ANNEX
1. Introduction.
This Annex aims to contribute to an effective application, implementation and enforcement of
the NIS Directive (EU) 2016/1148 on the security of network and information systems across
the Union1 (hereinafter referred to as “NIS Directive" or the “Directive”) and to help the
Member States to ensure that EU law is applied effectively. More particularly, its specific
objectives are threefold: (a) to offer greater clarity to national authorities on the obligations
contained in the Directive that apply to such authorities, (b) to ensure the effective
enforcement of the Directive's obligations applying to entities under obligations concerning
security requirements and incident notifications, and (c) to overall contribute to create legal
certainty for all relevant actors.
To this end, this Annex provides guidance on the following aspects, which are key to achieve
the goal of the NIS Directive i.e., to ensure a high common level of security of network and
information systems within the EU, underpinning the functioning of our society and economy:
Member States’ obligation to adopt a national strategy on security of network and
information systems (section 2);
The setting up of national competent authorities, single contact points and Computer
Security Incident Response Teams (section 3);
The security and incident notifications requirements applicable to operators of
essential services and to digital service providers (section 4); and
The relationship between the NIS Directive and other legislation (section 5)
To prepare this guidance, the Commission has used input and analysis gathered during the
preparation of the Directive, input from European Agency for network and information
security ("ENISA") and Cooperation Group. It has also used experiences from specific
Member States. When appropriate, the Commission has taken into account the guiding
principles for interpreting EU law: the wording, context and objectives of the NIS Directive.
Given that the Directive has not been transposed, no ruling of the Court of Justice of the
European Union (CJEU) or national courts has yet been rendered. Therefore, it is not possible
to use case-law as guidance.
Compiling this information in a single document may allow Member States to have a good
overview of the Directive and take this information into account when devising their national
legislation. At the same time, the Commission stresses that this Annex is not binding and does
not intend to create new rules. The final competence to interpret EU law lies with the CJEU.
1
Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures
for a high common level of security of network and information systems across the Union. The Directive entered
into force on 8 August 2016.
4