Don’t do SECURITY. Do business SECURELY.

EU NIS Directive enters into force

The first EU-wide cybersecurity legislation has entered into force; Member States have until May 2018 to implement it.

The Directive on security of network and information systems (NIS Directive), the first piece of EU-wide cybersecurity legislation, has entered into force. Member States have until 9 May 2018 to transpose it into national law.

What does it require?

  • Operators of essential services (in sectors such as energy, transport, banking, health, water and digital infrastructure) must take appropriate security measures and notify significant incidents.
  • Digital service providers (online marketplaces, search engines and cloud computing services) face similar, lighter-touch obligations.
  • Each Member State must have a national cybersecurity strategy, a CSIRT and a competent authority.

The UK Government has confirmed it will implement the Directive. If you operate in, or supply, one of the in-scope sectors, now is the time to understand how your security and incident reporting arrangements measure up.

Source: Directive (EU) 2016/1148 – NIS Directive (EUR-Lex)

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

More insights