19.7.2016
EN
Official Journal of the European Union
L 194/5
(24)
For the purposes of the identification process, where an entity provides an essential service in two or more
Member States, those Member States should engage in bilateral or multilateral discussions with each other. This
consultation process is intended to help them to assess the critical nature of the operator in terms of cross-border
impact, thereby allowing each Member State involved to present its views regarding the risks associated with the
services provided. The Member States concerned should take into account each other's views in this process, and
should be able to request the assistance of the Cooperation Group in this regard.
(25)
As a result of the identification process, Member States should adopt national measures to determine which
entities are subject to obligations regarding the security of network and information systems. This result could be
achieved by adopting a list enumerating all operators of essential services or by adopting national measures
including objective quantifiable criteria, such as the output of the operator or the number of users, which make it
possible to determine which entities are subject to obligations regarding the security of network and information
systems. The national measures, whether already existing or adopted in the context of this Directive, should
include all legal measures, administrative measures and policies allowing for the identification of operators of
essential services under this Directive.
(26)
In order to give an indication of the importance, in relation to the sector concerned, of the identified operators
of essential services, Member States should take into account the number and the size of those operators, for
example in terms of market share or of the quantity produced or carried, without being obliged to divulge
information which would reveal which operators have been identified.
(27)
In order to determine whether an incident would have a significant disruptive effect on the provision of an
essential service, Member States should take into account a number of different factors, such as the number of
users relying on that service for private or professional purposes. The use of that service can be direct, indirect or
by intermediation. When assessing the impact that an incident could have, in terms of its degree and duration,
on economic and societal activities or public safety, Member States should also assess the time likely to elapse
before the discontinuity would start to have a negative impact.
(28)
In addition to the cross-sectoral factors, sector-specific factors should also be considered in order to determine
whether an incident would have a significant disruptive effect on the provision of an essential service. With
regard to energy suppliers, such factors could include the volume or proportion of national power generated; for
oil suppliers, the volume per day; for air transport, including airports and air carriers, rail transport and maritime
ports, the proportion of national traffic volume and the number of passengers or cargo operations per year; for
banking or financial market infrastructures, their systemic importance based on total assets or the ratio of those
total assets to GDP; for the health sector, the number of patients under the provider's care per year; for water
production, processing and supply, the volume and number and types of users supplied, including, for example,
hospitals, public service organisations, or individuals, and the existence of alternative sources of water to cover
the same geographical area.
(29)
To achieve and maintain a high level of security of network and information systems, each Member State should
have a national strategy on the security of network and information systems defining the strategic objectives and
concrete policy actions to be implemented.
(30)
In view of the differences in national governance structures and in order to safeguard already existing sectoral
arrangements or Union supervisory and regulatory bodies, and to avoid duplication, Member States should be
able to designate more than one national competent authority responsible for fulfilling the tasks linked to the
security of the network and information systems of operators of essential services and digital service providers
under this Directive.
(31)
In order to facilitate cross-border cooperation and communication and to enable this Directive to be
implemented effectively, it is necessary for each Member State, without prejudice to sectoral regulatory
arrangements, to designate a national single point of contact responsible for coordinating issues related to the
security of network and information systems and cross-border cooperation at Union level. Competent authorities
and single points of contact should have the adequate technical, financial and human resources to ensure that
they can carry out the tasks assigned to them in an effective and efficient manner and thus achieve the objectives
of this Directive. As this Directive aims to improve the functioning of the internal market by creating trust and
confidence, Member State bodies need to be able to cooperate effectively with economic actors and to be
structured accordingly.