provides for discretion in transposing provisions related to operators of the essential
services, Member States recognised the importance of a harmonised approach in this
respect4.
The establishment and swift operation of the Network composed of Computer Security
Incident Response Teams (CSIRTs) in accordance with Article 12(1) of the Directive.
Since then, this network has started to lay the foundations for structured operational
cooperation at European level.
For both the policy and the operational levels represented by these two structures, the full
engagement of all Member States is essential to achieve the goal of a high common level of
security of network and information systems in the Union.
The present Communication with its annex will reinforce these efforts by bringing together
and comparing best practices from the Member States which are relevant for the
implementation of the Directive, by providing further guidance on how the Directive should
be implemented and through more detailed explanations on specific provisions. The
overarching goal is to support Members States to achieve an effective and harmonised
implementation of the NIS Directive across the EU.
This Communication will be further complemented by the upcoming Commission’s
Implementing Regulation on further specification of elements and parameters related to the
security and incident notification requirements for digital service providers, pursuant to
Article 16(8) of the NIS Directive. The Implementing Regulation will facilitate the
implementation of the Directive with respect to obligations concerning digital service
providers.5
The Communication presents the key conclusions of the analysis of the issues which are seen
as important points of reference and potential inspiration from the point of view of the
transposition into national law. Here the primary focus is on provisions related to Member
States’ capabilities and obligations concerning entities that are within the scope of the
Directive. The annex provides a more detailed examination of those areas where the
Commission sees the greatest value in providing practical transposition guidance through the
explanation and its interpretation of certain Directive’s provisions, and through presentation
of best practices and accumulated experience with the Directive so far.
Towards the effective implementation of the NIS Directive
The objective of the NIS Directive is to achieve a high common level of security of network
and information systems within the EU. This means improving the security of the Internet and
4
The Cooperation Group is currently working on reference guidance documents concerning among others: the
criteria defining the criticality of an operator pursuant to Article 5(2) of the Directive; the circumstances in
which operators of essential services are required to notify incidents based on Article 14(7) of the Directive; and
the security requirements for operators of essential services, in line with Articles 14(1) and 14(2).
5
The draft of the Implementing Regulation is made available for public consultation at
https://ec.europa.eu/info/law/better-regulation/have-your-say_en
3