L 194/8
EN
Official Journal of the European Union
19.7.2016
(47)
Competent authorities should retain the ability to adopt national guidelines concerning the circumstances in
which operators of essential services are required to notify incidents.
(48)
Many businesses in the Union rely on digital service providers for the provision of their services. As some digital
services could be an important resource for their users, including operators of essential services, and as such
users might not always have alternatives available, this Directive should also apply to providers of such services.
The security, continuity and reliability of the type of digital services referred to in this Directive are of the essence
for the smooth functioning of many businesses. A disruption of such a digital service could prevent the provision
of other services which rely on it and could thus have an impact on key economic and societal activities in the
Union. Such digital services might therefore be of crucial importance for the smooth functioning of businesses
that depend on them and, moreover, for the participation of such businesses in the internal market and crossborder trade across the Union. Those digital service providers that are subject to this Directive are those that are
considered to offer digital services on which many businesses in the Union increasingly rely.
(49)
Digital service providers should ensure a level of security commensurate with the degree of risk posed to the
security of the digital services they provide, given the importance of their services to the operations of other
businesses within the Union. In practice, the degree of risk for operators of essential services, which are often
essential for the maintenance of critical societal and economic activities, is higher than for digital service
providers. Therefore, the security requirements for digital service providers should be lighter. Digital service
providers should remain free to take measures they consider appropriate to manage the risks posed to the
security of their network and information systems. Because of their cross-border nature, digital service providers
should be subject to a more harmonised approach at Union level. Implementing acts should facilitate the specifi
cation and implementation of such measures.
(50)
While hardware manufacturers and software developers are not operators of essential services, nor are they
digital service providers, their products enhance the security of network and information systems. Therefore, they
play an important role in enabling operators of essential services and digital service providers to secure their
network and information systems. Such hardware and software products are already subject to existing rules on
product liability.
(51)
Technical and organisational measures imposed on operators of essential services and digital service providers
should not require a particular commercial information and communications technology product to be designed,
developed or manufactured in a particular manner.
(52)
Operators of essential services and digital service providers should ensure the security of the network and
information systems which they use. These are primarily private network and information systems managed by
their internal IT staff or the security of which has been outsourced. The security and notification requirements
should apply to the relevant operators of essential services and digital service providers regardless of whether
they perform the maintenance of their network and information systems internally or outsource it.
(53)
To avoid imposing a disproportionate financial and administrative burden on operators of essential services and
digital service providers, the requirements should be proportionate to the risk presented by the network and
information system concerned, taking into account the state of the art of such measures. In the case of digital
service providers, those requirements should not apply to micro- and small enterprises.
(54)
Where public administrations in Member States use services offered by digital service providers, in particular
cloud computing services, they might wish to require from the providers of such services additional security
measures beyond what digital service providers would normally offer in compliance with the requirements of this
Directive. They should be able to do so by means of contractual obligations.
(55)
The definitions of online marketplaces, online search engines and cloud computing services in this Directive are
for the specific purpose of this Directive, and without prejudice to any other instruments.