The Directive on security of network and information systems (NIS Directive), the first piece of EU-wide cybersecurity legislation, has entered into force. Member States have until 9 May 2018 to transpose it into national law.
What does it require?
- Operators of essential services (in sectors such as energy, transport, banking, health, water and digital infrastructure) must take appropriate security measures and notify significant incidents.
- Digital service providers (online marketplaces, search engines and cloud computing services) face similar, lighter-touch obligations.
- Each Member State must have a national cybersecurity strategy, a CSIRT and a competent authority.
The UK Government has confirmed it will implement the Directive. If you operate in, or supply, one of the in-scope sectors, now is the time to understand how your security and incident reporting arrangements measure up.
Source: Directive (EU) 2016/1148 – NIS Directive (EUR-Lex)
This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.