European Parliament Adopts Directive on Security of Network and Information Systems
Time 2 Minute Read

On July 6, 2016, the European Parliament adopted the Directive on Security of Network and Information Systems (the “NIS Directive”), which will come into force in August 2016. EU Member States will have 21 months to transpose the NIS Directive into their national laws. The NIS Directive is part of the European Commission’s cybersecurity strategy for the European Union, and is designed to increase cooperation between EU Member States on cybersecurity issues.

The objective of the NIS Directive is to set a common level of security for networks and information systems throughout the European Union. To achieve this objective, EU Member States must:

  • adopt a national strategy on the security of the network and information systems;
  • designate a competent authority to monitor the implementation of the NIS Directive; and
  • designate one or more Computer Security Incident Response Team(s).

A cooperation group composed of representatives from EU Member States will be appointed and will work on providing guidance and sharing information on network security.

At a company level, there will be a risk management and incident reporting obligation to national authorities for operators of “essential services” and digital service providers. Operators of essential services will be identified by EU Member States based on the following criteria: (1) if the entity provides a service which is essential for the maintenance of critical societal/economic activities; (2) the provision of that service depends on network and information systems; and (3) a security incident would have significant disruptive effects on the provision of the essential service. The targeted digital service providers include online marketplaces, cloud computing services and search engines.

The sectors in scope of the NIS Directive include energy, transportation, banking, financial markets, health, water and digital infrastructure. The incidents requiring notification will be assessed according to the following factors: number of users affected, duration of incident, geographic spread, the extent of the disruption of the service and the impact on economic and societal activities.

Going forward, the European Commission will adopt implementing acts with respect to security requirements and notifications obligations of digital service providers within one year of the adoption of the NIS Directive.

You May Also Be Interested In

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Time 2 Minute Read

On March 3, 2026, the European Commission published draft guidelines intended to clarify the application of the Cyber Resilience Act and opened a public consultation to gather feedback from stakeholders.

Time 2 Minute Read

On February 23, 2026, a Joint Statement on AI-Generated Imagery was published by 61 data protection authorities. The Joint Statement addresses concerns regarding AI systems capable of generating realistic images and videos depicting identifiable individuals without their knowledge or consent.

Time 2 Minute Read

On February 18, 2026, Virginia Attorney General Jay Jones announced that his office intends to fully enforce new provisions of the Virginia Consumer Data Protection Act restricting minors’ use of social media.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page