Document Generated: 2022-06-22
Status: This is the original version (as it was originally made).
“online search engine” means a digital service that allows users to perform searches of, in
principle, all websites or websites in a particular language on the basis of a query on any subject
in the form of a keyword, phrase or other input, and returns links in which information related
to the requested content can be found;
“operator of an essential service” (“OES”) means a person who is deemed to be designated as
an operator of an essential service under regulation 8(1) or is designated as an operator of an
essential service under regulation 8(3);
“relevant law-enforcement authority” has the meaning given in section 63A(1A) of the Police
and Criminal Evidence Act 1984(11); and
“risk” means any reasonably identifiable circumstance or event having a potential adverse
effect on the security of network and information systems.
(3) In these Regulations a reference to—
(a) an Article, Annex, paragraph of an Article or Annex is a reference to the Article, Annex
of paragraph as numbered in Directive 2016/1148;
(b) a numbered regulation, paragraph or Schedule is a reference to the regulation, paragraph
or Schedule as numbered in these Regulations;
(c) “the relevant authorities in a Member State” is a reference to the designated single point
of contact (“SPOC”), computer security incident response team (“CSIRT”) and national
competent authorities for that Member State;
(d) the “designated competent authority for an operator of an essential service” is a reference
to the competent authority that is designated under regulation 3(1) for the subsector in
relation to which that operator provides an essential service;
(e) a “relevant digital service provider” (“RDSP”) is a reference to a person who provides a
digital service in the United Kingdom and satisfies the following conditions—
(i) the head office for that provider is in the United Kingdom or that provider has
nominated a representative who is established in the United Kingdom;
(ii) the provider is not a micro or small enterprise as defined in Commission
Recommendation 2003/361/EC(12);
(f) the “NIS enforcement authorities” is a reference to the competent authorities designated
under regulation 3(1) and the Information Commissioner;
(g) “security of network and information systems” means the ability of network and
information systems to resist, at a given level of confidence, any action that compromises
the availability, authenticity, integrity or confidentiality of stored or transmitted or
processed data or the related services offered by, or accessible via, those network and
information systems.
(4) Expressions and words used in these Regulations which are also used in Directive 2016/1148
have the same meaning as in Directive 2016/1148.
(5) Nothing in these Regulations prevents a person from taking an action (or not taking an action)
which that person considers is necessary for the purposes of safeguarding the United Kingdom’s
essential State functions, in particular—
(11) 1984 c.60. Section 63A(1A) and (1B) were substituted by section 81(2) of the Criminal Justice and Police Act 2001 (c.16).
Subsection (1A) was amended by sections 117(5)(b) and 59 of, and paragraphs 43 and 46 of Schedule 4 to, the Serious and
Organised Crime and Police Act 2005 (c. 15); and section 15(3) of, and paragraph 186 of Schedule 8 to, the Crime and Courts
Act 2013 (c. 22).
(12) Commission Recommendation concerning the definition of micro, small and medium-sized enterprises (OJ No. L 124,
20.5.2003, p. 36).
3