2. National strategy on security of network and information systems. Pursuant to Article 7 of the NIS Directive, Member States are required to adopt a national strategy on the security of network and information systems that can be considered equivalent to the term National Cyber Security Strategy ("NCSS"). The function of a national strategy is to define the strategic objectives and appropriate policy and regulatory actions in relation to cybersecurity. The concept of NCSS is widely used internationally and in Europe, notably in the context of ENISA’s work with Member States on national strategies which recently resulted in an updated NCSS Good Practice Guide.2 In this section the Commission specifies how the NIS Directive enhances Member States' preparedness by requiring to have in place robust national strategies on the security of network and information systems (Article 7). This section addresses the aspects: (a) the scope of the strategy, and (b) the content and procedure for adoption. As further described below, the correct transposition of Articles 7 of the NIS Directive is fundamental for the achievement of the Directive's objectives and it necessitates the allocation of adequate financial and human resources for this purpose. 2.1. The scope of the national strategy. Pursuant to the wording of Article 7, the obligation to adopt a NCSS only applies to the sectors referred to in Annex II (i.e., energy, transport, banking, financial market, health, drinking water supply and distribution and digital infrastructure) and to the services referred to in Annex III (online marketplace, online search engine and cloud computing service). Article 3 of the Directive specifically sets forth the principle of minimum harmonisation, pursuant to which Member States may adopt or maintain provision with a view to achieving a higher level of security of network of information systems. The application of this principle to the obligation to adopt a "NCSS" enables Member States to include more sectors and services than those covered in Annex II and III of the Directive. In the Commission's view and in the light of the objective of the NIS Directive, i.e., to achieve a high common level of security of network and information systems within the Union3, it would be advisable to develop a national strategy that encompasses all relevant dimensions of society and economy, and not only the sectors and digital services covered respectively in Annex II and III of the NIS Directive. This is in line with international best practices (see ITU Guidance and OECD analysis referred to later) and the NIS Directive. As further explained below this is particularly the case regarding public administrations responsible for sectors and services other than those listed in the Directive’s Annexes II and III. Public administrations may process sensitive information, which warrant the need of 2 ENISA, National Cyber-Security Strategy Good Practice 2016). Available at https://www.enisa.europa.eu/publications/ncss-good-practice-guide 3 See Article 1(1) 5

Select target paragraph3