt from the regular submission of these deliverables, unless there is evidence, indications, or information suggesting that they are not complying with the NIS 2 Act.

[1] Deadlines and other technical details regarding deliverables are specified in the ILR regulations.

[2] The analysis of key cyber risk scenarios serves as a streamlined oversight tool, limited to a set of predefined scenarios. It does not exempt the entity from conducting its own risk analysis, in accordance with Article 12 of the NIS 2 Act, to identify and address all risks affecting the security of its networks and information systems. The choice of an appropriate risk analysis method is the responsibility of the entity. As part of its supervisory duties, the ILR may request that an entity submit its detailed risk analysis along with evidence demonstrating its effective implementation.

Summary of supervision and obligations by type of entity

Supervision/ObligationEssential entitiesImportant entitiesEntities not subject to supervision under NIS 2
SupervisionEx-ante & ex postEx-post
Reporting of security measuresNot requiredOn a voluntary basis
Reporting of significant incidentsOn a voluntary basis
Reporting of non-significant incidentsOn a voluntary basisOn a voluntary basisOn a voluntary basis
Reporting of near-miss incidentsOn a voluntary basisOn a voluntary basisOn a voluntary basis
Reporting of cyber threatsOn a voluntary basisOn a voluntary basisOn a voluntary basis

Publications

Check out the latest publications available

Publication Communiqués Cybersécurité - NISS July 6, 2026
Publication Guides Cybersécurité - NISS March 4, 2026
Publication Communiqués Cybersécurité - NISS May 2, 2025
Publication Communiqués Cybersécurité - NISS May 2, 2025
Publication Autres publications Cybersécurité - NISS November 6, 2024
1 sur

News

Check our latest news

  • Securing your organisation

    The NISS department ensures that legislation on network and information system security is properly enforced across a range of sectors.

  • NIS 2 Act

    Find out more about the NIS 2 Act.

  • Incident Notification

    Please use SERIMA to report incidents.