 provides for discretion in transposing provisions related to operators of the essential services, Member States recognised the importance of a harmonised approach in this respect4. The establishment and swift operation of the Network composed of Computer Security Incident Response Teams (CSIRTs) in accordance with Article 12(1) of the Directive. Since then, this network has started to lay the foundations for structured operational cooperation at European level. For both the policy and the operational levels represented by these two structures, the full engagement of all Member States is essential to achieve the goal of a high common level of security of network and information systems in the Union. The present Communication with its annex will reinforce these efforts by bringing together and comparing best practices from the Member States which are relevant for the implementation of the Directive, by providing further guidance on how the Directive should be implemented and through more detailed explanations on specific provisions. The overarching goal is to support Members States to achieve an effective and harmonised implementation of the NIS Directive across the EU. This Communication will be further complemented by the upcoming Commission’s Implementing Regulation on further specification of elements and parameters related to the security and incident notification requirements for digital service providers, pursuant to Article 16(8) of the NIS Directive. The Implementing Regulation will facilitate the implementation of the Directive with respect to obligations concerning digital service providers.5 The Communication presents the key conclusions of the analysis of the issues which are seen as important points of reference and potential inspiration from the point of view of the transposition into national law. Here the primary focus is on provisions related to Member States’ capabilities and obligations concerning entities that are within the scope of the Directive. The annex provides a more detailed examination of those areas where the Commission sees the greatest value in providing practical transposition guidance through the explanation and its interpretation of certain Directive’s provisions, and through presentation of best practices and accumulated experience with the Directive so far. Towards the effective implementation of the NIS Directive The objective of the NIS Directive is to achieve a high common level of security of network and information systems within the EU. This means improving the security of the Internet and 4 The Cooperation Group is currently working on reference guidance documents concerning among others: the criteria defining the criticality of an operator pursuant to Article 5(2) of the Directive; the circumstances in which operators of essential services are required to notify incidents based on Article 14(7) of the Directive; and the security requirements for operators of essential services, in line with Articles 14(1) and 14(2). 5 The draft of the Implementing Regulation is made available for public consultation at https://ec.europa.eu/info/law/better-regulation/have-your-say_en 3

Select target paragraph3