NIS2 and EU Cyber Legislation
Back in 2020, the European Commission published the EU Cybersecurity Strategy for the Digital Decade, with the objective of strengthening resilience of Member States, industries and citizens in a constantly changing digital threat landscape. With a range of sector-specific and cross-sectoral laws and regulations the EU aims to improve cybersecurity of the digital domain across Member States. This improvement is essential for people to be able to trust, use, and benefit from innovation, connectivity and automation, while their fundamental rights and freedoms are respected and safeguarded.
NIS2
One of the key parts of the EU Cybersecurity Strategy is the Network and Information Security Directive 2 (“NIS2”). This Directive intends to set a minimum and uniform standard for the duty of care, risk management and incident reporting within the EU. By facilitating cooperation between national authorities and cross-border partners, the EU aims to raise the level of security and reliability of the digital domain, promote innovation and protect critical infrastructure. NIS2 thus adds backbone to the EU’s response to cyber threats for the benefit of continuity of essential services in the internal market.
In the Netherlands, NIS2 has been implemented in the Cybersecurity Act (‘Cbw’). The Cbw gives substance to the measures from NIS2, such as the duty of care, the duty to report, the designation of competent authorities and a Cyber Security Incident Response Team (the CSIRT). A more detailed substance of the Cbw can be found in the Cybersecurity Decree and supplementary national laws.
EU cyber legislation
Besides NIS2, the EU has issued another varied package of laws to give substance to the cybersecurity strategy in several areas. These laws are directed at cybersecurity, such as the Cyber Resilience Act (CRA), the Cyber Security Act (CSA), Critical Entities Resilience Directive (CERD) and the Digital Operational Resilience Act (DORA) for the financial sector. Other laws aimed at digital services and data as such, like the Digital Services Act (DSA), the Digital Markets Act (DMA), the AI Act, the Data Act (DA), the Data Governance Act (DGA) and a few more, are also relevant to the EU Cybersecurity strategy as a whole.
This fan of EU laws in combination with the Netherlands’ own Nederlandse Cybersecurity Strategie (‘NLCS’) is also transposed in national legislation, such as the Critical Entities Resilience Act (Wet weerbaarheid kritieke entiteiten, ‘Wwke’), the implementation of the CERD) and the Data Exchange by Partnerships Act (Wet gegevensuitwisseling door samenwerkingsverbanden, ‘Wgs’).
Cybersecurity in practice
Developments in the landscape of digital security laws are an important reflection of the urgency experienced on this topic in society. This urgency is also seen in several initiatives implementing cybersecurity strategies on a practical level, e.g. in public-private partnerships concerning cyber incidents: Cyclotron and Project Melissa.
Questions? Please feel free to contact one of our experts by telephone or by e-mail: Rosalie Brand and Robert van Schaik.