L 333/86
EN
Official Journal of the European Union
27.12.2022
directly or through a single entry point. Moreover, Member States should continue to include the financial sector in
their cybersecurity strategies and CSIRTs can cover the financial sector in their activities.
(29)
In order to avoid gaps between or duplications of cybersecurity obligations imposed on entities in the aviation
sector, national authorities under Regulations (EC) No 300/2008 (11) and (EU) 2018/1139 (12) of the European
Parliament and of the Council and the competent authorities under this Directive should cooperate in relation to
the implementation of cybersecurity risk-management measures and the supervision of compliance with those
measures at national level. The compliance of an entity with the security requirements laid down in Regulations (EC)
No 300/2008 and (EU) 2018/1139 and in the relevant delegated and implementing acts adopted pursuant to those
Regulations could be considered by the competent authorities under this Directive to constitute compliance with
the corresponding requirements laid down in this Directive.
(30)
In view of the interlinkages between cybersecurity and the physical security of entities, a coherent approach should
be ensured between Directive (EU) 2022/2557 of the European Parliament and of the Council (13) and this Directive.
To achieve this, entities identified as critical entities under Directive (EU) 2022/2557 should be considered to be
essential entities under this Directive. Moreover, each Member State should ensure that its national cybersecurity
strategy provides for a policy framework for enhanced coordination within that Member State between its
competent authorities under this Directive and those under Directive (EU) 2022/2557 in the context of information
sharing about risks, cyber threats, and incidents as well as on non-cyber risks, threats and incidents, and the exercise
of supervisory tasks. The competent authorities under this Directive and those under Directive (EU) 2022/2557
should cooperate and exchange information without undue delay, in particular in relation to the identification of
critical entities, risks, cyber threats, and incidents as well as in relation to non-cyber risks, threats and incidents
affecting critical entities, including the cybersecurity and physical measures taken by critical entities as well as the
results of supervisory activities carried out with regard to such entities.
Furthermore, in order to streamline supervisory activities between the competent authorities under this Directive
and those under Directive (EU) 2022/2557 and in order to minimise the administrative burden for the entities
concerned, those competent authorities should endeavour to harmonise incident notification templates and
supervisory processes. Where appropriate, the competent authorities under Directive (EU) 2022/2557, should be
able to request the competent authorities under this Directive to exercise their supervisory and enforcement powers
in relation to an entity that is identified as a critical entity under Directive (EU) 2022/2557. The competent
authorities under this Directive and those under Directive (EU) 2022/2557 should, where possible in real time,
cooperate and exchange information for that purpose.
(31)
Entities belonging to the digital infrastructure sector are in essence based on network and information systems and
therefore the obligations imposed on those entities pursuant to this Directive should address in a comprehensive
manner the physical security of such systems as part of their cybersecurity risk-management measures and
reporting obligations. Since those matters are covered by this Directive, the obligations laid down in Chapters III, IV
and VI of Directive (EU) 2022/2557 do not apply to such entities.
(11) Regulation (EC) No 300/2008 of the European Parliament and of the Council of 11 March 2008 on common rules in the field of civil
aviation security and repealing Regulation (EC) No 2320/2002 (OJ L 97, 9.4.2008, p. 72).
(12) Regulation (EU) 2018/1139 of the European Parliament and of the Council of 4 July 2018 on common rules in the field of civil
aviation and establishing a European Union Aviation Safety Agency, and amending Regulations (EC) No 2111/2005, (EC)
No 1008/2008, (EU) No 996/2010, (EU) No 376/2014 and Directives 2014/30/EU and 2014/53/EU of the European Parliament and
of the Council, and repealing Regulations (EC) No 552/2004 and (EC) No 216/2008 of the European Parliament and of the Council
and Council Regulation (EEC) No 3922/91 (OJ L 212, 22.8.2018, p. 1).
(13) Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities
and repealing Council Directive 2008/114/EC (see page 164 of this Official Journal).