NIS 2 Directive — Mapping

Map each criterion to its control text.

Cancel
ID Original criterion text Mapped control text
C1
Article 2 - Scope
Criterion C1. The Entity shall disclose whether it is a public or private entity of a type referred to in Annex I or Annex II to Directive (EU) 2022/2555, together with the sector and subsector concerned, and shall disclose the ground or grounds on which it falls within the scope of that Directive. Where the Entity falls within scope on the basis of its size, the disclosure shall state the size category of the Entity determined in accordance with Article 2 of the Annex to Recommendation 2003/361/EC, indicating whether the Entity qualifies as a medium-sized enterprise or exceeds the ceilings for medium-sized enterprises provided for in paragraph 1 of that Article, it being understood that Article 3(4) of the Annex to that Recommendation does not apply for that determination. Where the Entity falls within scope regardless of its size, the disclosure shall state the applicable ground under Article 2(2), (3), (4) or (5). The Entity shall further disclose the Member States in which it provides its services or carries out its activities, and shall keep the disclosure current. The disclosure shall include at least the elements set out in the listed evidence below. Proof of compliance: Declaration Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidence about the provisions covering the criterion by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail: (a) the type of entity as referred to in Annex I or Annex II, together with the corresponding sector and subsector; (b) the legal status of the Entity as a public or private entity, and its legal identifier; (c) the size category of the Entity determined in accordance with Article 2 of the Annex to Recommendation 2003/361/EC, on the basis of headcount and annual turnover or annual balance sheet total, and excluding the application of Article 3(4) of that Annex; (d) the Member States in which the Entity provides its services or carries out its activities within the Union; (e) where applicable, the ground of applicability under Article 2(2), namely: (i) provision of public electronic communications networks or of publicly available electronic communications services; (ii) provision of trust services; (iii) operation of a top-level domain name registry or provision of domain name system services; (iv) status as the sole provider in a Member State of a service essential for the maintenance of critical societal or economic activities; (v) identification by a Member State on the ground of significant impact on public safety, public security or public health; (vi) identification by a Member State on the ground of significant systemic risk, in particular where the disruption could have a cross-border impact; (vii) identification by a Member State on the ground of specific importance at national or regional level for the particular sector or type of service or for other interdependent sectors; (viii) status as a public administration entity of central government, or at regional level following a risk-based assessment; (f) where applicable, identification of the Entity as a critical entity under Directive (EU) 2022/2557, with the reference and date of the identification decision; (g) where applicable, the provision by the Entity of domain name registration services; (h) where applicable, the inclusion of the Entity within scope by virtue of a national measure adopted under Article 2(5) covering public administration entities at local level or education institutions carrying out critical research activities, with a reference to the national transposition provision concerned; (i) the reference and date of any decision, notification or entry in a national register by which a competent authority has identified the Entity, or confirmed its identification, under any of the grounds referred to in points (e) to (h); (j) the date from which each disclosed ground of applicability applies. Permissible Standards: N/A
C2
Article 2 - Scope
Criterion C2. The Entity shall process personal data pursuant to Directive (EU) 2022/2555 only to the extent necessary for the purposes of that Directive and in accordance with Regulation (EU) 2016/679, and shall in particular identify, for each processing operation carried out pursuant to that Directive, the legal basis on which it relies under Article 6 of that Regulation. Where the Entity is a provider of public electronic communications networks or a provider of publicly available electronic communications services, it shall in addition carry out any processing of personal data pursuant to Directive (EU) 2022/2555 in accordance with Union data protection law and Union privacy law, in particular Directive 2002/58/EC and the national provisions transposing it. The Entity shall be able to demonstrate that the processing is limited to what is necessary for the purposes of the Directive and shall include at least the elements set out in the listed evidence below. Proof of compliance: Declaration Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidence about the provisions covering the criterion by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail: (a) the identification of the processing operations carried out by the Entity pursuant to Directive (EU) 2022/2555, including at least those arising from incident detection and handling, incident notification under Article 23, vulnerability handling and disclosure, supply chain security, access control and authentication, and registration and notification of changes under Article 3(4); (b) for each such processing operation, the categories of personal data and the categories of data subjects concerned; (c) for each such processing operation, the legal basis relied on under Article 6(1) of Regulation (EU) 2016/679 and, where special categories of personal data are processed, the condition relied on under Article 9(2) of that Regulation; (d) the demonstration that each such processing operation is limited to what is necessary for the purposes of Directive (EU) 2022/2555, including the data minimisation measures applied; (e) the entries in the record of processing activities maintained under Article 30 of Regulation (EU) 2016/679 that cover those processing operations; (f) the recipients of the personal data, including competent authorities, single points of contact and CSIRTs, and, where applicable, the safeguards applied to any transfer to a third country or international organisation under Chapter V of that Regulation; (g) the retention periods applied to the personal data processed pursuant to Directive (EU) 2022/2555, and the criteria used to determine them; (h) the information provided to data subjects under Articles 13 and 14 of Regulation (EU) 2016/679 in respect of those processing operations and, where any restriction is applied, the Union or Member State law on which it is based; (i) where applicable, the data protection impact assessment carried out under Article 35 of that Regulation in respect of those processing operations; (j) where the Entity is a provider of public electronic communications networks or of publicly available electronic communications services, the measures ensuring compliance of the processing with Directive 2002/58/EC, in particular Article 5 on confidentiality of communications, Article 6 on traffic data and Article 9 on location data, with reference to the national transposition provisions applicable in each Member State concerned; (k) the identity and contact details of the data protection officer or, where none is designated, of the function responsible for the processing operations concerned. Permissible Standards: N/A
C3
Article 3 - Essential And Important Entities
Criterion XX. Where the Provider qualifies as an essential entity or an important entity within the meaning of Article 3 of Directive (EU) 2022/2555, the Provider shall submit at least the following information to the competent authorities and shall notify any changes to the details submitted without delay, and, in any event, within two weeks of the date of the change. Proof of compliance: Declaration Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidences about the provisions covering the criterion by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail: (a) confirmation that the information listed in the first subparagraph of Article 3(4) has been submitted in full, identifying each competent authority and Member State to which it was submitted, the date of submission and the mechanism used, including any national mechanism established for entities to register themselves, together with any acknowledgement or registration reference issued, if any, by the competent authority; (b) the name of the entity as submitted; (c) confirmation that the address and up-to-date contact details of the entity, including email addresses, IP ranges and telephone numbers, were included in the submission; (d) where applicable, the type of entity and the relevant sector and subsector referred to in Annex I or II as submitted; (e) where applicable, the Member States where the Provider provides services falling within the scope of the Directive, as submitted; (f) the procedure by which the Provider identifies changes to the submitted details and notifies them to the competent authorities within two weeks of the date of the change, together with the date of the most recent submission, update or change notification, if any. Permissible Standards: N/A
C4
Article 20 - Governance
Criterion XX. The Entity shall ensure that its management body approves the cybersecurity risk-management measures taken by the Entity in order to comply with Article 21 of Directive (EU) 2022/2555 (NIS2) and oversees the implementation of those measures. The members of the management body of the Entity shall be required to follow training in order that they gain sufficient knowledge and skills to enable them to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the Entity, and the Entity is encouraged to offer similar training to its employees on a regular basis. Proof of compliance: Declaration/certification Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidence about the provisions covering the criterion by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail: (a) the governance arrangement by which the management body formally approves the cybersecurity risk-management measures adopted under Article 21, including the approval instrument, its date and the body that adopted it; (b) the process by which the management body oversees the implementation of those measures, including reporting lines, frequency of review and the records of such oversight; (c) the training followed by the members of the management body, including its content, frequency and completion records, demonstrating that it enables them to identify risks and assess cybersecurity risk-management practices and their impact on the services provided by the Entity; (d) the training offered, if any, on a regular basis to the employees of the Entity, including its content, frequency and coverage. Permissible Standards: N/A Note: This criterion reflects legal requirements under Article 20(1) and (2) of Directive (EU) 2022/2555 (NIS2). Note: Under Article 20(1), the management body can be held liable for infringements by the Entity of Article 21; that liability is established by national transposing law and is without prejudice to national law as regards the liability rules applicable to public institutions, public servants and elected or appointed officials. It is stated here as context and is not, as such, subject to evidence.
C5
Article 21 - Cybersecurity Risk-Management Measures
Criterion XX. The Entity shall implement appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of the network and information systems it uses for its operations or for the provision of its services, and to prevent or minimise the impact of incidents on the recipients of its services and to prevent or minimise the impact of incidents on recipients of their services and on other services. These measures shall take into account the state-of-the-art and, where applicable, relevant European and international standards, as well as the cost of implementation, and shall ensure a level of security appropriate to the risks posed, proportionate to the Entity's degree of exposure to risks, its size, and the likelihood of occurrence of incidents and their severity, including their societal and economic impact. The measures shall be based on an all-hazards approach that aims to protect network and information systems and the physical environment of those systems from incidents, and shall include at least the elements set out in the listed evidence below. Proof of compliance: Declaration/certification Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidence about the provisions covering the criterion by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail: (a) policies on risk analysis and information system security; (b) incident handling; (c) business continuity, such as backup management and disaster recovery, and crisis management; (d) supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers; (e) security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure; (f) policies and procedures to assess the effectiveness of cybersecurity risk-management measures; (g) basic cyber hygiene practices and cybersecurity training; (h) policies and procedures regarding the use of cryptography and, where appropriate, encryption; (i) human resources security, access control policies and asset management; (j) the use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the entity, where appropriate. Permissible Standards: N/A
C6
Article 21 - Cybersecurity Risk-Management Measures
Criterion XX. The Entity shall, when determining which supply chain security measures are appropriate under security-related aspects of the relationships with its direct suppliers and service providers, take into account the vulnerabilities specific to each direct supplier and service provider, the overall quality of the products and the cybersecurity practices of its suppliers and service providers (including their secure development procedures), and the results of the coordinated security risk assessments of critical supply chains carried out at Union level in accordance with Article 22(1) of Directive (EU) 2022/2555. The appropriateness of the measures shall be assessed and documented on this basis. Proof of compliance: Declaration/certification Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidence about the provisions covering the criterion by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail: (a) the process by which the Entity identifies and assesses the vulnerabilities specific to each direct supplier and service provider, and how those vulnerabilities inform the selection of supply chain security measures; (b) how the Entity evaluates the overall quality of the products supplied and the cybersecurity practices of its suppliers and service providers, including their secure development procedures (e.g. supplier security assessments, questionnaires, audits, certifications or contractual security requirements); (c) how the Entity takes into account the results of the coordinated security risk assessments of critical supply chains conducted at Union level under Article 22(1), where such results are relevant to its suppliers, products or services; (d) the documented link between this appropriateness assessment and the supply chain security measures implemented, demonstrating that the determination of "appropriate" measures is risk-informed. Permissible Standards: N/A Note: This criterion reflects Article 21(3) of Directive (EU) 2022/2555 (NIS2), and the factors that must drive the selection and calibration of the supply chain security measures already required in Article 21(2)(d). Note: Item (c) depends on the existence and availability of coordinated assessments under Article 22(1); where none yet exist for the relevant supply chain, the evidence should state this and confirm the Entity's process for incorporating such results once published.
C7
Article 21 - Cybersecurity Risk-Management Measures
Criterion XX. The Entity shall, where it finds that it does not comply with the measures provided for in Article 21(2) of Directive (EU) 2022/2555, take, without undue delay, all necessary, appropriate and proportionate corrective measures. Proof of compliance: Declaration/certification Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidence about the provisions covering the criterion by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail: (a) the process by which the Entity identifies and records instances of non-compliance with the measures set out in Article 21(2), including the sources of such findings (e.g. internal audit, self-assessment, security testing, incident analysis, supervisory findings); (b) the procedure ensuring that, upon such a finding, all necessary, appropriate and proportionate corrective measures are taken without undue delay, including responsibilities, escalation paths and timelines; (c) records, if any, evidencing previous findings of non-compliance and the corrective measures taken in response, including their tracking to closure. Permissible Standards: N/A Note: This criterion reflects legal requirements under Article 21(4) of Directive (EU) 2022/2555. Note: This criterion should be read together with Criterion XX drafted for Article 21(1) and (2) and Criterion XX drafted for Article 21(3) of Directive (EU) 2022/2555.
C8
Article 23 - Reporting Obligations
Criterion XX. The Entity shall notify, without undue delay, the relevant CSIRT or, where applicable, the competent authority in accordance with Article 23(4) of Directive (EU) 2022/2555 of any incident that has a significant impact on the provision of its services as referred to in Article 23(3) (significant incident) of Directive (EU) 2022/2555. The notification shall include, inter alia, any information enabling the CSIRT or, where applicable, the competent authority to determine any cross-border impact of the incident. Proof of compliance: Declaration/certification Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidences about the provisions covering the criterion by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail: (a) the documented process by which the Provider detects, classifies and determines whether an incident is "significant" against the two thresholds defined in Article 23(3) and described herein: i) it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned; or (ii) it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage; (b) the procedure ensuring notification to the competent CSIRT or competent authority without undue delay, including responsibilities, escalation paths and the identification of the correct recipient in each relevant jurisdiction; (c) how the notification captures the information needed to assess cross-border impact; (d) records or logs evidencing that significant incidents have been notified in accordance with this process. Permissible Standards: N/A Note: This criterion reflects legal requirements under Article 23(1) of Directive (EU) 2022/2555. Note: This notification duty is operationalized in Article 23(4) of Directive (EU) 2022/2555 and should be read together with Criterion C10 drafted for that paragraph.
C9
Article 23 - Reporting Obligations
Criterion (XX) The Entity shall, where applicable, communicate without undue delay to the recipients of its services that are potentially affected by a significant cyber threat any measures or remedies that those recipients are able to take in response to that threat. Where appropriate, the Provider shall also inform those recipients of the significant cyber threat itself. Proof of compliance: Declaration/certification Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidence about the provisions covering the criterion by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail: (a) the process by which the Provider identifies the recipients of its services that are potentially affected by a significant cyber threat; (b) the procedure and channels for communicating to those recipients, without undue delay, the measures or remedies they are able to take in response to the threat; (c) the criteria the Entity applies to determine when it is "appropriate" to additionally inform those recipients of the significant cyber threat itself, and how that information is communicated. Permissible Standards: N/A Note: According to Article 23(3) of Directive (EU) 2022/2555 (NIS2), an incident shall be treated as significant where it has caused or is capable of causing severe operational disruption of the services or financial loss for the Entity, or where it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage.
C10
Article 23 - Reporting Obligations
Criterion XX. The Entity shall, for the purpose of notification under Article 23(1) of Directive (EU) 2022/2555, submit to the CSIRT or, where applicable, the competent authority: (i) without undue delay and in any event within 24 hours of becoming aware of the significant incident, an early warning, which, where applicable, shall indicate whether the significant incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact; (ii) without undue delay and in any event within 72 hours of becoming aware of the significant incident, an incident notification, which, where applicable, shall update the information referred to in point (i) and indicate an initial assessment of the significant incident, including its severity and impact, as well as, where available, the indicators of compromise; (iii) upon the request of a CSIRT or, where applicable, the competent authority, an intermediate report on relevant status updates; and (iv) a final report not later than one month after the submission of the incident notification under point (ii), including the following: 1) a detailed description of the incident, including its severity and impact; (2) the type of threat or root cause that is likely to have triggered the incident; (3) applied and ongoing mitigation measures; (4) where applicable, the cross-border impact of the incident; and v) in the event of an ongoing incident at the time of the submission of the final report referred to in point (iv), provide a progress report at that time and a final report within one month of their handling of the incident. Proof of compliance: Declaration/certification Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidences about the provisions covering the criterion by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail: (a) the early-warning procedure ensuring submission within 24 hours of becoming aware of the significant incident, indicating, where applicable, whether the incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact; (b) the incident-notification procedure ensuring submission within 72 hours, updating the information in the early warning and providing an initial assessment of the incident, including its severity and impact and, where available, the indicators of compromise; (c) the capability to provide an intermediate report on relevant status updates upon the request of the CSIRT or competent authority; (d) the final-report procedure ensuring submission within one month of the incident notification, containing a detailed description of the incident (including its severity and impact), the type of threat or root cause likely to have triggered it, the applied and ongoing mitigation measures, and, where applicable, the cross-border impact; (e) the handling of ongoing incidents, ensuring submission of a progress report at the one-month point and a final report within one month of the incident being resolved; (f) where the Entity is a trust service provider, the procedure ensuring that significant incidents affecting the provision of its trust services are notified within 24 hours of becoming aware of the incident, in derogation from the 72-hour incident notification. Permissible Standards: N/A Note: This criterion reflects legal requirements under Article 23(4) of Directive (EU) 2022/2555. Note: This criterion operationalises the notification duty in Article 23(1) and should be read together with Criterion C8 drafted for that paragraph.
C11
Article 26 - Jurisdiction And Territoriality
Criterion XX. Where the Entity is a DNS service provider, a TLD name registry, an entity providing domain name registration services, a cloud computing service provider, a data centre service provider, a content delivery network provider, a managed service provider, a managed security service provider, or a provider of an online marketplace, of an online search engine or of a social networking services platform, and is not established in the Union but offers services within the Union, the Entity shall designate a representative in the Union. The representative shall be established in one of those Member States where the services are offered. Proof of compliance: Declaration/certification Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidence about the provisions covering the criterion by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail: (a) whether the Entity is established in the Union and, if so, the Member State in which the decisions related to the cybersecurity risk-management measures are predominantly taken, or, where such a Member State cannot be determined or such decisions are not taken in the Union, the Member State where cybersecurity operations are carried out or, failing that, the Member State where the Entity has the establishment with the highest number of employees in the Union; (b) where the Entity is not established in the Union but offers services within the Union, the identity, address and contact details of the representative designated in the Union and the instrument of designation; (c) that the designated representative is established in one of the Member States where the services are offered; (d) the Member State under whose jurisdiction the Entity considers itself to fall, and the basis for that determination. Permissible Standards: N/A Note: This criterion reflects legal requirements under Article 26(1) – (3) of Directive (EU) 2022/2555.
C12
Article 27 - Registry Of Entities
Criterion XX. Where the Entity is a DNS service provider, a TLD name registry, an entity providing domain name registration services, a cloud computing service provider, a data centre service provider, a content delivery network provider, a managed service provider, a managed security service provider, or a provider of an online marketplace, of an online search engine or of a social networking services platform, the Entity shall submit the following information to the competent authorities: (a) the name of the entity; (b) the relevant sector, subsector and type of entity referred to in Annex I or II of Directive (EU) 2022/2555, where applicable; (c) the address of the entity's main establishment and its other legal establishments in the Union or, if not established in the Union, of its representative designated pursuant to Article 26(3) of that Directive; (d) up-to-date contact details, including email addresses and telephone numbers of the entity and, where applicable, of its representative designated pursuant to Article 26(3); (e) the Member States where the entity provides services; and (f) the entity's IP ranges. The Entity shall notify the competent authority about any changes to the information submitted without delay and in any event within three months of the date of the change. Proof of compliance: Declaration/certification Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidence about the provisions covering the criterion by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail: (a) the submission made to the competent authority containing each of the items (a) to (f) listed in the criterion above; (b) where applicable, that the submission was made through the national mechanism referred to in Article 3(4), fourth subparagraph, of the Directive; (c) the documented process ensuring that any change to the information submitted is notified to the competent authority without delay and in any event within three months of the date of the change, including responsibilities and record-keeping; (d) records, if any, evidencing that changes have been notified in accordance with that process. Permissible Standards: N/A Note: Reflects Article 27(2), (3) and (5) of Directive (EU) 2022/2555 (NIS2). Note: This criterion should be read together with the Criterion XX Article 3(4).
C13
Article 28 - Database Of Domain Name Registration Data
Criterion XX. Where the Entity is a TLD name registry or an entity providing domain name registration services, the Entity shall collect and maintain accurate and complete domain name registration data in a dedicated database with due diligence in accordance with Union data protection law as regards data which are personal data. That database shall contain the necessary information to identify and contact the holders of the domain names and the points of contact administering the domain names under the TLDs, including: (a) the domain name; (b) the date of registration; (c) the registrant's name, contact email address and telephone number; and (d) the contact email address and telephone number of the point of contact administering the domain name in the event that they are different from those of the registrant. The Entity shall have policies and procedures, including verification procedures, in place to ensure that the database includes accurate and complete information, and shall make those policies and procedures publicly available. The Entity shall make publicly available, without undue delay after the registration of a domain name, the domain name registration data which are not personal data. The Entity shall provide access to specific domain name registration data upon lawful and duly substantiated requests by legitimate access seekers, in accordance with Union data protection law, shall reply without undue delay and in any event within 72 hours of receipt of any requests for access, and shall make the policies and procedures with regard to the disclosure of such data publicly available. Compliance with these obligations shall not result in a duplication of collecting domain name registration data, and to that end the Entity shall cooperate with other TLD name registries and entities providing domain name registration services. Proof of compliance: Declaration/certification Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidence about the provisions covering the criterion by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail: (a) the dedicated database of domain name registration data maintained by the Entity, and the demonstration that it contains the information listed in points (a) to (d) of Article 28(2) of Directive (EU) 2022/2555 (NIS2); (b) the policies and procedures, including verification procedures, in place to ensure that the database includes accurate and complete information, together with a resolvable hyperlink demonstrating that they are made publicly available; (c) the process ensuring publication, without undue delay after the registration of a domain name, of the domain name registration data which are not personal data; (d) the policies and procedures with regard to the disclosure of specific domain name registration data upon lawful and duly substantiated requests by legitimate access seekers, together with a resolvable hyperlink demonstrating that they are made publicly available, and the criteria applied to assess the lawfulness and substantiation of such requests; (e) the procedure ensuring that any request for access is replied to without undue delay and in any event within 72 hours of receipt, and records evidencing compliance with that time limit; (f) how the collection and maintenance of domain name registration data is carried out with due diligence and in accordance with Union data protection law as regards data which are personal data; (g) the cooperation arrangements with other TLD name registries and entities providing domain name registration services which ensure that compliance with the above obligations does not result in a duplication of collecting domain name registration data. Permissible Standards: N/A Note: Reflects Article 28 of Directive (EU) 2022/2555 (NIS2). The original provisions are addressed to Member States ("Member States shall require..."); for the purposes of this criterion the obligations are expressed directly against the Entity. This criterion applies only where the Entity is a TLD name registry or an entity providing domain name registration services within the meaning of Article 6, points (21) and (22), of that Directive.
C14
Article 29 - Cybersecurity Information-Sharing Arrangements
Criterion XX. Where the Entity participates in cybersecurity information-sharing arrangements referred to in Article 29(2) of Directive (EU) 2022/2555 (NIS2), the Entity shall notify the competent authorities of its participation in such arrangements upon entering into them, or, as applicable, of its withdrawal from such arrangements, once the withdrawal takes effect. Proof of compliance: Declaration/certification Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidence about the provisions covering the criterion by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail: (a) the cybersecurity information-sharing arrangements to which the Entity is a party, including the communities of essential and important entities and, where relevant, the suppliers or service providers within which the exchange of information takes place; (b) the procedure ensuring that the competent authority is notified of the Entity's participation upon entering into such an arrangement and of its withdrawal once the withdrawal takes effect, including responsibilities and timelines; (c) records evidencing that such notifications have been made; (d) where the Entity exchanges cybersecurity information on a voluntary basis under Article 29(1), the measures taken in respect of the potentially sensitive nature of the information shared. Permissible Standards: N/A Note: Reflects Article 29(4) of Directive (EU) 2022/2555 (NIS2). The original provision is addressed to Member States ("Member States shall ensure that essential and important entities notify"); for the purposes of this criterion the obligation is expressed directly against the Entity. Note: Article 29(1) establishes the ability of entities to exchange relevant cybersecurity information among themselves on a voluntary basis; it does not impose an obligation to do so, and item (d) is therefore conditional upon such participation. Article 29(3) and (5) are addressed to Member States and to ENISA respectively and do not impose obligations on the Entity.
C15
Article 32 - Supervisory And Enforcement Measures In Relation To Essential Entities
Criterion XX. The Entity shall ensure that any natural person responsible for the Entity or acting as its legal representative on the basis of the power to represent it, the authority to take decisions on its behalf or the authority to exercise control of it, has the power to ensure the Entity's compliance with Directive (EU) 2022/2555 (NIS2). Such natural persons may be held liable for breach of their duties to ensure compliance with that Directive. Proof of compliance: Declaration/certification Instruction for declaration: Using the Gaia-X Ontology, the declaration shall include evidence about the provisions covering the criterion by providing a resolvable hyperlink to an external source containing the evidence. The evidence shall detail: (a) the identification of the natural person or persons who are responsible for the Entity or who act as its legal representative on the basis of the power to represent it, the authority to take decisions on its behalf, or the authority to exercise control of it; (b) the instrument or arrangement (such as, but not limited to, statutes, articles of association, delegation of authority, mandate or board resolution) conferring on that person or those persons the power to ensure the Entity's compliance with Directive (EU) 2022/2555, including the scope of that power; (c) how that power enables the person concerned to require, adopt or enforce the measures necessary to bring the Entity into compliance, including the resources, reporting lines and decision-making authority available to them; (d) the arrangements under which such natural persons may be held liable for breach of their duties to ensure compliance with the Directive (EU) 2022/2555, as established under the applicable national transposing law. Permissible Standards: N/A Note: This criterion reflects legal requirements under Article 32(6) of Directive (EU) 2022/2555 (NIS2). Note: Article 32 applies to essential entities. However, by virtue of Article 33(5), Article 32(6) applies mutatis mutandis to important entities. This criterion therefore applies to the Entity irrespective of whether it is classified as an essential or an important entity. Note: The liability of the natural persons concerned is established by national transposing law and, as regards public administration entities, is without prejudice to national law as regards the liability of public servants and elected or appointed officials. It is stated here as context and is not, as such, subject to evidence beyond item (d).
Cancel