Please find here information on:

  • Procedures for notifying security measures applicable to supervised entities
  • Securing your organisation in line with the best practices published by the NISS

Notification of the security measures:

Essential entities are subject to ex ante and ex post supervision and must submit annually [1] :

When setting its supervisory priorities within the meaning of Article 21(1) of the Law, the Institute may, in accordance with a risk-based approach, make certain categories of essential entities subject to the obligation to submit the list of their dependencies on their direct suppliers or service providers. The entities concerned are informed thereof by the Institute within a reasonable period and also submit that list on an annual basis.

Important entities are subject to ex post supervision and are exempt from the regular submission of these deliverables, unless there is evidence, indications, or information suggesting that they are not complying with the NIS 2 Act.

[1] Deadlines and other technical details regarding deliverables are specified in the ILR regulations.

[2] The analysis of key cyber risk scenarios serves as a streamlined oversight tool, limited to a set of predefined scenarios. It does not exempt the entity from conducting its own risk analysis, in accordance with Article 12 of the NIS 2 Act, to identify and address all risks affecting the security of its networks and information systems. The choice of an appropriate risk analysis method is the responsibility of the entity. As part of its supervisory duties, the ILR may request that an entity submit its detailed risk analysis along with evidence demonstrating its effective implementation.

Summary of supervision and obligations by type of entity

Supervision/ObligationEssential entitiesImportant entitiesEntities not subject to supervision under NIS 2
SupervisionEx-ante & ex postEx-post
Reporting of security measuresNot requiredOn a voluntary basis
Reporting of significant incidentsOn a voluntary basis
Reporting of non-significant incidentsOn a voluntary basisOn a voluntary basisOn a voluntary basis
Reporting of near-miss incidentsOn a voluntary basisOn a voluntary basisOn a voluntary basis
Reporting of cyber threatsOn a voluntary basisOn a voluntary basisOn a voluntary basis

Publications

Check out the latest publications available

Publication Guides Cybersécurité - NISS August 3, 2026
Publication Guides Cybersécurité - NISS August 3, 2026
Publication Guides Cybersécurité - NISS August 3, 2026
Publication Guides Cybersécurité - NISS August 3, 2026
Publication Communiqués Cybersécurité - NISS July 6, 2026
1 sur

News

Check our latest news

  • Securing your organisation

    The NISS department ensures that legislation on network and information system security is properly enforced across a range of sectors.

  • NIS 2 Act

    Find out more about the NIS 2 Act.

  • Incident Notification

    Please use SERIMA to report incidents.