Article 34
Algemene voorwaarden voor het opleggen van administratieve geldboeten aan essentiële en belangrijke entiteiten
The 'Addressees' section of NIS2 specifically identifies and defines the entities and authorities to whom the directive applies and who bear responsibility for compliance. This requires a dedicated topic covering the identification, classification, and designation procedures for all addressees under NIS2.
The scope and classification of entities responsible for compliance under the Network and Information Security 2 Directive (NIS2) are primarily governed by Articles 3 and 4 NIS2, which define the categories of "essential entities" and "important entities." Recital 15 NIS2 provides the rationale for this two-tier classification, stipulating that entities must be categorized based on their criticality for the sector or type of service provided, as well as their size. This classification determines the stringency of cybersecurity risk management measures and incident reporting obligations that apply.
The authoritative commentary from Tekst & Commentaar, while focused on the GDPR, underscores a fundamental legal principle relevant to NIS2's application: the importance of clear and unambiguous identification of obligated parties. Applied to NIS2, this principle means Member States must precisely transpose the sector-based criteria of Annexes I and II into national law to designate essential and important entities. The commentary's emphasis on avoiding situations where entities have no real choice aligns with NIS2's goal of ensuring that all designated entities are definitively within scope and understand their obligations. Furthermore, Recital 24 NIS2 highlights the need for coordination where sector-specific Union law imposes equivalent reporting duties, requiring that incident notifications are routed to the competent authorities under NIS2 (such as CSIRTs or single points of contact) to ensure consistent handling. This prevents regulatory gaps or overlaps for entities operating under multiple regimes.
Algemene voorwaarden voor het opleggen van administratieve geldboeten aan essentiële en belangrijke entiteiten
Guidelines on codes of conduct and monitoring bodies
Guidelines on the application of Article 60 GDPR
With the introduction of the GDPR, the concept of the one-stop shop was established as one of the main innovations. In cross-border processing cases, the supervisory authority in the Member State of the controller's or processor's main establishment is the authority leading the enforcement of the GDPR for the respective cross-border processing activities, in cooperation with all the authorities which may face the effects of the processing activities at stake: be it through the establishments ...
Guidelines on the targeting of social media users
Guidelines on the application of Article 60 GDPR