L 333/84
EN
Official Journal of the European Union
27.12.2022
(18)
In order to ensure a clear overview of the entities falling within the scope of this Directive, Member States should
establish a list of essential and important entities as well as entities providing domain name registration services. For
that purpose, Member States should require entities to submit at least the following information to the competent
authorities, namely, the name, address and up-to-date contact details, including the email addresses, IP ranges and
telephone numbers of the entity, and, where applicable, the relevant sector and subsector referred to in the annexes,
as well as, where applicable, a list of the Member States where they provide services falling within the scope of this
Directive. To that end, the Commission, with the assistance of the European Union Agency for Cybersecurity
(ENISA), should, without undue delay, provide guidelines and templates regarding the obligation to submit
information. To facilitate the establishing and updating of the list of essential and important entities as well as
entities providing domain name registration services, Member States should be able to establish national
mechanisms for entities to register themselves. Where registers exist at national level, Member States can decide on
the appropriate mechanisms that allow for the identification of entities falling within the scope of this Directive.
(19)
Member States should be responsible for submitting to the Commission at least the number of essential and
important entities for each sector and subsector referred to in the annexes, as well as relevant information about the
number of identified entities and the provision, from among those laid down in this Directive, on the basis of which
they were identified, and the type of service that they provide. Member States are encouraged to exchange with the
Commission information about essential and important entities and, in the case of a large-scale cybersecurity
incident, relevant information such as the name of the entity concerned.
(20)
The Commission should, in cooperation with the Cooperation Group and after consulting the relevant stakeholders,
provide guidelines on the implementation of the criteria applicable to microenterprises and small enterprises for the
assessment of whether they fall within the scope of this Directive. The Commission should also ensure that
appropriate guidance is given to microenterprises and small enterprises falling within the scope of this Directive.
The Commission should, with the assistance of the Member States, make information available to microenterprises
and small enterprises in that regard.
(21)
The Commission could provide guidance to assist Member States in implementing the provisions of this Directive on
scope and evaluating the proportionality of the measures to be taken pursuant to this Directive, in particular as
regards entities with complex business models or operating environments, whereby an entity may simultaneously
fulfil the criteria assigned to both essential and important entities or may simultaneously carry out activities, some
of which fall within and some of which are excluded from the scope of this Directive.
(22)
This Directive sets out the baseline for cybersecurity risk-management measures and reporting obligations across the
sectors that fall within its scope. In order to avoid the fragmentation of cybersecurity provisions of Union legal acts,
where further sector-specific Union legal acts pertaining to cybersecurity risk-management measures and reporting
obligations are considered to be necessary to ensure a high level of cybersecurity across the Union, the Commission
should assess whether such further provisions could be stipulated in an implementing act under this Directive.
Should such an implementing act not be suitable for that purpose, sector-specific Union legal acts could contribute
to ensuring a high level of cybersecurity across the Union, while taking full account of the specificities and
complexities of the sectors concerned. To that end, this Directive does not preclude the adoption of further sectorspecific Union legal acts addressing cybersecurity risk-management measures and reporting obligations that take
due account of the need for a comprehensive and consistent cybersecurity framework. This Directive is without
prejudice to the existing implementing powers that have been conferred on the Commission in a number of sectors,
including transport and energy.
(23)
Where a sector-specific Union legal act contains provisions requiring essential or important entities to adopt
cybersecurity risk-management measures or to notify significant incidents, and where those requirements are at
least equivalent in effect to the obligations laid down in this Directive, those provisions, including on supervision