NIS2 Impact on Electronic Communications Networks Providers
Cristina Contero Almagro · 2023
Five years after the deadline for the transposition of the first EU-wide legislation on cybersecurity, known as Directive (EU) 2016/1148 or NIS, ended, the Directive (EU) 2022/2555, otherwise NIS2, entered into force, addressing the limitations and challenges of NIS [1], [2]. NIS2 expands the scope of the previous rules by adding eleven more sectors, introducing new cybersecurity risk and incident management requirements and strengthening the reporting requirements. In terms of categories of operators and providers, NIS2 eliminates this distinction and classifies the entities based on whether they are essential or important, which also determines their supervisory regime. Security and reporting requirements take a risk management approach with a minimum list of basic security elements that need to be applied [3].