27.12.2022
EN
Official Journal of the European Union
L 333/85
and enforcement, should apply to such entities. If a sector-specific Union legal act does not cover all entities in a
specific sector falling within the scope of this Directive, the relevant provisions of this Directive should continue to
apply to the entities not covered by that act.
(24)
Where provisions of a sector-specific Union legal act require essential or important entities to comply with reporting
obligations that are at least equivalent in effect to the reporting obligations laid down in this Directive, the
consistency and effectiveness of the handling of incident notifications should be ensured. To that end, the
provisions relating to incident notifications of the sector-specific Union legal act should provide the CSIRTs, the
competent authorities or the single points of contact on cybersecurity (single points of contact) under this Directive
with an immediate access to the incident notifications submitted in accordance with the sector-specific Union legal
act. In particular, such immediate access can be ensured if incident notifications are being forwarded without undue
delay to the CSIRT, the competent authority or the single point of contact under this Directive. Where appropriate,
Member States should put in place an automatic and direct reporting mechanism that ensures systematic and
immediate sharing of information with the CSIRTs, the competent authorities or the single points of contact
concerning the handling of such incident notifications. For the purpose of simplifying reporting and of
implementing the automatic and direct reporting mechanism, Member States could, in accordance with the sectorspecific Union legal act, use a single entry point.
(25)
Sector-specific Union legal acts which provide for cybersecurity risk-management measures or reporting obligations
that are at least equivalent in effect to those laid down in this Directive could provide that the competent authorities
under such acts exercise their supervisory and enforcement powers in relation to such measures or obligations with
the assistance of the competent authorities under this Directive. The competent authorities concerned could
establish cooperation arrangements for that purpose. Such cooperation arrangements could specify, inter alia, the
procedures concerning the coordination of supervisory activities, including the procedures of investigations and
on-site inspections in accordance with national law, and a mechanism for the exchange of relevant information on
supervision and enforcement between the competent authorities, including access to cyber-related information
requested by the competent authorities under this Directive.
(26)
Where sector-specific Union legal acts require or provide incentives to entities to notify significant cyber threats,
Member States should also encourage the sharing of significant cyber threats with the CSIRTs, the competent
authorities or the single points of contact under this Directive, in order to ensure an enhanced level of those bodies’
awareness of the cyber threat landscape and to enable them to respond effectively and in a timely manner should the
significant cyber threats materialise.
(27)
Future sector-specific Union legal acts should take due account of the definitions and the supervisory and
enforcement framework laid down in this Directive.
(28)
Regulation (EU) 2022/2554 of the European Parliament and of the Council (10) should be considered to be a sectorspecific Union legal act in relation to this Directive with regard to financial entities. The provisions of Regulation
(EU) 2022/2554 relating to information and communication technology (ICT) risk management, management of
ICT-related incidents and, in particular, major ICT-related incident reporting, as well as on digital operational
resilience testing, information-sharing arrangements and ICT third-party risk should apply instead of those
provided for in this Directive. Member States should therefore not apply the provisions of this Directive on
cybersecurity risk-management and reporting obligations, and supervision and enforcement, to financial entities
covered by Regulation (EU) 2022/2554. At the same time, it is important to maintain a strong relationship and the
exchange of information with the financial sector under this Directive. To that end, Regulation (EU) 2022/2554
allows the European Supervisory Authorities (ESAs) and the competent authorities under that Regulation to
participate in the activities of the Cooperation Group and to exchange information and cooperate with the single
points of contact, as well as with the CSIRTs and the competent authorities under this Directive. The competent
authorities under Regulation (EU) 2022/2554 should also transmit details of major ICT-related incidents and, where
relevant, significant cyber threats to the CSIRTs, the competent authorities or the single points of contact under this
Directive. This is achievable by providing immediate access to incident notifications and forwarding them either
(10) Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for
the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and
(EU) 2016/1011 (see page 1 of this Official Journal).