L 194/16
EN
Official Journal of the European Union
19.7.2016
(b) a governance framework to achieve the objectives and priorities of the national strategy on the security of network
and information systems, including roles and responsibilities of the government bodies and the other relevant actors;
(c) the identification of measures relating to preparedness, response and recovery, including cooperation between the
public and private sectors;
(d) an indication of the education, awareness-raising and training programmes relating to the national strategy on the
security of network and information systems;
(e) an indication of the research and development plans relating to the national strategy on the security of network and
information systems;
(f) a risk assessment plan to identify risks;
(g) a list of the various actors involved in the implementation of the national strategy on the security of network and
information systems.
2.
Member States may request the assistance of ENISA in developing national strategies on the security of network
and information systems.
3.
Member States shall communicate their national strategies on the security of network and information systems to
the Commission within three months from their adoption. In so doing, Member States may exclude elements of the
strategy which relate to national security.
Article 8
National competent authorities and single point of contact
1.
Each Member State shall designate one or more national competent authorities on the security of network and
information systems (‘competent authority’), covering at least the sectors referred to in Annex II and the services referred
to in Annex III. Member States may assign this role to an existing authority or authorities.
2.
The competent authorities shall monitor the application of this Directive at national level.
3.
Each Member State shall designate a national single point of contact on the security of network and information
systems (‘single point of contact’). Member States may assign this role to an existing authority. Where a Member State
designates only one competent authority, that competent authority shall also be the single point of contact.
4.
The single point of contact shall exercise a liaison function to ensure cross-border cooperation of Member State
authorities and with the relevant authorities in other Member States and with the Cooperation Group referred to in
Article 11 and the CSIRTs network referred to in Article 12.
5.
Member States shall ensure that the competent authorities and the single points of contact have adequate resources
to carry out, in an effective and efficient manner, the tasks assigned to them and thereby to fulfil the objectives of this
Directive. Member States shall ensure effective, efficient and secure cooperation of the designated representatives in the
Cooperation Group.
6.
The competent authorities and single point of contact shall, whenever appropriate and in accordance with national
law, consult and cooperate with the relevant national law enforcement authorities and national data protection
authorities.
7.
Each Member State shall notify to the Commission without delay the designation of the competent authority and
single point of contact, their tasks, and any subsequent change thereto. Each Member State shall make public its
designation of the competent authority and single point of contact. The Commission shall publish the list of designated
single points of contacts.