2. National strategy on security of network and information systems.
Pursuant to Article 7 of the NIS Directive, Member States are required to adopt a national
strategy on the security of network and information systems that can be considered equivalent
to the term National Cyber Security Strategy ("NCSS"). The function of a national strategy is
to define the strategic objectives and appropriate policy and regulatory actions in relation to
cybersecurity. The concept of NCSS is widely used internationally and in Europe, notably in
the context of ENISA’s work with Member States on national strategies which recently
resulted in an updated NCSS Good Practice Guide.2
In this section the Commission specifies how the NIS Directive enhances Member States'
preparedness by requiring to have in place robust national strategies on the security of
network and information systems (Article 7). This section addresses the aspects: (a) the scope
of the strategy, and (b) the content and procedure for adoption.
As further described below, the correct transposition of Articles 7 of the NIS Directive is
fundamental for the achievement of the Directive's objectives and it necessitates the allocation
of adequate financial and human resources for this purpose.
2.1. The scope of the national strategy.
Pursuant to the wording of Article 7, the obligation to adopt a NCSS only applies to the
sectors referred to in Annex II (i.e., energy, transport, banking, financial market, health,
drinking water supply and distribution and digital infrastructure) and to the services referred
to in Annex III (online marketplace, online search engine and cloud computing service).
Article 3 of the Directive specifically sets forth the principle of minimum harmonisation,
pursuant to which Member States may adopt or maintain provision with a view to achieving a
higher level of security of network of information systems. The application of this principle to
the obligation to adopt a "NCSS" enables Member States to include more sectors and services
than those covered in Annex II and III of the Directive.
In the Commission's view and in the light of the objective of the NIS Directive, i.e., to
achieve a high common level of security of network and information systems within the
Union3, it would be advisable to develop a national strategy that encompasses all relevant
dimensions of society and economy, and not only the sectors and digital services covered
respectively in Annex II and III of the NIS Directive. This is in line with international best
practices (see ITU Guidance and OECD analysis referred to later) and the NIS Directive.
As further explained below this is particularly the case regarding public administrations
responsible for sectors and services other than those listed in the Directive’s Annexes II and
III. Public administrations may process sensitive information, which warrant the need of
2
ENISA, National Cyber-Security Strategy Good Practice 2016). Available at
https://www.enisa.europa.eu/publications/ncss-good-practice-guide
3
See Article 1(1)
5