Skip to main content

ITRE-Amendments to NIS 2-Directive

Page 1

POSITION | CYBERSECURITY | EUROPEAN LEGISLATION

ITRE-Amendments to NIS 2-Directive German industry’s position on the ITRE Committee’s amendments to the Commission proposal for a Directive on measures for a high common level of cybersecurity across the Union, repealing Directive (EU) 2016/1148 July 2021 Executive Summary German industry welcomes the European Commission’s aim to significantly strengthen Europe's cyber-resilience and to create a regulatory level playing field for essential and important entities across the European Union. Cyber and IT security are the basis for a long-term secure digital transformation. All those involved – from hardware and software manufacturers to commercial operators, government agencies and private users – must be actively and holistically involved in strengthening cyber-resilience. German industry will continue to make its contribution to this, because a high degree of cyberresilience is a prerequisite for the smooth functioning of highly digitalised processes in companies. In light of the amendments 92 to 600 proposed by members of the ITRE Committee, German industry wishes to stress the need for a high degree of European harmonisation on cybersecurity legislation. To ensure that the NIS 2 Directive will at the same time not overstrain companies, German industry espouses the following further amendments to the Commission’s NIS 2 proposal: ▪

scope (Article 2 & Annex I+II): While we recognise the necessity to broaden the scope, all SMEs falling into the sectors outlined in Annex I and II should be exempted from the scope, apart from those SMEs that are suppliers of critical hardware and software to essential entities.

▪

definitions (Article 4): BDI urges the co-legislators to alter the proposed definition of “network and information system”, “online marketplaces” and “cloud computing services”. Also, a definition of “management bodies” should be introduced in the NIS 2 Directive.

▪

ENISA’s cybersecurity report (Article 15): ENISA publishing a biennial report that includes merely general information will not augment the EU’s cyber-resilience. Rather, ENISA should publish online up-to-date information on cybersecurity incidents.

▪

management bodies (Article 17 in conjunction with 29): We recognise the responsibility of management bodies for the cybersecurity strategy of an entity. However, no single member should be held accountable for any cybersecurity-related misconduct. We urge the Commission to publish binding recommendations on what constitutes sufficient knowledge and skills.

▪

fines (Article 31): In order to ensure that all entities implement the cybersecurity risk mitigation measures laid down in Article 18 and fulfil their reporting obligations pursuant to Article 20 the introduction of administrative fines seems justified. We advocate for a maximum of two million Euros and a deletion of any reference to percentages of annual turnover.

This paper contains a discussion of selected amendments. For our detailed position, please see: https://english.bdi.eu/publication/news/policy-paper-on-eu-commission-proposal-for-a-nis-2-directive/ Steven Heckler | Digitalisation and Innovation | T: +49 30 2028-1523 | s.heckler@bdi.eu | www.bdi.eu


ITRE-Amendments to NIS 2-Directive

Table of Content Executive Summary ............................................................................................................................ 1 Discussion of selected Amendments proposed by members of the EPP group ......................... 4 Article 2 in conjunction with Annex II – Scope ...................................................................................... 4 Article 4 – Definitions ............................................................................................................................. 4 Article 5 – National cybersecurity strategy ............................................................................................ 5 Article 6 – Coordinated vulnerability disclosure and a European vulnerability registry......................... 5 Article 8 – National competent authorities and single points of contact ................................................ 6 Article 15 – Report on the state of cybersecurity in the Union .............................................................. 7 Article 18 – Cybersecurity risk management measures ........................................................................ 7 Article 20 – Reporting obligations ......................................................................................................... 9 Article 21 – Use of European cybersecurity certification schemes ..................................................... 11 Article 24 – Jurisdiction and territoriality .............................................................................................. 12 Article 25 – Registry for essential and important entities .................................................................... 12 Article 26 – Cybersecurity information-sharing arrangements ............................................................ 12 Article 27 – Voluntary notification of relevant information ................................................................... 12 Article 29 – Supervision and enforcement for essential entities ......................................................... 13 Article 30 – Supervision and enforcement for important entities......................................................... 15 Article 31 – General conditions for imposing administrative fines on essential and important entities15 Article 38 – Transposition .................................................................................................................... 15 Discussion of selected Amendments proposed by members of the S&D group ....................... 16 Article 2 in conjunction with Annex II – Scope .................................................................................... 16 Article 4 – Definitions ........................................................................................................................... 16 Article 5 – National cybersecurity strategy .......................................................................................... 17 Article 6 – Coordinated vulnerability disclosure and a European vulnerability registry....................... 17 Article 15 – Report on the state of cybersecurity in the Union ............................................................ 17 Article 17 – Governance ...................................................................................................................... 18 Article 18 – Cybersecurity risk management measures ...................................................................... 18 Amendment 418: Article 18a – Cybersecurity risk management capabilities ..................................... 19 Article 20 – Reporting obligations ....................................................................................................... 21 Article 21 – Use of European cybersecurity certification schemes ..................................................... 23 Article 25 – Registry for essential and important entities .................................................................... 24 Article 29 – Supervision and enforcement for essential entities ......................................................... 24 Article 30 – Supervision and enforcement for important entities ......................................................... 26 Article 35 – Review .............................................................................................................................. 26

2


ITRE-Amendments to NIS 2-Directive

Discussion of selected Amendments proposed by members of the Renew group ................... 27 Article 2 in conjunction with Annex II – Scope .................................................................................... 27 Article 5 – National cybersecurity strategy .......................................................................................... 27 Article 18 – Cybersecurity risk management measures ...................................................................... 27 Article 19 – EU coordinated risk assessments of critical supply chains ............................................. 27 Article 20 – Reporting obligations ....................................................................................................... 28 Article 21 – Use of European cybersecurity certification schemes ..................................................... 29 Discussion of selected Amendments proposed by members of the Group of the Greens/European Free Alliance ....................................................................................................... 31 Article 5 – National cybersecurity strategy .......................................................................................... 31 Article 6 – Coordinated vulnerability disclosure and a European vulnerability registry....................... 31 Article 15 – Report on the state of cybersecurity in the Union ............................................................ 31 Article 20 – Reporting obligations ....................................................................................................... 31 Article 25 – Registry for essential and important entities .................................................................... 32 Amendment 584 – Article 34a – Right to an effective judicial remedy ................................................ 32 German industry’s proposals for amendments ............................................................................. 33 Recital 54 – Encryption ....................................................................................................................... 33 Article 2 in conjunction with Annex I and II – Scope ........................................................................... 34 Article 4 – Definitions ........................................................................................................................... 35 Article 6 – Coordinated vulnerability disclosure and a European vulnerability registry....................... 38 Article 7 – National cybersecurity crisis management frameworks ..................................................... 39 Article 15 – Report on the state of cybersecurity in the Union ............................................................ 39 Article 17 – Governance ...................................................................................................................... 40 Article 19 – EU coordinated risk assessments of critical supply chains ............................................. 41 Article 20 – Reporting obligations ....................................................................................................... 41 Article 22 – Standardisation ................................................................................................................ 43 Article 24 – Jurisdiction and territoriality .............................................................................................. 43 Article 25 – Registry for essential and important entities .................................................................... 44 Article 26 – Cybersecurity information-sharing arrangements ............................................................ 44 Article 27 – Voluntary notification of relevant information ................................................................... 45 Article 29 – Supervision and enforcement for essential entities ......................................................... 45 Article 30 – Supervision and enforcement for important entities ......................................................... 45 Article 31 – General conditions for imposing administrative fines on essential and important entities46 Article 35 – Review .............................................................................................................................. 47 Imprint ................................................................................................................................................ 48

3


ITRE-Amendments to NIS 2-Directive

Discussion of selected Amendments proposed by members of the EPP group Article 2 in conjunction with Annex II – Scope Amendment 216 – paragraph 1 Summary of Amendment

Evaluation

▪

▪

Only essential entities according to Annex I or important entities according to Annex II respectively that carry out inscope activities in the Union shall fall within the scope of this directive.

German industry welcomes this amendment as it clarifies that only those entities that are active within the Union in sectors falling inside the scope of the NIS 2 have to fulfil the obligations stipulated in this Directive. Especially for MNE, which do not operate NIS 2-related activities inside the Union but outside the Union, this clarification is of utmost importance. German industry favours Amendment 216 over 215.

Amendment 217 – paragraph 1 Summary of Amendment

Evaluation

▪

▪

Manufacturers and providers of ICT products shall fall within the Directive’s scope.

While from a supply-chain perspective the inclusion of entities producing ICT products is welcomed, all categories of entities falling inside the Directive’s scope should be listed in Annex I and II. No additional broadening of the scope should be included in other parts of the Directive. Henceforth, the EPP group should ensure that ICT providers that offer critical components and services for essential and important entities are addressed in the annexes.

Amendment 226 – paragraph 2a Summary of Amendment

Evaluation

▪

▪

The Directive shall apply only to manufacturing facilities of important and essential entities listed in Annexes I and II that are located within the Union.

German industry welcomes the clarification that only manufacturing sites within the Union shall fall under the Directive’s scope. However, it must be ensured that ICT providers that provide critical components and services for essential and important entities are adequately addressed.

Article 4 – Definitions Amendment 244 – paragraph 1 – point 5 Summary of Amendment ▪

The amendment specifies that ‘incidents’ are those events compromising

Evaluation ▪

A company’s internal cybersecurity measures, such as internal security and 4


ITRE-Amendments to NIS 2-Directive

the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of related services offered by, or accessible via network and information systems that are unwanted or unexpected.

penetration tests or scans, could lead to an “incident”. Therefore, we appreciate the proposal to narrow the definition of “incident” in such a way that these internally triggered incidents are falling outside the scope of the Directive.

Article 5 – National cybersecurity strategy Amendment 296 – paragraph 1 Summary of Amendment

Evaluation

▪

▪

The amendment proposes the inclusion of measures to raise awareness for cybersecurity topics among citizens in national cybersecurity strategy.

Ensuring a high degree of cyber-resilience is only possible, if all actors contribute their part. Therefore, we welcome the proposal to include cybersecurity awareness measures for citizens in each Member States’ national cybersecurity strategy.

Article 6 – Coordinated vulnerability disclosure and a European vulnerability registry Amendment 308 – paragraph 2 Summary of Amendment

Evaluation

▪

Only those vulnerabilities for which a patch is available shall be listed in the vulnerability registry.

▪

▪

When several users are affected by the same vulnerability, ENISA should coordinate the installation schedule for mitigation patches.

German industry appreciates the specification that only those vulnerabilities for which a mitigation measure is available shall be listed in the registry. Henceforth, all other vulnerabilities should not be included in the registry as this could have serious security repercussions.

▪

However, we oppose the idea of ENISA deciding when mitigating measures should be made available for installation. Companies will always work hard on providing patches as quickly as possible. Once available, users should be provided with these patches as soon as technically possible. The current formulation could imply that Member States could ask ENISA to delay the publication of mitigating patches, for example for ‘national security’ reasons. BDI urges policy makers to refrain from the inclusion of the last sentence of Amendment 308.

5


ITRE-Amendments to NIS 2-Directive

Amendment 310 – paragraph 2 Summary of Amendment

Evaluation

▪

ENISA shall not be entitled to request from producers of ICT products/solutions the provision of patches within a specific time.

▪

▪

When several users are affected by the same vulnerability, ENISA should coordinate the schedule of the installation of the mitigation patches.

German industry appreciates the specification that ENISA shall not be entitled to require from companies to provide patches within a specific timeframe as ENISA lacks the necessary case-specific information to define a realistic timeframe. In addition, when coding a respective patch companies should not encounter additional outside pressure which could lead to a deterioration of the quality of the respective patch.

▪

Moreover, we oppose the idea of ENISA deciding when mitigating measures should be made available for installation. Companies will always work hard to provide patches as quickly as possible. Once available, users should be provided with these patches as soon as technically feasible. The current formulation could imply that Member States could ask ENISA to delay the publication of mitigating patches, for example for ‘national security’ reasons. BDI urges policy makers to refrain from the inclusion of the last sentence of Amendment 308.

Article 8 – National competent authorities and single points of contact Amendment 317 – paragraph 2 a (new) Summary of Amendment

Evaluation

▪

▪

Member States shall ensure that the competent authorities designated pursuant to paragraph 1 cooperate with competent authorities designated pursuant to the CER Directive for the purposes of information sharing on incidents and cyber threats and the exercise of supervisory tasks.

German industry appreciates the proposal for a high degree of cooperation between the competent authorities pursuant to Article 8 of the NIS 2 Directive and the competent authorities pursuant to Article 8 of the CER Directive.

6


ITRE-Amendments to NIS 2-Directive

Article 15 – Report on the state of cybersecurity in the Union Amendment 366 – paragraph 1 – point c Summary of Amendment

Evaluation

▪

▪

The amendment recommends that the cybersecurity index shall provide for an aggregated assessment of the maturity level of cybersecurity capabilities of the Union.

BDI recommends that if such a biennial report is deemed necessary, which we do not think, than it should provide insights both into the Member States’ and the Union’s cybersecurity capabilities.

Article 18 – Cybersecurity risk management measures Amendment 387 – paragraph 1 Summary of Amendment

Evaluation

▪

▪

German industry welcomes the amendment as it clarifies that measures to be taken by operators of essential and important entities shall be “appropriate and proportionate in terms of time and effort, according to risk analysis”. While German industry strongly advocates the increase of the level of cyber-resilience in the Union, entities should only be required to adopt risk-adequate measures.

▪

The additional reference to international standards is also much appreciated.

With regard to the requirement, that Member States shall ensure that essential and important entities take appropriate and proportionate technical and organisational measures to manage the risks posed to the security of network and information systems which those entities use in the provision of their services, the amendment foresees the following specification: “corrective measures should be appropriate and proportionate in terms of time and effort, according to risk analysis”. Moreover, apart from the state of the art, the amendment now also references international standards (such as ISO31000 and ISA/IEC 27005) as a basis for ensuring that these measures provide for a level of security of network and information systems appropriate to the risk presented.

Amendment 388 – paragraph 1 Summary of Amendment

Evaluation

▪

▪

The amendment stresses that Member States shall ensure that also manufacturers and providers of ICT products take appropriate and proportionate technical and organisational measures to manage the risks posed to the security of network and information systems which those entities use in the provision of their services.

While from a supply-chain perspective the inclusion of entities producing ICT products is welcomed, all categories of entities falling inside the Directive’s scope should be listed in Annex I and II. No additional broadening of the scope should be included in other parts of the Directive. In terms of legal clarity, the legislator should define the scope within Article 2 and the Annexes I and II and should refrain from the inclusion of additional entities in other Articles. Notwithstanding these general considerations 7


ITRE-Amendments to NIS 2-Directive

concerning the Directive’s set-up, we support the underlying idea of adopting cybersecurity measures along the supply chain. Amendment 405 – paragraph 2 – point g b (new) Summary of Amendment

Evaluation

▪

▪

The appropriate and proportionate technical and organisational measures to manage the risks posed to the security of network and information systems that essential and important entities shall implement, shall also include wide adoption of basic computer hygiene practices such as software updates, device configuration, network segmentation, identity and access management or user awareness and training regarding corporate email cyber threats, phishing or social engineering techniques.

As a high level of cyber-resilience can only be achieved if all essential and important entities adopt basis computer hygiene practices, German industry welcomes the proposed amendment.

Amendment 407 – paragraph 3 Summary of Amendment

Evaluation

▪

▪

When taking measures to minimise supply chain risks, entities shall be required to consider the vulnerabilities exposed only by first-level suppliers.

This specification is very appropriate as ICT products and services often possess a very long supply chain which, in particular, medium-sized entities will not always be able to analyse and evaluate. Nonetheless, the cyber-resilience of components integrated in essential and important entities must be sufficiently safeguarded.

Amendment 412 – paragraph 5 Summary of Amendment

Evaluation

▪

▪

ENISA in collaboration with Member States shall draw up advice and guidelines regarding the technical and methodological specifications to be considered in relation to paragraph 2.

Providing companies with guidelines to implement the cybersecurity risk mitigation measures pursuant to Article 2 is a useful step, especially for companies that do not have a large IT team. When developing these guidelines, ENISA and Member States should strive to provide recommendations that are easy to understand and implement.

8


ITRE-Amendments to NIS 2-Directive

▪

When developing implementing acts, the Commission shall also consult all relevant stakeholders by means of a formal, open, transparent and inclusive consultation process.

▪

It is much appreciated that the Commission shall consult with industry when developing implementing acts. While a high degree of harmonisation concerning cybersecurity requirements is appreciated, German industry wants to stress that implementing acts should not lead to additional implementing costs for entities, which might already have implemented country-specific requirements and – to this end – had to invest in their IT security measures.

Article 20 – Reporting obligations Amendment 430 – paragraph 2 – subparagraph 1 Summary of Amendment

Evaluation

▪

▪

Deletion of the entire paragraph requiring essential and important entities to notify, without undue delay, the competent authorities or the CSIRT of any significant cyber threat that those entities identify that could have potentially resulted in a significant incident.

BDI welcomes the deletion of the notification of cyber-threats that could have resulted in a significant incident.

Amendment 434 – paragraph 2 – subparagraph 2 Summary of Amendment

Evaluation

▪

▪

In order to enhance Europe’s cyber-resilience holistically, BDI regards it as necessary that all actors have the necessary information to contribute to enhanced cyber-resilience.

▪

However, only recipients of services that are affected by a cyber incident should be informed. Therefore, BDI welcomes the deletion of this paragraph from Article 20.

Deletion of the entire paragraph requiring entities to notify, without undue delay, the recipients of their services that are potentially affected by a significant cyber threat of any measures or remedies that those recipients can take in response to that threat.

Amendment 447 – paragraph 4 – subparagraph 1 – point a Summary of Amendment

Evaluation

▪

▪

The time which entities have to hand in the first report on an incident is increased from 24 hours to no later than 72 hours.

BDI welcomes the increase of the reporting time from 24 hours to 72 hours as it allows entities to focus on taking all necessary mitigating measures first before having to report an incident.

9


ITRE-Amendments to NIS 2-Directive

Amendment 451 – paragraph 4 – subparagraph 1 – point c Summary of Amendment ▪

Instead of handing in“a final report, entities shall provide the competent authority with a status report not later than three months for an essential entity and no later than four months for an important entity after the submission of the initial notification.

Evaluation ▪

BDI welcomes this amendment. Indeed, companies need much more time to analyse cyberattacks.

Amendment 456 – paragraph 4 – subparagraph 1 – point c a (new) Summary of Amendment

Evaluation

▪

▪

In addition to the immediate, interim and status report, the EPP’s amendment foresees the handing-in of a final report one month after the incident had been mitigated.

While BDI welcomes the idea of handing-in a final report one month after the incident has been completely mitigated, this should happen instead of the status report and not in addition to such a report.

Amendment 457 – paragraph 4 – subparagraph 1 – point 1 a (new) Summary of Amendment

Evaluation

▪

▪

Addition of:

Member States may establish a single-entry point for all notifications required under this Directive, the Regulation (EU) 2016/679, Directive2002/58/EC and sector specific legislation.

BDI welcomes the introduction of a single-entry point for all notifications. However, we would prefer a European single entry point rather than 27 different ones.

Amendment 458 – paragraph 4 – subparagraph 1 – point 1 b (new) Summary of Amendment

Evaluation

▪

▪

Addition of:

ENISA, in cooperation with the Cooperation Group, should develop common notification templates by means of guidelines to streamline the reporting information requested by this Directive and decrease the burdens for reporting entities

BDI welcomes the development of notification templates by ENISA, this will help especially MNEs as it harmonises the EU-wide reporting of cyberattacks.

Amendment 459 – paragraph 4 – subparagraph 1 – point 1 c (new) Summary of Amendment

Evaluation

▪

▪

Addition of:

Member States shall ensure confidentiality and appropriate protections around sensitive information about incidents shared with competent authorities, and enact parameters around how incident information is further shared and reused.

BDI appreciates that competent authorities shall be required to ensure the protection of sensitive data concerning cyber-incidents.

10


ITRE-Amendments to NIS 2-Directive

Amendment 461 – paragraph 5 Summary of Amendment

Evaluation

▪

▪

CSIRTs and national authorities shall provide reporting entities with an actionable advice.

Incident reporting should indeed be no longer a one-way road. Therefore, BDI welcomes the requirement that CSIRTs or competent authorities shall provide advice to reporting entities. This could be very helpful for attacked companies, especially for SMEs.

Amendment 467 – paragraph 7 Summary of Amendment

Evaluation

▪

▪

According to the Commission proposal, national competent authorities were entitled, after consulting the entity concerned, to inform the public about the incident or require the entity to do so. The amendment requires the entity itself to inform the public about the incident.

BDI welcomes the proposed amendment of the paragraph as it minimises bureaucratic requirements. Entities themselves should publish the information and not the CSIRTs or other authorities.

Amendment 482 – paragraph 11 Summary of Amendment ▪

By derogation from the Commission’s proposal, no longer shall the Commission specify by way of implementing act the type of information, the format and the procedure of a notification, rather the EPP proposes that ENISA shall develop an EU-wide template thereof.

Evaluation ▪

BDI welcomes the deletion of the Commission’s right to introduce implementing acts and that instead ENISA will develop EU-wide information templates. It seems appropriate that such technicalities will be developed by the Agency rather than by the Commission.

Article 21 – Use of European cybersecurity certification schemes Amendment 495 – paragraph 2 Summary of Amendment

Evaluation

▪

▪

The amendment foresees the deletion of the following paragraph:

The Commission shall be empowered to adopt delegated acts specifying which categories of essential entities shall be required to obtain a certificate and under which specific European cybersecurity certification schemes pursuant to paragraph 1. The delegated acts shall be adopted in accordance with Article 36.

German industry urges the co-legislators to reduce the number of delegated acts to be introduced after the coming into effect of the NIS 2 Directive. Therefore, we appreciate the deletion of this paragraph, especially if a respective delegated act was to be published with a significant delay after the coming into effect of the NIS 2. However, more regulatory harmonisation would be much appreciated. This should be either achieved by publishing a regulation or by ENISA issuing technical guidelines.

11


ITRE-Amendments to NIS 2-Directive

Article 24 – Jurisdiction and territoriality Amendment 516 – paragraph 2 a (new) Summary of Amendment

Evaluation

▪

▪

Addition of:

Essential and important entities should be subject to this Directive only in those Member States where they perform activities relevant to their designation as essential or important entities.

BDI welcomes the clarification that an entity only falls under the scope of the Directive in those Member States where it conducts business activities covered by Article 2 and the Annexes I and II.

Article 25 – Registry for essential and important entities Amendment 519 – paragraph 1 – introductory part Summary of Amendment

Evaluation

▪

▪

When setting up its registry, no longer shall entities submit the respective information, but the amendment seems to suggest that ENISA shall provide the information concerning the entities.

When developing a registry for certain essential and important entities, ENISA should ask the respective entities to provide the necessary information. Henceforth, BDI objects Amendment 519.

Amendment 521 – paragraph 3 Summary of Amendment

Evaluation

▪

▪

Deletion of the entire paragraph requiring ENISA to forward upon receipt of the information under paragraph 1 these to the respective single point of contact in each entity’s main establishment.

Entities should only be obliged to hand in information once. Henceforth, ENISA should be required to directly exchange these information with respective national authorities.

Article 26 – Cybersecurity information-sharing arrangements Amendment 525 – paragraph 1 point b Summary of Amendment

Evaluation

▪

▪

Addition of containment and prevention, facilitating collaboration in cyber threat research among public entities, private entities and research bodies.

BDI welcomes a strong collaboration and partnership of public and private entities with research bodies.

Article 27 – Voluntary notification of relevant information Amendment 537 – paragraph 1 Summary of Amendment

Evaluation

▪

▪

Inclusion of the specification that entities within the scope and those falling outside the scope of this Directive shall be entitled to voluntary notification.

BDI welcomes the specification that now does include also entities within the scope of this Directive.

12


ITRE-Amendments to NIS 2-Directive

Article 29 – Supervision and enforcement for essential entities Amendment 543 – paragraph 2 – point b Summary of Amendment

Evaluation

▪

▪

Member States shall ensure that competent authorities, where exercising their supervisory tasks in relation to essential entities, have the power to subject essential entities to annual audits (previously regular).

German industry appreciates the specification of the frequency in which competent authorities can audit essential entities. However, we would suggest audits to take place only every two years.

Amendment 544 – paragraph 2 – point b – point i (new) Summary of Amendment

Evaluation

▪

▪

In deviation from Amendment 543, an ad hoc audit can be carried out in cases justified on the ground of a significant incident or non-compliance by the essential entity.

The provision seems sensible as long as the proportionality of such audits is ensured. In addition, the amendment should clarify that “significant incidents” should only lead to audits in the essential entity that had encountered the significant incident.

Amendment 548 – paragraph 2 a (new) Summary of Amendment

Evaluation

▪

▪

Amendment 548 stresses that where exercising their power under points (a) to (d) in paragraph 2, the competent authorities shall follow a due process in order to minimise the impact on business processes for the entity.

German industry appreciates the intention to minimise impacts on businesses.

Amendment 553 – paragraph 4 – point i Summary of Amendment

Evaluation

▪

▪

The amendment foresees the integration of “where necessary for risk management purposes” in point i of para. 4:

make a public statement, where necessary for risk management purposes, which identifies the legal and natural person(s) responsible for the infringement of an obligation laid down in this Directive and the nature of that infringement

In comparison to amendment 553, amendment 552 contains the more suitable approach from industry’s perspective. However, taking everything into account, we advocate the deletion of para. 4 point i.

Amendment 556 – paragraph 5 – subparagraph 1 – introductory part Summary of Amendment

Evaluation

▪

▪

Integration of or manufacturers and providers of ICT products are in para. 5 sub-para 1.

We oppose the broadening of the scope outside Article 2 and the Annexes I and II. All entities falling into the scope of the Directive must be clearly stated in Article

13


ITRE-Amendments to NIS 2-Directive

2 and/or the Annexes I and II. See our comments on amendment 388. Amendment 559 – paragraph 5 – subparagraph 1 – point a Summary of Amendment

Evaluation

▪

▪

Integration of or manufacturers and providers of ICT products are in para. 5 sub-para 1.

We oppose the broadening of the scope outside Article 2 and the Annexes I and II. All entities falling into the scope of the Directive must be clearly stated in Article 2 and/or the Annexes I and II. See our comments on amendment 388.

Amendment 559 – paragraph 5 – subparagraph 1 – point b Summary of Amendment

Evaluation

▪

▪

The amendment foresees the deletion of:

impose or request the imposition by the relevant bodies or courts according to national laws of a temporary ban against any person discharging managerial responsibilities at chief executive officer or legal representative level in that essential entity, and of any other natural person held responsible for the breach, from exercising managerial functions in that entity.

We welcome the proposal to delete paragraph 5 – subparagraph 1 – point b. As the NIS 2-Directive already includes very far-reaching supervisory and enforcement powers – including fines – it should be the responsibility of the respective entity to take any necessary employee-related measures. The competent authority shall not have the competence to oust any employee – including members of the management body.

Amendment 564 – paragraph 5 – subparagraph 1 – point b Summary of Amendment

Evaluation

▪

▪

Integration of or manufacturers and providers of ICT products are in para. 5 sub-para 1.

We oppose the broadening of the scope outside Article 2 and the Annexes I and II. All entities falling into the scope of the Directive must be clearly stated in Article 2 and/or the Annexes I and II. See our comments on amendment 388.

Amendment 568 – paragraph 5 – subparagraph 2 Summary of Amendment

Evaluation

▪

▪

Integration of or manufacturers and providers of ICT products are in para. 5 sub-para 1.

We oppose the broadening of the scope outside Article 2 and the Annexes I and II. All entities falling into the scope of the Directive must be clearly stated in Article 2 and/or the Annexes I and II. See our comments on amendment 388.

14


ITRE-Amendments to NIS 2-Directive

Amendment 571 – paragraph 7 – point c Summary of Amendment

Evaluation

▪

▪

The amendment foresees the deletion of the possibility that enforcement actions or sanctions from competent authorities can also be evoked in case of potential damage or losses that could have been triggered, insofar as they can be determined.

German industry welcomes the deletion of any reference to potential losses, as the explanation rightly states that enforcement action or sanction from competent authorities should only apply when actual damages or losses have occurred.

Article 30 – Supervision and enforcement for important entities Amendment 578 – paragraph 4 – point h Summary of Amendment

Evaluation

▪

▪

The amendment foresees the integration of where necessary for risk management purposes in point h of para. 4:

make a public statement, where necessary for risk management purposes, which identifies the legal and natural person(s) responsible for the infringement of an obligation laid down in this Directive and the nature of that infringement

In comparison to amendment 578, amendment 577 contains the more suitable approach from industry’s perspective. However, taking everything into account, we advocate the deletion of the entire para. 4 point h.

Article 31 – General conditions for imposing administrative fines on essential and important entities Amendment 579 – paragraph 1 Summary of Amendment

Evaluation

▪

▪

Administrative fines shall only be imposed on essential or important entities if the infringement was intentional, negligent or the entity had prior notice of the possibility of committing an infringement

German industry welcomes the proposed amendment since administrative finds should only be the ultima ratio. The legislators need to recognise the fact that it is not the entity that is the real criminal but rather those that initiate cybersecurity attacks.

Article 38 – Transposition Amendment 589 – paragraph 1 Summary of Amendment

Evaluation

▪

▪

The transposition period shall be increased from 18 to 24 months.

A longer transposition period is in general appreciated, if it is utilised to discuss the national implementation with relevant stakeholders.

15


ITRE-Amendments to NIS 2-Directive

Discussion of selected Amendments proposed by members of the S&D group Article 2 in conjunction with Annex II – Scope Amendments 231, 233, 235 – paragraphs 5a (new), 5b, 5c Summary of Amendment

Evaluation

▪

▪

The Amendments clarify the legal basis (GDPR) for the processing of personal data when complying with requirements stipulated in the NIS 2 Directive

German industry welcomes this clarification and stresses that essential and important entities will always process personal data to the extent necessary and proportionate for the purposes of ensuring network and information security in accordance with the obligations set out in the NIS 2 Directive.

Amendment 238 – paragraph 6 Summary of Amendment

Evaluation

▪

▪

Sector-specific legislative acts requiring essential or important entities either to adopt cybersecurity risk management measures or to notify incidents or significant cyber threats shall, where possible, refer to the definitions in Article 4 of this Directive.

German industry appreciates a maximum degree of harmonisation of legal acts addressing “cybersecurity”. The current development of a regulatory zoo must be ended. Rather, the EU and its Member States should strive for a high degree of harmonisation.

Article 4 – Definitions Amendment 243 – paragraph 1 – point 4 a (new) Summary of Amendment

Evaluation

▪

▪

The amendment defines a near miss as an event which could have caused harm, but was successfully prevented from fully transpiring

BDI welcomes the inclusion of a clear and unambiguous definition of ‘near miss’ as it provides entities with regulatory clarity. It is equally important that a ‘near miss’ does not impose additional obligations but only empowers entities to exchange information as foreseen in Art. 26 paragraph 1.

Amendment 245 – paragraph 1 – point 7 a (new) Summary of Amendment

Evaluation

▪

▪

The amendment adds a definition of the term risk meaning the potential for loss or disruption caused by an incident and is to be expressed as a combination of the magnitude of such loss or disruption and the likelihood of occurrence of that incident.

BDI welcomes the inclusion of this definition, especially considering the need for a risk-based regulatory approach.

16


ITRE-Amendments to NIS 2-Directive

Article 5 – National cybersecurity strategy Amendment 284 – paragraph 2 – point a a (new) Summary of Amendment

Evaluation

▪

▪

German industry welcomes the proposal to provide companies, public administration and other entities with guidelines concerning supply chain security with a focus on cybersecurity.

▪

However, we urge the co-legislators to only opt for non-binding measures, as each entity must be able to decide on the concrete steps it takes to enhance its own cyber-resilience.

The amendment foresees the inclusion in the national cybersecurity strategies of guidelines addressing cybersecurity in the supply chain for ICT products and services used by entities outside the scope of this Directive.

Article 6 – Coordinated vulnerability disclosure and a European vulnerability registry Amendment 311 – paragraph 2 Summary of Amendment

Evaluation

▪

▪

ENISA shall take all necessary technical and organisational measures to ensure the security and integrity of the registry.

German industry welcomes this specification as a high degree of protection of these very sensitive data must be ensured.

Article 15 – Report on the state of cybersecurity in the Union Amendment 364 – paragraph 1 – point a a (new) Summary of Amendment

Evaluation

▪

▪

ENISA’s biennial report shall additionally include the level of cyber-awareness among citizens and consumers.

While a holistic approach to cybersecurity is essential to achieve a high degree of cyber-resilience, it has to be questioned whether ENISA has the necessary resources to deliver such a farreaching report. If ENISA shall publish such a far-reaching report every two years, we call on the co-legislators to significantly increase the number of personal employed by ENISA.

Amendment 368 – paragraph 1 – point c b Summary of Amendment ▪

ENISA’s report on the state of cybersecurity in the Union should also assess the level of convergence among Member States’ national cybersecurity strategies.

Evaluation ▪

The harmonisation of Member States’ cybersecurity strategies is important. ENISA should aid Member States to harmonise their national strategies.

17


ITRE-Amendments to NIS 2-Directive

Article 17 – Governance Amendment 383 – paragraph 2 Summary of Amendment

Evaluation

▪

▪

German industry welcomes the specification that only members of the management body of entities falling inside the scope of the NIS 2 Directive shall be required to follow cybersecurity training.

▪

While cybersecurity awareness is important also for other employees of essential and important entities, each company must decide on its own which employees should receive specific training according to the job profile of each single employee.

The amendment includes two aspects: Firstly, only members of the management body of essential and important entities shall be required to follow specific trainings. Secondly, Member States shall encourage essential and important entities to offer similar trainings to all employees.

Article 18 – Cybersecurity risk management measures Amendment 396 – paragraph 2 – point c a (new) Summary of Amendment ▪

Essential and important entities’ appropriate and proportionate technical and organisational measures to manage the risks posed to the security of network and information systems shall – where relevant – also include multi-factor authentication and/or continuous authentication solutions.

Evaluation ▪

The NIS 2 Directive should not mention specific security measures as the legislative act should be technology-neutral and future-proof.

Amendment 399 – paragraph 2 – point f a (new) Summary of Amendment

Evaluation

▪

▪

The appropriate and proportionate technical and organisational measures to manage the risks posed to the security of network and information systems implemented by essential and important entities shall also include the deployment of secured voice, video and text communications, and of secured emergency communications systems within the entity.

The NIS 2 Directive should not mention specific security measures as the legislative act should be technology-neutral and future-proof.

18


ITRE-Amendments to NIS 2-Directive

Amendment 400 – paragraph 2 – point f b (new) Summary of Amendment

Evaluation

▪

▪

The appropriate and proportionate technical and organisational measures to manage the risks posed to the security of network and information systems implemented by essential and important entities shall also include periodic compromise assessments of the entity’s network, infrastructure and devices.

The NIS 2 Directive should not mention specific security measures as the legislative act should be technology-neutral and future-proof.

Amendment 418: Article 18a – Cybersecurity risk management capabilities Summary of Amendment

Evaluation

▪

▪

The amendment foresees the introduction of an entire new article:

Member States shall ensure that entities referred to in Annex I and Annex II have the capabilities to implement the requirements of Article 18 by: 1. Prepare and identify pursuant to Article 18(2)(a): (a) maintain records of essential or important functions and network and information systems supporting them, including their interdependencies within an entity and into the supply chain. Have a process in place to regularly review and update;

To German industry it remains unclear which actor must fulfil the tasks stipulated in the proposed Article 18a. For instance, the text leaves it open whether entities or Member States have to “have a process in place to regularly perform or commission a comprehensive risk or compromise assessment and to identify risk and assess cyber threats and vulnerabilities on networks and information systems” (cf. Art. 18a para. 1 point a).

(b) have a process in place to regularly perform or commission a comprehensive risk or compromise assessment and to identify risk and assess cyber threats and vulnerabilities on networks and information systems. 2. Protect, detect and defend pursuant to Article 18(2)(b): (a) use appropriate tools to real-time monitor networks and information systems to effectively detect malfunctions and cyber threats and mitigate their impact; (b) ensure resilience, continuity, confidentiality, integrity, availability and authenticity of network and information systems and associated access rights, including where

19


ITRE-Amendments to NIS 2-Directive

appropriate, by protecting data from exfiltration or other forms of interference both at rest and in transit using appropriate technical and organizational controls and risk assessment procedures; (c) have the processes and capabilities in place to dynamically adjust the risk mitigation measures and efforts to the cyber threats and incidents as they occur; (d) have mechanisms in place that enable different layers of technical and organizational controls and criteria that activate actions pursuant to Article18(2)(b) of this Directive taking into account the risk. 3. Recover pursuant to Article 18(2)(c): (a) have processes and tools in place to enable timely processing and resolution of incidents while prioritizing and mitigating risks; (b) have processes and tools in place to enable dedicated plans to contain, recover from cyber threats and accidental incidents and ensure service continuity; (c) test regularly the efficacy of the measures foreseen pursuant to Article 18(2)(c); (d) (d) maintain a record of all incidents having a significant impact on the provision of the service, and proper procedures for timely notifying the management body of the entity of such incidents. To the extent relevant, the processes described in this article may be constituted by processes established pursuant to Article 28, 30 and 32 of Regulation (EU) 2016/679.

20


ITRE-Amendments to NIS 2-Directive

Article 20 – Reporting obligations Amendment 424 – paragraph 1 Summary of Amendment

Evaluation

▪

▪

In addition to informing competent authorities and/or CSIRTs without undue delay in case of a cyber-incident, essential and important entities shall also, where the incident concerns the provisions of entities’ services, notify affected recipients about the unavailability or underlying risks of use of the service in order to mitigate the adverse effects of the incident. However, essential and important entities may deviate from notifying affected recipients in case of overriding reasons inducing, but not limited to, that a notification worsens the impact of an ongoing incident.

While mitigating the impact of an attack must always come first, German industry recognises the necessity to inform affected customers.

Amendment 431 – paragraph 2 – subparagraph 1 Summary of Amendment

Evaluation

▪

▪

Deletion of the entire paragraph requiring essential and important entities to notify, without undue delay, the competent authorities or the CSIRT of any significant cyber threat that could have potentially resulted in a significant incident.

BDI welcomes the deletion of the notification of cyber-threats that potentially could have resulted in a significant incident.

Amendment 433 – paragraph 2 – subparagraph 2 Summary of Amendment

Evaluation

▪

▪

In order to enhance Europe’s cyber-resilience holistically, BDI regards it as necessary that all actors have the necessary information to contribute to enhanced cyber-resilience.

▪

However, only recipients of services that are affected by a cyber-incident should be informed. Therefore, BDI welcomes the deletion of this subparagraph.

Deletion of the entire paragraph requiring entities to notify, without undue delay, the recipients of their services that are potentially affected by a significant cyber threat of any measures or remedies that those recipients can take in response to that threat.

Amendment 436 – paragraph 2 – subparagraph 2 Summary of Amendment

Evaluation

▪

▪

Addition of and in respect to their contractual arrangements.

In order not to confuse customers, only those customers that are affected should be notified. Henceforth, we appreciate Amendment 433 and reject the proposed Amendment 436.

21


ITRE-Amendments to NIS 2-Directive

Amendment 445 – paragraph 4 – subparagraph 1 – point a (new) Summary of Amendment

Evaluation

▪

▪

In addition to the obligation to send in an immediate report within 72 hours (cf. Amendment 448), the S&D groups wants entities to send an early warning within 24 hours after having become aware of an incident.

BDI is convinced that an early warning is not needed in addition to the immediate report within 72 hours. Attacked companies should focus on tackling the incident first, rather than having to report twice within the first 72 hours.

Amendment 448 – paragraph 4 – subparagraph 1 – point a Summary of Amendment

Evaluation

▪

▪

The timeframe for an initial notification is increased from 24 hours to 72 hours.

BDI welcomes the increase of the reporting time from 24 hours to 72 hours.

Amendment 453 – paragraph 4 – subparagraph 1 – point c Summary of Amendment ▪

Change of wording from “final report” to comprehensive report.

Evaluation ▪

BDI welcomes the change of the wording. Nevertheless, BDI is convinced that a comprehensive report after three months could provide more reliable information as mitigating a complex cyberincident is a time-consuming task.

Amendment 471 – paragraph 8 Summary of Amendment

Evaluation

▪

▪

The amendments include an addition of a compliance obligation for information sharing across the Member States’ CSIRTs or authorities.

BDI welcomes the addition of a compliance clause to ensure data protection.

Amendment 481 – paragraph 8 Summary of Amendment

Evaluation

▪

▪

Addition of:

ENISA, in cooperation with the Cooperation Group, shall develop common incident notification templates by (date of transposition deadline of the Directive), to streamline the reporting obligations of essential and important entities, and simplify the sharing of relevant information referred to in point (b) of paragraph 1 of this Article.

BDI welcomes the development of notification templates by ENISA. This will especially help MNEs which, in case of an incident, have to report incidents in various Member States.

22


ITRE-Amendments to NIS 2-Directive

Article 21 – Use of European cybersecurity certification schemes Amendment 487 – paragraph 1 Summary of Amendment

Evaluation

▪

▪

While we appreciate the idea of a higher degree of EU-wide harmonisation, the proposed additional legislative act will just add to the already existing regulatory zoo. Therefore, we oppose the idea of an additional legislative act that specifies which essential and important entities have to certify products and services.

▪

Rather, we encourage the EU Commission to propose horizontal cybersecurity requirements based on the New Legislative Framework, i.e. a horizontal framework that will be applicable to all sectors where there are currently no sector-specific requirements regarding IT security. At the same time, sectors, such as the automotive industry, where standards already exist should be exempted from such a regulatory act.

The amendment proposes to elevate the overall level of cybersecurity resilience, by granting the Commission the possibility to issue a legislative proposal under Article 114 TFEU requiring certain essential and important entities to certify certain ICT products, ICT services and ICT processes under existing specific European cybersecurity certification schemes. Such certification requirements shall foresee a transition period that allows providers and end users to get into conformity, and they shall be developed in a way that avoids market distortion.

Amendment 488 – paragraph 1 Summary of Amendment ▪

Member States shall encourage essential and important entities to certify certain ICT products, ICT services and ICT processes, developed either by the essential and important entities or procured from third parties, under specific European cybersecurity certification schemes adopted pursuant to Article 49 of Regulation (EU) 2019/881, or under equivalent and internationally accepted certification schemes.

Evaluation ▪

BDI appreciates the new wording as it also references internationally recognised certification schemes, which is of utmost importance for inter alia the automotive sector, where UNECE R155 and ISO 5112 will be vital to certify solutions in the area of connected vehicles and hence, where no dedicated EU CSA scheme will be required.

▪

In addition to allowing certification based on international standards, we urge the Commission to introduce horizontal NLF-based cybersecurity requirements. German industry expressly supports the European Commission's considerations, supported by the European Council, to introduce mandatory, horizontal cybersecurity requirements based on the principles of the New Legislative Framework. A regulatory bridge to schemes developed under the Cybersecurity Act must be introduced.

23


ITRE-Amendments to NIS 2-Directive

Details on BDI’s proposal for introducing horizontal, mandatory cybersecurity requirements based on the NLF can be found here: https://english.bdi.eu/publication/news/eu-wide-cybersecurity-requirements/ Amendment 494 – paragraph 2 Summary of Amendment

Evaluation

▪

▪

The amendment foresees the deletion of the following paragraph:

The Commission shall be empowered to adopt delegated acts specifying which categories of essential entities shall be required to obtain a certificate and under which specific European cybersecurity certification schemes pursuant to paragraph 1. The delegated acts shall be adopted in accordance with Article 36.

German industry urges the co-legislators to reduce the number of delegated acts introduced pursuant to the coming into effect of the NIS 2 Directive. Therefore, we appreciate the deletion of this paragraph, especially if a respective delegated act were to be published with a significant delay after the coming into effect of the NIS 2. However, more regulatory harmonisation would be much appreciated. This should be either achieved by publishing a regulation or by ENISA issuing technical guidelines.

Article 25 – Registry for essential and important entities Amendment 518 – paragraph 1 – introductory part Summary of Amendment

Evaluation

▪

▪

Addition of:

ENISA shall establish appropriate information classification and management protocols to ensure the security and confidentiality of disclosed information, and restrict the access, storage, and transmission of such information to intended users.

BDI welcomes the introduction of information classification and management protocols by ENISA to ensure confidentiality and data protection.

Article 29 – Supervision and enforcement for essential entities Amendment 552 – paragraph 4 – point i Summary of Amendment

Evaluation

▪

▪

The amendment foresees the deletion of the following provision:

make a public statement which identifies the legal and natural person(s) responsible for the infringement of an obligation laid down in this Directive and the nature of that infringement

We agree with the members of the S&D group that this provision would be too far-reaching.

24


ITRE-Amendments to NIS 2-Directive

Amendment 557 – paragraph 5 – subparagraph 1 – point a Summary of Amendment

Evaluation

▪

▪

The amendment foresees the following alterations (in italics):

where applicable, temporarily suspend or request a certification or authorisation body to temporarily suspend a certification or authorisation concerning part or all the services or activities provided by an essential entity until the entity takes the necessary action to remedy the deficiencies or comply with the requirements of the competent authority for which such sanctions were applied.

We appreciate this specification as it leads to a higher degree of proportionality.

Amendment 565 – subparagraph 1 – point b Summary of Amendment

Evaluation

▪

▪

German industry is surprised to read that only C-level executives of private entities will be responsible for the implementation of the requirements pursuant to the NIS 2 Directive and that respective employees in public administration entities cannot be banned from their duties in case of non-compliance.

▪

German industry urges the S&D Group to introduce a language that rules out such a possibility for all entities regardless of the ownership of that entity.

▪

In addition, public administrations, which is often handling highly sensitive data of individuals and companies alike as well as offering vita public services, should not be exempt from the scope of the NIS 2 Directive. They have to fulfil the exact same obligations as other essential entities.

The amendment foresees that national competent authorities can impose or request the imposition by the relevant bodies or courts according to national laws of a temporary ban against any person discharging managerial responsibilities at chief executive officer or legal representative level in that essential entity from exercising managerial functions in that entity, apart from legal representatives of public administration entities as referred to in point (23) of Article 4.

Amendment 570 – paragraph 7 – point c Summary of Amendment

Evaluation

▪

▪

The amendment foresees the deletion of the possibility that enforcement actions or sanctions from competent authorities can also be evoked in case of potential damage or losses that could have been triggered, insofar as they can be determined.

German industry welcomes the deletion of any reference to potential losses, as the explanation rightly states that enforcement action or sanction from competent authorities should only apply to actual damages or losses.

25


ITRE-Amendments to NIS 2-Directive

Article 30 – Supervision and enforcement for important entities Amendment 577 – paragraph 4 – point h Summary of Amendment

Evaluation

▪

▪

The amendment foresees the deletion of the following provision:

make a public statement which identifies the legal and natural person(s) responsible for the infringement of an obligation laid down in this Directive and the nature of that infringement

We agree with the members of the S&D group that this provision would be too far-reaching.

Article 35 – Review Amendment 586 – paragraph 1 a (new) Summary of Amendment

Evaluation

▪

▪

The amendment entails the definition of digital platforms being characterised as “very large” according to the Digital Services Act of falling under the gatekeeper definition pursuant to the Digital Markets Act as essential entities, rather than important entities:

As regards Digital Providers referred to in point (6) of Annex II, where platforms operated by such important entities are classified as very large online platforms within the meaning of Article 25 of Regulation (EU) XXXX/XXXX [Single Market For Digital Services (Digital Services Act) and amending Directive 2000/31/EC], or where the providers of core platform services are designated as gatekeepers within the meaning of Article 3 of Regulation (EU) XXXX/XXXX [Contestable and fair markets in the digital sector (Digital Markets Act)], these providers shall be designated as essential entities within the meaning of this Directive to adequately address the functioning of the economy and society in relation to cybersecurity, given the systemic risk stemming from the functioning and use made of their services in the Union, or the important gateway function that their core platform services serve for business users to reach end users.

As large platforms, defined as gatekeepers pursuant to the Digital Markets Acts, have a large market power and also a large economic weight their classification as essential rather than important entities is understandable. Nonetheless, the co-legislators have to ensure sufficient legal clarity regarding the classification of companies within the two types of entities. This should always happen either within Article 2 or the Annexes I or II. No addition to the scope should be included in other parts of the Directive.

26


ITRE-Amendments to NIS 2-Directive

Discussion of selected Amendments proposed by members of the Renew group Article 2 in conjunction with Annex II – Scope Amendment 215 – paragraph 1 Summary of Amendment

Evaluation

▪

▪

Only essential entities according to Annex I or important entities according to Annex II respectively that provide their services or carry out their activities within the Union shall fall within the scope of this directive.

German industry welcomes this clarification as it minimises the potential extra territorial effect of the NIS 2 Directive and hence, enhances the directive’s legal clarity.

Article 5 – National cybersecurity strategy Amendment 300 – paragraph 2 b (new) Summary of Amendment

Evaluation

▪

▪

The amendment recommends the inclusion of policy measures addressing the ransomware threat and disrupting the ransomware business model in each Member States’ cybersecurity strategy.

Considering the recent attacks and the increased repercussions emanating from ransomware attacks, German industry regards the introduction of concrete policy measures against the ransomware business model as an appropriate suggestion.

Article 18 – Cybersecurity risk management measures Amendment 395 – paragraph 2 – point c Summary of Amendment ▪

Essential and important entities’ appropriate and proportionate technical and organisational measures to manage the risks posed to the security of network and information systems shall – besides business continuity and crisis management – also include backup-management.

Evaluation ▪

Backup-management is one of many measures in the toolbox of business continuity management. Naming it expressively here does not bring additional clarity. Therefore, we doubt the added value of amendment 395.

Article 19 – EU coordinated risk assessments of critical supply chains Amendment 419 – paragraph 1 a (new) Summary of Amendment

Evaluation

▪

▪

The following wording is moved from Recital 47:

To identify the specific critical ICT services, systems or products supply chains that are subject to a coordinated risk assessment, the following criteria

German industry wishes to stress the need for an EU-wide harmonised approach to risk assessments of critical supply chains. Therefore, German industry appreciates the amendment.

27


ITRE-Amendments to NIS 2-Directive

shall be taken into account: a) the extent to which essential and important entities use and rely on specific critical ICT services, systems or products; b) the relevance of specific critical ICT services, systems or products for performing critical or sensitive functions, including the processing of personal data; c) the availability of alternative ICT services, systems or products; d) the resilience of the overall supply chain of ICT services, systems or products against disruptive events; and e) (e) the potential significance to entities' activities of emerging ICT services, systems or products.

Article 20 – Reporting obligations Amendment 426 – paragraph 1 Summary of Amendment

Evaluation

▪

In contrast to the Commission’s proposal which entailed that entities had to notify without undue delay incidents having a significant impact on the provision of an entity’s services, the amendment proposes that entities have to notify without undue delay incidents.

▪

BDI does not welcome this significant widening of the reporting obligations. Entities should inform the competent authority or the CSIRTs about those cyberattacks that had repercussions for the provision of their service.

▪

▪

In addition, where the competent authorities or the CSIRTs consider that it is necessary, essential and important entities may notify other essential and important entities of any significant incident occurring in their sector.

In addition, if the competent authorities or the CSIRT deems it necessary that other entities should be informed about an incident, they should provide these entities with the respective anonymised information themselves, as entities will regularly lack the respective contact details of other entities.

Amendment 464 – paragraph 5 a (new) Summary of Amendment

Evaluation

▪

▪

Member States shall establish a singleentry point for all notifications required under this Directive.

BDI welcomes the introduction of a single-entry point for all notifications. However, would prefer a European single entry point rather than 27 different ones.

28


ITRE-Amendments to NIS 2-Directive

Amendment 465 – paragraph 5 b (new) Summary of Amendment

Evaluation

▪

▪

ENISA, in cooperation with the Cooperation Group, shall develop common notification templates by means of guidelines that simplify and streamline the reporting information requested by Union law.

BDI welcomes the development of notification templates by ENISA, this will especially help MNEs which, in case of an incident, have to report incidents in various Member States.

Article 21 – Use of European cybersecurity certification schemes Amendment 489 – paragraph 1 Summary of Amendment

Evaluation

▪

▪

German industry welcomes that the Renew group recognises the fact that it is not essential or important entities that have to certify products but rather the producer of ICT products, services and processes. At the same time, however, international certification schemes should not only be an acceptable solution in the absence of a European certification scheme but should also be allowed as a basis for certification when a European certification scheme exists. Europe should strive for a high degree of international harmonisation in terms of ICT regulation and standardisation.

▪

In addition to allowing certification based on international standards, we urge the Commission to introduce horizontal NLF-based cybersecurity requirements. German industry expressly supports the European Commission's current considerations, supported by the European Council, to introduce mandatory, horizontal cybersecurity requirements based on the principles of the New Legislative Framework (NLF).

In order to demonstrate compliance with certain requirements of Article 18, Member States may require essential and important entities to use certain certified ICT products, ICT services and ICT processes, whether procured from third parties or developed by the essential or important entity, certified under specific European cybersecurity certification schemes adopted pursuant to Article 49 of Regulation (EU) 2019/881, or, in the absence of such a scheme, under equivalent internationally recognised certification schemes.

Details on BDI’s proposal for introducing horizontal, mandatory cybersecurity requirements based on the NLF can be found here: https://english.bdi.eu/publication/news/euwide-cybersecurity-requirements/

29


ITRE-Amendments to NIS 2-Directive

Amendment 497 – paragraph 2a (new) Summary of Amendment

Evaluation

▪

▪

The Renew Group proposes the following amendment:

In order to demonstrate compliance with certain requirements of Article 18 of this Directive, Member States may require essential and important entities to use qualified trust services pursuant to Regulation (EU) No 910/2014.

The NIS 2 Directive should follow a technology-neutral approach. Henceforth, the directive should not entail language on how entities demonstrate compliance with the requirements pursuant to Article 18.

30


ITRE-Amendments to NIS 2-Directive

Discussion of selected Amendments proposed by members of the Group of the Greens/European Free Alliance Article 5 – National cybersecurity strategy Amendment 280 –paragraph 1 – point d a (new) Summary of Amendment

Evaluation

▪

▪

The amendment proposes the inclusion of cybersecurity awareness amongst citizens in national cybersecurity strategy.

Ensuring a high degree of cyber resilience is only possible, if all actors contribute their part. Therefore, we welcome the proposal to include cybersecurity awareness measures in each Member States’ national cybersecurity strategy.

Article 6 – Coordinated vulnerability disclosure and a European vulnerability registry Amendment 309 – paragraph 2 Summary of Amendment

Evaluation

▪

▪

For ensuring security and accessibility of information, state of the art cybersecurity measures shall be accompanied by machine-readable datasets and corresponding interfaces (APIs).

German industry appreciates the idea of a high degree of automation when it comes to the set-up of the European vulnerability registry.

Article 15 – Report on the state of cybersecurity in the Union Amendment 367 – paragraph 1 – point c Summary of Amendment

Evaluation

▪

▪

The report on the state of cybersecurity in the Union shall also include information on citizens’ cybersecurity awareness and the general level of security of consumer-oriented connected devices.

While a holistic approach to cybersecurity is essential to achieve a high degree of cyber-resilience, it has to be questioned whether ENISA has the necessary resources to deliver such a farreaching report. If ENISA shall publish such a far-reaching report every two years, we call on the co-legislators to significantly increase the number of personal employed by ENISA.

Article 20 – Reporting obligations Amendment 425 – paragraph 1 Summary of Amendment

Evaluation

▪

▪

In addition to the requirement to inform the recipients of one’s service, entities shall provide information that enables the recipients to mitigate the adverse effects of cyberattacks. By exception,

The information that entities shall be required to provide recipients of their services should always be proportionate.

31


ITRE-Amendments to NIS 2-Directive

where public disclosure could trigger further cyberattacks, essential and important entities could delay the notification. Amendment 432 – paragraph 2 – subparagraph 1 Summary of Amendment

Evaluation

▪

▪

The wording of the subparagraph has been changed as follows:

Member States shall ensure that essential and important entities notify, without undue delay, the competent authorities or the CSIRT of any significant cyber threat that those entities identify that could have potentially, if steps to mitigate the risk had not been taken or are not taken in the future, would have resulted or are likely in the future to result in a significant incident.

Entities should only be required to notify competent authorities or the CSIRT about cyber-attacks that have resulted in incidents.

Amendment 445 – paragraph 2 – subparagraph 2 Summary of Amendment

Evaluation

▪

▪

Only if public disclosure could trigger further attacks, important entities shall be allowed to delay the notification.

The benefits of public disclosure of an incident should always be carefully weight against potential negative implications.

Article 25 – Registry for essential and important entities Amendment 25 – paragraph 1 – introductory part Summary of Amendment ▪

Addition of the term “secure” as a characteristic of the registry.

Evaluation ▪

BDI welcomes the addition of security as one of the characteristics of ENISAs registry.

Amendment 584 – Article 34a – Right to an effective judicial remedy Summary of Amendment

Evaluation

▪

▪

The following additional Article is proposed:

Article 34a - Right to an effective judicial remedy

German industry does not see the legal necessity for this addition. To our understanding, recipients of services would have such a possibility anyhow.

Without prejudice to any available administrative or non-judicial remedy, the recipients of services provided by essential and important entities, having incurred damages as a result of the providers' non-compliance with this Directive, shall have the right to an effective judicial remedy.

32


ITRE-Amendments to NIS 2-Directive

German industry’s proposals for amendments Ensuring a high degree of cyber-resilience across the European Union is of outstanding importance in light of the increasing interlinkages between sectors and actors, and along supply-chains. Therefore, German industry regards the EU Commission’s proposal for repealing Directive (EU) 2016/1148 and proposing a Directive on measures for a high common level of cybersecurity across the Union (NIS 2Directive) as an important step. However, the European legislator has to strike the right balance between a high degree of cyber-resilience and companies’ abilities to fulfil the cybersecurity risk mitigating measures proposed in the draft NIS 2-Directive. In addition to the amendments proposed by the ITRE committee, Germany industry urges the colegislators to make the following amendments to the proposal for a NIS 2 Directive:

Recital 54 – Encryption Text proposed by the Commission

Proposed Amendment

In order to safeguard the security of electronic communications networks and services, the use of encryption, and in particular end-to-end encryption, should be promoted and, where necessary, should be mandatory for providers of such services and networks in accordance with the principles of security and privacy by default and by design for the purposes of Article 18. The use of end-to-end encryption should be reconciled with the Member State’ powers to ensure the protection of their essential security interests and public security, and to permit the investigation, detection and prosecution of criminal offences in compliance with Union law. Solutions for lawful access to information in end-to-end encrypted communications should maintain the effectiveness of encryption in protecting privacy and security of communications, while providing an effective response to crime.

In order to safeguard the security of electronic communications networks and services, the use of encryption, and in particular end-to-end encryption, should be promoted and, where necessary, should be mandatory for providers of such services and networks in accordance with the principles of security and privacy by default and by design for the purposes of Article 18. Authorities across all Member States should promote the utilisation of cryptographic processes in order to ensure Europe’s digital sovereignty and digital transformation. By promoting encryption, the EU will set a positive role-model for other parts of the world.

Explanation Cryptographic methods (e.g. end-to-end cryptography) strengthen trust in digital communication tools such as e-mails and messenger services. To protect companies from industrial espionage by third countries and citizens from cybercriminals, the EU should support the advancement and utilisation of cryptographic methods. German industry calls on the European Commission, the European Parliament and the EU Member States to promote encryption without demanding any measures that could weaken cryptographic procedures. While German industry recognises the importance to gain access to electronic evidence for competent authorities, in order to conduct successful investigations and thereby bring criminals to justice, but also to protect victims and help ensure security, national authorities must also see the potential downsides a weakening of encryption can have for Europe’s digital sovereignty. Moreover, weakening encryption in Europe could set a precedence for authoritarian regimes. Therefore, German industry urges policy makers to refrain from any measure that could weaken encryption. We strictly oppose any technical solutions, such as backdoors or master key, as their pure existence would weaken encryption in the EU.

33


ITRE-Amendments to NIS 2-Directive

Europe needs not fewer, but more trustworthy IT solutions to reap the benefits of the digital transformation in administration, industry and society. To this end, European legislators should be proponents of strong encryption and should increasingly promote the development of post-quantum cryptography procedures to accommodate future requirements for secure communication.

Article 2 in conjunction with Annex I and II – Scope Text proposed by the Commission

Proposed Amendment

(1) This Directive applies to public and private entities of a type referred to as essential entities in Annex I and as important entities in Annex II. This Directive does not apply to entities that qualify as micro and small enterprises within the meaning of Commission Recommendation 2003/361/EC.

(1) This Directive applies to public and private entities of a type referred to as essential entities in Annex I and as important entities in Annex II. This Directive does not apply to entities that qualify as micro, small and medium enterprises within the meaning of Commission Recommendation 2003/361/EC except for those SMEs that are suppliers of critical hardware and software to essential entities or that can be defined as critical in any other way.

Explanation We welcome the exemptions for micro and small enterprises as these often do not have the necessary financial means and capacities to fulfil the far-reaching obligations stipulated in the NIS 2-Directive. However, we expect that especially smaller SMEs (50 – 100 employees), which do not fall under the “size cap”, as they have ≥50 employees or an annual turnover of more than 10 Mio. Euro, will face considerable challenges in meeting the far-reaching risk management measures and reporting obligations. Therefore, we call on the co-legislators to exempt all SMEs according to Commission Recommendation 2003/361/EC from the scope of the Directive, i.e. that all companies – at least those operational in sectors classified as “important” – with ≤ 250 employees or an annual turnover of less than 50 Mio. Euro. An exemption to this exclusion shall apply for SME that supply critical hardware and software solutions to essential entities or that can be defined as “critical” in supply chains any other regards. This adaptation would ensure that the NIS 2-Directive follows a functional risk-based approach, strengthens the EU’s cyber-resilience without putting unacceptably high burdens on smaller entities. By following a company rather than a plant-focus, the EU Commission seems to aspire to protect operational continuity of factories, operational continuity of administrative and sales processes, knowhow and trade secrets, as well as the reliability/quality of products. In their joined letter, the heads of state of Denmark, Estonia Finland and Germany urge the European Commission to “identify systems of critical technologies and strategic sectors” 1. German industry supports this approach. Companies should not be included into the Directive’s scope solely based on NACE sectors or their size, but rather according to a product’s or service’s importance for the supply chain and an enterprise’s criticality for society. Otherwise, a huge amount of companies will compete for the very few IT security specialists available on the market. This would result in exorbitant costs for basic cybersecurity measures. Hence, especially smaller entities would have difficulties paying for IT security expertise. This, however, has the potential to weaken rather than strengthen Europe’s cyber-resilience.

1

Cf. Prime Minister’s Office. 2021. Finland, Germany, Denmark and Estonia call on EU to accelerate digital transformation. URL: https://vnk.fi/en/-/finland-germany-denmark-and-estonia-call-on-eu-to-accelerate-digital-transformation 34


ITRE-Amendments to NIS 2-Directive

Text proposed by the Commission

Proposed Amendment (7) Where an operator of essential services relies on a third-party digital service provider for the provision of a service which is essential for the maintenance of critical societal and economic activities, any significant impact on the continuity of the essential services due to an incident affecting the digital service provider shall be notified by that operator.

Explanation The current proposal does not sufficiently address the reality of B2B interactions, in which one essential service provider might be the client of another essential service provider. This could lead to legal ambiguity and overlap in reporting obligations. From our point of view, a business client acting as an essential entity, and that uses third-party digital servicers or digital infrastructure to serve multiple end users, would be better positioned to assess the impact and gravity of an incident than the essential entity providing the digital service or infrastructure. Under the current proposal, a cloud provider or any other digital infrastructure provider deemed as essential, would have to report to the regulator without having the necessary information or overview of end users affected.

Text proposed by the Commission

Proposed Amendment

Annex II:

Annex II:

Waste management: Undertakings carrying out waste management referred to in points (9) of Article 3 of Directive 2008/98/EC (29) but excluding undertakings for whom waste management is not their principal economic activity

Municipal waste management: Undertakings carrying out waste management referred to in points (9) of Article 3 of Directive 2008/98/EC (29) of municipal waste but excluding undertakings for whom waste management is not their principal economic activity

Explanation German industry recognises the importance of the waste management sector. However, we advocate to narrow the scope to municipal waste management, since the management of municipal waste is of paramount importance to maintain public health and safety.

Article 4 – Definitions Text proposed by the Commission

Proposed Amendment

(1) ‘network and information system’ means:

(1) ‘network and information system’ means:

(a) an electronic communications network within the meaning of Article 2(1) of Directive (EU) 2018/1972;

(a) an electronic communications network within the meaning of Article 2(1) of Directive (EU) 2018/1972;

(b) any device or group of inter–connected or related devices, one or more of which, pursuant to

(b) any device or group of inter-connected or related devices, one or more of which, pursuant to a program, perform automatic processing of digital data, which are integrated into the IT- and/or 35


ITRE-Amendments to NIS 2-Directive

a program, perform automatic processing of digital data; (c) digital data stored, processed, retrieved or transmitted by elements covered under points (a) and (b) for the purposes of their operation, use, protection and maintenance;

OT-system of an essential or important entity pursuant to Article 2 of this directive and there fulfil functionalities that are of importance for the proper operational capacity, integrity and/or availability of the entity; (c) digital data stored, processed, retrieved or transmitted by elements covered under points (a) and (b) for the purposes of their operation, use, protection and maintenance;

Explanation Clear and unambiguous definitions are of utmost importance in order to ensure legal certainty. To this end, German industry urges the European Commission, the European Parliament and the European Council to revise the proposed definition of “network and information systems”. The current definition does not specify that the “device or group of inter-connected or related devices” described in letter 1 b are only those devices that are integrated into the IT or OT system of an essential or important entity. Since the aim of the NIS 2-Directive is to ensure the integrity, availability and operational capacity of essential and important entities, the respective definition of “network and information systems” should be limited to those devices that are of paramount importance for guaranteeing these goals.

Text proposed by the Commission

Proposed Amendment

(5) ‘incident’ means any event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the related services offered by, or accessible via, network and information systems;

(5) ‘incident’ means any unwanted or unexpected event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the related services offered by, or accessible via, network and information systems;

Explanation A company’s internal cybersecurity measures, such as internal security and penetration tests or scans, could lead to an “incident”. Therefore, the definition of “incident” should be narrowed in such a way that these internally triggered incidents are falling outside the scope of the Directive. Therefore, we propose the integration of “unwanted or unexpected” into the definition. Hence, BDI appreciates amendment 244.

Text proposed by the Commission

Proposed Amendment

(17) ‘online marketplace’ means a digital service within the meaning of Article 2 point (n) of Directive 2005/29/EC of the European Parliament and of the Council

(17) ‘online marketplace’ means a digital service within the meaning of (insert correct reference, the current one seems to be incorrect). Excluded from this definition are services that only enable online contracting on a website as a minor service subordinated to the main service with a different focus.

36


ITRE-Amendments to NIS 2-Directive

Explanation Providers of online marketplaces (Annex II No. 6) are classified as “important entities”. Again, the EU Commission does not explicitly distinguish between entities, whose service is primarily based on an online marketplace, and those entities, who merely “offer” an online marketplace as a subordinate service to another business activity. Such “second order” online marketplaces should be excluded from the Directive’s scope.

Text proposed by the Commission

Proposed Amendment

(19) ‘cloud computing service’ means a digital service that enables on-demand administration and broad remote access to a scalable and elastic pool of shareable and distributed computing resources;

(19) ‘cloud computing service’ means a digital service that in its core function enables on-demand administration and broad remote access to a scalable and elastic pool of shareable and distributed computing resources. Excluded from this definition are services that only use cloud computing services of a third party as a partial performance to be able to provide their own service with a different focus.

Explanation The term “cloud computing service providers” (Annex I No.8) is too wide and imprecise. The current wording includes not only the providers of mere distributed storage and computing capacities, but also software providers who offer storage in a cloud in connection with their virtually usable software products. Due to a further virtualisation of information technology, the very broad definition could lead to an increasing number of services falling into this category. Hence, the NIS 2-Directive should distinguish between “digital service providers” on the one hand, and users, such as “enterprises” or “operators of essential services”, on the other hand, who in turn require “digital services” as a basis for providing their services. Only providers of cloud-based software products whose services enable essential utility services should fall under the Directive’s scope. In contrast, Companies which use a “digital service” to provide their SaaS without the focus of their own SaaS being on the provision of cloud capacity to users should be explicitly excluded from the Directive’s scope.

Text proposed by the Commission

Proposed Amendment (27) ‘management body’ means an institution's body or bodies, which are appointed in accordance with national law, which are empowered to set the institution's strategy, objectives and overall direction, and which oversee and monitor management decision-making, and include the persons who effectively direct the business of the institution

Explanation The European Commission must introduce a definition of management bodies that outlines who is the addressee of the requirements pursuant to Article 17. We propose a definition similar to the one introduced by Directive 2013/36/EU (CRD).

37


ITRE-Amendments to NIS 2-Directive

Article 6 – Coordinated vulnerability disclosure and a European vulnerability registry Text proposed by the Commission

Proposed Amendment

2. ENISA shall develop and maintain a European vulnerability registry. To that end, ENISA shall establish and maintain the appropriate information systems, policies and procedures with a view in particular to enabling important and essential entities and their suppliers of network and information systems to disclose and register vulnerabilities present in ICT products or ICT services, as well as to provide access to the information on vulnerabilities contained in the registry to all interested parties. The registry shall, in particular, include information describing the vulnerability, the affected ICT product or ICT services and the severity of the vulnerability in terms of the circumstances under which it may be exploited, the availability of related patches and, in the absence of available patches, guidance addressed to users of vulnerable products and services as to how the risks resulting from disclosed vulnerabilities may be mitigated.

2. ENISA shall swiftly develop and maintain a European, yet internationally compatible, vulnerability registry. To that end, ENISA shall establish and maintain the appropriate information systems, policies and procedures with a view in particular to enabling important and essential entities and their suppliers of network and information systems to disclose and register vulnerabilities present in ICT products or ICT services, as well as to provide access to the information on vulnerabilities contained in the registry to all interested parties after the producer of an ICT product or the provider of an ICT service had sufficient time to provide customers with an update or a patch. The registry shall, in particular, include information describing the vulnerability, the affected ICT product or ICT services and the severity of the vulnerability in terms of the circumstances under which it may be exploited, the availability of related patches and, in the absence of available patches, guidance addressed to users of vulnerable products and services as to how the risks resulting from disclosed vulnerabilities may be mitigated. 3. CSIRTs, competent authorities pursuant to Article 8 of this Directive, and all other authorities of the EU and its Member States have to immediately inform by applying coordinated vulnerability disclosure principles the producer of an ICT product or the provider of an ICT service respectively of any vulnerability in such products or services they become aware of. No public authority in the Union shall hold back this information.

Explanation German industry appreciates the European Commission’s approach to holistically address cyber-resilience and thereby, also to pay closer attention to the cyber-resilience of products and services. Any security vulnerability, regardless of whether it is an unintentional bug in the product or an intentional backdoor, should be included in the registry. Manufacturers of such products should not only be obliged to report security gaps, but also to swiftly close such security gaps. In order to keep the effort for everyone involved as low as possible, the European Commission needs to implement a lean and efficient reporting process. The European Union should institutionalise coordinated vulnerability disclosure based on international standards, such as ISO/IEC 29147: 2018 Information technology – Security techniques – Vulnerability disclosure, and CVE. Within CVE trustworthy organisations nowadays act as CVE Numbering Authorities around the world in a voluntary program, so that cybersecurity experts can more easily prioritise and address vulnerabilities. 38


ITRE-Amendments to NIS 2-Directive

When disclosing vulnerabilities, ENISA must cooperate with the respective manufacturer of a product or the provider of a service and inform them prior to any public disclosure. Manufacturers of ICT products and providers of ICT services must have the chance to provide their customers with updates or patches to mitigate the risks of the respective vulnerability before a vulnerability is publicly disclosed by a third party. Otherwise, hackers could exploit the disclosed information which would have serious repercussions for Europe’s cyber-resilience. Therefore, a timeframe should be established for how quickly ENISA must notify the manufacturer and how long the manufacturer has to review the requests, respond to them, and roll out a bug fix if necessary. Reporting vulnerabilities should not be a one-way road. Rather, public entities, including secret services, must be obliged to report their knowledge on vulnerabilities as well. German industry calls onto the European Commission to integrate into Article 6 a requirement that obliges government agencies from EU Members States to immediately report any information on vulnerabilities or backdoors in IT products to the respective manufacturers and/or ENISA. Currently it is the case that government agencies frequently hold back such knowledge which represents a significant threat to Europe’s cyberresilience. This is especially the case when serious vulnerabilities in ICT products or services utilised in critical entities are concerned. Moreover, CSIRTs must never have the power to suppress or delay the disclosure of a detected vulnerability.

Article 7 – National cybersecurity crisis management frameworks Text proposed by the Commission

Proposed Amendment 5. Member States shall consult in a structured manner essential and important entities when developing the plans according to paragraph 2, in order to ensure the provision of the services provided by essential entities during large-scale incidents and crises.

Explanation As the SolarWinds case as well as the attack on the Ukrainian power grid in December 2015 demonstrated, cyber incidents can have far-reaching repercussions. Therefore, German industry welcomes the EU Commission’s proposal that every Member State has to adopt a national cybersecurity incident and crisis response plan. When developing and drafting such plans, Member States should be required to consult essential and important entities, as these companies provide vital services for society.

Article 15 – Report on the state of cybersecurity in the Union Text proposed by the Commission

Proposed Amendment

Report on the state of cybersecurity in the Union

Daily updated management report on cybersecurity in the Union

1. ENISA shall issue, in cooperation with the Commission, a biennial report on the state of cybersecurity in the Union. The report shall in particular include an assessment of the following:

1. ENISA shall issue, in cooperation with the national competent authorities, a daily updated management report. The daily updated management report shall in particular include:

(a) the development of cybersecurity capabilities across the Union;

(a) an overview of new threat vectors, that have been reported by entities according to Article 2

39


ITRE-Amendments to NIS 2-Directive

(b) the technical, financial and human resources available to competent authorities and cybersecurity policies, and the implementation of supervisory measures and enforcement actions in light of the outcomes of peer reviews referred to in Article 16;

(b) an analysis of new attack vectors (c) an overview of vulnerabilities that have been published in the register according to Article 6

(c) a cybersecurity index providing for an aggregated assessment of the maturity level of cybersecurity capabilities. Explanation ENISA publishing a biennial report that includes mainly general information will not augment the EU’s cyber-resilience. Rather, ENISA should publish online up-to-date information on cybersecurity incidents. An improved daily updated, holistic situation picture as well as daily updated, sector-specific warnings would significantly help essential and important entities to benefit from the data aggregated at national competent authorities, and thereby, to better protect their business processes. Such information would help essential and information entities to support their cybersecurity risk mitigating measures.

Article 17 – Governance Text proposed by the Commission

Proposed Amendment

(1) Member States shall ensure that the management bodies of essential and important entities approve the cybersecurity risk management measures taken by those entities in order to comply with Article 18, supervise its implementation and be accountable for the non-compliance by the entities with the obligations under this Article.

(1) Member States shall ensure that the management bodies of essential and important entities approve the cybersecurity risk management measures taken by those entities in order to comply with Article 18 and supervise its implementation.

Explanation BDI recognises that management bodies are responsible for the cybersecurity strategy of an essential or important entity. This step will help to significantly increase the awareness for cybersecurity issues among top-level management. However, we regard it as important that the European Commission recognises that members of management bodies of essential entities and important entities have IT security personnel that possesses the necessary qualifications to develop and implement an entity’s cybersecurity strategy. Consequently, it has to be questioned whether members of management bodies have to pass a respective training or whether reports by CISOs or IT security personnel are equally sufficient to provide members of management bodies with in-depth information. Moreover, personal accountability for non-compliance is a step too far, especially if the goal is to ensure appropriate cybersecurity awareness in companies across sectors.

Text proposed by the Commission

Proposed Amendment

(2) Member States shall ensure that members of the management body follow specific trainings, on a regular basis, to gain sufficient knowledge

(2) Member States shall ensure that members of the management body follow specific trainings, on a regular basis, to gain sufficient knowledge 40


ITRE-Amendments to NIS 2-Directive

and skills in order to apprehend and assess cybersecurity risks and management practices and their impact on the operations of the entity.

and skills in order to apprehend and assess cybersecurity risks and management practices and their impact on the operations of the entity. (3) The European Commission will publish, by no later than six months after the ratification of this directive and after consulting business associations, binding recommendations on what constitutes sufficient knowledge and skills according to number two of this Article.

Explanation However, if the European Commission regards a mandatory IT security training necessary for members of management bodies, it should swiftly define what constitutes “sufficient knowledge and skills”, in order to provide guidance on which skills are considered adequate to implement the Commission’s requirements. Moreover, such recommendations must be the same across the EU to ensure that members of management bodies are not confronted with diverging requirements across the Single Market, and – in a worst-case scenario – have to undergo different trainings per country.

Article 19 – EU coordinated risk assessments of critical supply chains Based on the experience of the EU’s coordinated risk assessment on 5G, German industry welcomes the proposal to conduct such risk assessments of critical supply chains. However, the measures proposed after having conducted such an analysis must be proportionate and always foresee a sufficient implementation period.

Article 20 – Reporting obligations Text proposed by the Commission

Proposed Amendment

5. Member States shall ensure that, for the purpose of the notification under paragraph 1, the entities concerned shall submit to the competent authorities or the CSIRT:

5. Member States shall ensure that, for the purpose of the notification under paragraph 1, the entities concerned shall submit to the competent authorities or the CSIRT:

a. without undue delay and in any event within 24 hours after having become aware of the incident, an initial notification, which, where applicable, shall indicate whether the incident is presumably caused by unlawful or malicious action;

a. without undue delay and in any event within 72 hours after having become aware of the incident, an initial notification, which, where applicable, shall indicate whether the incident is presumably caused by unlawful or malicious action;

b. upon the request of a competent authority or a CSIRT, an intermediate report on relevant status updates;

b. upon the request of a competent authority or a CSIRT, a maximum of one intermediate report on relevant status updates;

c.

a final report not later than one month after the submission of the report under point (a), including at least the following: i.

a detailed description of the incident, its severity and impact;

c. a final report not later than one month after the entity has finished its forensic analysis as well as other measures to handle the incidents and its potential business implications, including at least the following:

41


ITRE-Amendments to NIS 2-Directive

ii.

the type of threat or root cause that likely triggered the incident;

i.

a detailed description of the incident, its severity and impact;

iii.

applied and ongoing mitigation measures.

ii.

the type of threat or root cause that likely triggered the incident;

Member States shall provide that in duly justified cases and in agreement with the competent authorities or the CSIRT, the entity concerned can deviate from the deadlines laid down in points (a) and (c).

iii.

applied and ongoing mitigation measures.

Member States shall provide that in duly justified cases and in agreement with the competent authorities or the CSIRT, the entity concerned can deviate from the deadlines laid down in points (a) and (c). Member States shall ensure that any reporting obligation is in full compliance with the Union’s data protection rules or respective international, legal obligations.

Explanation When being confronted with a cyber-incident, essential and important entities must first focus on all necessary measures to minimise the implications of the cyber-incident, rather than having to fulfil reporting obligations. Business continuity, saving workplaces and thereby supporting social cohesion in a region have to be the first priority. Reporting can only come second. Therefore, companies should be required to only notify competent authorities within 72 hours after identifying a successful attack. Furthermore, CSIRTs should be allowed to ask for a maximum of one interim report. Moreover, since the investigation time for a complex cybersecurity incident often amount to half a year, handing in a final report after one months is not possible. Therefore, the final report should be handed in to the competent national authorities no later than one month after the entity has finished its forensic analysis and has conducted all other measures necessary to ensure business continuity and handling the notified cybersecurity incident. Such longer deadlines for handing in a final report are pertinent to ensure that companies can focus on mitigating the cybersecurity incident in the first place and ensure the full operational capacity of a company is swiftly regained. This is in the interest of both shareholders and stakeholders, employees and employers, as well as the wider community. Text proposed by the Commission

Proposed Amendment (12) Member States shall, establish within 12 months after transferring this Directive into national law, a one-stop-shop solution through which entities pursuant to Article 2 and Annex I and II of this Directive can report incidents according to this Article and the respective requirements pursuant to Regulation (EU) 2016/679.

Explanation If the European Commission seeks to introduce far-reaching reporting obligations, an efficient reporting process has to be established across all EU Member States. The creation of an efficient, harmonised reporting channel to one competent authority (one-stop-shop principle), instead of reporting obligations to various national and/or European authorities, such as competent authorities for cybersecurity and data protection officers is paramount. Otherwise, especially smaller companies will be overburdened by reporting obligations and cannot sufficiently address the actual cyber incident. 42


ITRE-Amendments to NIS 2-Directive

Article 22 – Standardisation Text proposed by the Commission

Proposed Amendment

In order to promote the convergent implementation of Article 18(1) and (2), Member States shall, without imposing or discriminating in favour of the use of a particular type of technology, encourage the use of European or internationally accepted standards and specifications relevant to the security of network and information systems.

1. In order to promote the convergent implementation of Article 18(1) and (2), ENISA shall, without imposing or discriminating in favour of the use of a particular type of technology, encourage the use of European or internationally accepted standards and specifications relevant to the security of network and information systems.

Explanation German industry welcomes the technology-neutral approach adopted by the European Commission regarding recommendations for the implementation of cybersecurity risk mitigating measures. Furthermore, we welcome that – in contrast to Germany’s new IT Security Law 2.0 – the European Commission focuses on the adoption of European and international standards. This will facilitate the spread of such universal standards. However, to ensure that entities operating in more than one country do not have to fulfil diverging requirements, German industry would welcome if ENISA was to recommend basic guidelines for such measures for the entire EU.

Article 24 – Jurisdiction and territoriality Text proposed by the Commission

Proposed Amendment

1. DNS service providers, TLD name registries, cloud computing service providers, data centre service providers and content delivery network providers referred to in point 8 of Annex I, as well as digital providers referred to in point 6 of Annex II shall be deemed to be under the jurisdiction of the Member State in which they have their main establishment in the Union.

1. DNS service providers, TLD name registries, cloud computing service providers, data centre service providers and content delivery network providers referred to in point 8 of Annex I, as well as digital providers referred to in point 6 of Annex II shall be deemed to be under the jurisdiction of the Member State in which they have their group’s main establishment in the Union.

2. For the purposes of this Directive, entities referred to in paragraph 1 shall be deemed to have their main establishment in the Union in the Member State where the decisions related to the cybersecurity risk management measures are taken. If such decisions are not taken in any establishment in the Union, the main establishment shall be deemed to be in the Member State where the entities have the establishment with the highest number of employees in the Union.

2. For the purposes of this Directive, entities referred to in paragraph 1 shall be deemed to have their group’s main establishment in the Union in the Member State where the decisions related to the cybersecurity risk management measures are taken. If such decisions are not taken in any establishment in the Union, the main establishment shall be deemed to be in the Member State where the entities have the establishment with the highest number of employees in the Union.

Explanation German industry welcomes that DNS service providers, TLD name registries, cloud computing service providers, data centre service providers and content delivery network providers referred to in point 8 of Annex I of the NIS 2-Directive fall under the jurisdiction of the Member State in which they have their 43


ITRE-Amendments to NIS 2-Directive

main establishment in the Union. For companies in the ICT sector it is important to fall under the jurisdiction of just one Member State as it significantly reduces the reporting obligations. Therefore, it needs to be clarified that an entity’s main establishment equates to the group’s headquarter in the Union and not only to the national entity’s headquarter in a Member State.

Article 25 – Registry for essential and important entities Text proposed by the Commission

Proposed Amendment

3. Upon receipt of the information under paragraph 1, ENISA shall forward it to the single points of contact depending on the indicated location of each entity’s main establishment or, if it is not established in the Union, of its designated representative. Where an entity referred to in paragraph 1 has besides its main establishment in the Union further establishments in other Member States, ENISA shall also inform the single points of contact of those Member States.

3. Upon receipt of the information under paragraph 1, ENISA shall forward it to the single points of contact depending on the indicated location of each entity’s main establishment or, if it is not established in the Union, of its designated representative. Where an entity referred to in paragraph 1 has besides its main establishment in the Union further establishments in other Member States, ENISA shall also inform the single points of contact of those Member States. Entities shall only be obliged to report the information under paragraph 1 to ENISA and not in addition to the single points of contact in the Member States. ENISA shall ensure the exchange of these information with national competent authorities.

Explanation The Federation of German Industry welcomes the idea of an EU-wide registry for DNS service providers, TLD name registries, cloud computing service providers, data centre service providers and content delivery network providers. However, the EU’s proposal will increase the administrative burden for the respective companies. Therefore, it should be made clear that a registration only has to be conducted once at ENISA and that ENISA will provide national competent authorities with all necessary information. In addition, the mere existence of a registry with information about all cyber establishments in the Union, can in itself represent a cybersecurity risk. If the registry is to be created, all information shared with ENISA needs to be treated with the highest degree of confidentiality. Moreover, effective cybersecurity measures, including encryption, would need to be in place to protect the information in such a registry.

Article 26 – Cybersecurity information-sharing arrangements German industry appreciates this proposal since experience from the UP KRITIS, the German public private partnership bringing together experts from operators of critical entities and representatives of government agencies, showcases the benefits of a regular exchange on cybersecurity topics between such companies and respective public authorities. In order to ensure the protection of intellectual property and business know-how, the extent and scope of this exchange need to be clearly defined. Moreover, it has to be ensured that all essential and important entities can join such cybersecurity information sharing arrangements. Experiences with non-profit platforms such as the German CERT Association (“Deutscher CERT Verbund”) and the CERT@VDE have also proven for years that trustful cooperation based on a voluntary commitment by companies works well.

44


ITRE-Amendments to NIS 2-Directive

Article 27 – Voluntary notification of relevant information German industry appreciates that voluntary reporting shall not result in the imposition of any additional obligations upon the reporting entity to which it would not have been subject had it not submitted the notification. At the same time, however, national competent authorities should be obliged to respond to such notifications within two days. If companies are provided with benefits when reporting cybersecurity incidents, the amount of notifications is likely to rise. Thereby, the national competent authorities will gain a more holistic picture of the current cyberthreat landscape.

Article 29 – Supervision and enforcement for essential entities Text proposed by the Commission

Proposed Amendment

Paragraph six

deleted

Member States shall ensure that any natural person responsible for or acting as a representative of an essential entity on the basis of the power to represent it, the authority to take decisions on its behalf or the authority to exercise control of it has the powers to ensure its compliance with the obligations laid down in this Directive. Member States shall ensure that those natural persons may be held liable for breach of their duties to ensure compliance with the obligations laid down in this Directive. Explanation As the NIS 2-Directive already includes very far-reaching supervision and enforcement powers – including fines – it should be the responsibility of the respective entity to take any necessary employeerelated measures. The competent authority shall not have the competence to oust any employee – including members of the management body. In addition to the responsibility of entities to maintain an adequate level of IT security and to avoid any violations of the duties outlined in the NIS 2-Directive, the Directive also establishes responsibilities and sanctions directed at single employees “exercising managerial functions”. Since the term “management” is too broadly used in companies across the Union German industry opposes such a farreaching personal liability of individual employees.

Article 30 – Supervision and enforcement for important entities Text proposed by the Commission

Proposed Amendment

2. (c) security scans based on objective, fair and transparent risk assessment criteria;

deleted

Explanation Furthermore, we point out that intrusive and unannounced “security scans” are problematic with regard to cyber security as, if done incorrectly, they could trigger a cyber incident of their own. Therefore, this option should be deleted.

45


ITRE-Amendments to NIS 2-Directive

Text proposed by the Commission

Proposed Amendment

4. (b) issue binding instructions or an order requiring those entities to remedy the deficiencies identified or the infringement of the obligations laid down in this Directive;

4. (b) issue an order requiring those entities to remedy the deficiencies identified or the infringement of the obligations laid down in this Directive;

Explanation It is in an important entities’ intrinsic interest to maintain a high degree of cyber-resilience. In this regard it should be noted that companies are best equipped to conduct any necessary measure to enhance their cyber-resilience. Therefore, we oppose the possibility of granting competent authorities with any possibility to “issue binding instructions”, as stipulated in Article 30 Nr. 4 point (b). If competent authorities were provided with such far-reaching competencies, the European Commission has to clarify that the competent authority will bear any cost resulting from such measures.

Article 31 – General conditions for imposing administrative fines on essential and important entities Text proposed by the Commission

Proposed Amendment

4. Member States shall ensure that infringements of the obligations laid down in Article 18 or Article 20 shall, in accordance with paragraphs 2 and 3 of this Article, be subject to administrative fines of a maximum of at least 10 000 000 EUR or up to 2% of the total worldwide annual turnover of the undertaking to which the essential or important entity belongs in the preceding financial year, whichever is higher.

4. Member States shall ensure that infringements of the obligations laid down in Article 18 or Article 20 shall, in accordance with paragraphs 2 and 3 of this Article, be subject to administrative fines of a maximum of two million EUR.

Explanation In order to ensure that all entities implement the cybersecurity risk mitigation measures laid down in Article 18 and fulfil their reporting obligations pursuant to Article 20 the introduction of administrative fines seems justified. However, a significant reduction of the maximum level of administrative fines imposed on entities seems necessary. Unlike in the case of data protection (cf. GDPR), the legal interest to be protected here is not a fundamental right (GDPR = right to informational self-determination; vs NIS 2 = cybersecurity of essential and important entities). Nor do the considerations regarding data protection law – that have led to fines being calculated based on group sales – fit with regard to the NIS 2 Directive. Therefore, the maximum level of administrative fines should be no higher than two million Euros without any reference to annual turnover. Such a level would strike an acceptable balance between the intent to punish companies violating the requirements stipulated in Articles 18 and 20, and German industry’s requirements for administrative fines that are not excessive. This is particularly important since, according to a Bitkom study from 2019, the consequences of successful cyberattacks already amount to costs of more than 100 billion euros per year for the German economy. 2

2

Bitkom. 2019. Wirtschaftsschutz in der digitalen Welt. URL: 11/bitkom_wirtschaftsschutz_2019_0.pdf (Accessed on 14th January 2021).

https://www.bitkom.org/sites/default/files/2019-

46


ITRE-Amendments to NIS 2-Directive

Article 35 – Review German industry strongly appreciates the EU Commission’s clear statement of a regular review of the functioning of the Directive. This is of utmost importance to ensure that the regulatory framework concerning the cybersecurity requirements imposed on essential and important entities are adequate in light of the existing cyberthreat landscape.

47


ITRE-Amendments to NIS 2-Directive

Imprint Bundesverband der Deutschen Industrie e.V. (BDI) Breite Straße 29, 10178 Berlin www.bdi.eu T: +49 30 2028-0 EU Transparency Register: 1771817758-48 Editors Steven Heckler Deputy Head of Department Digitalisation and Innovation T: +49 30 2028-1523 s.heckler@bdi.eu

Lars Jüngling-Dahlhoff Intern l.juengling-dahlhoff@bdi.eu

BDI document number: D 1412

48


Turn static files into dynamic content formats.

Create a flipbook
ITRE-Amendments to NIS 2-Directive by Bundesverband der Deutschen Industrie e.V. - Issuu