Today is NIS2 Day! Now What?

Author photo: Larry O'Brien
ByLarry O'Brien
Category:
Technology Trends

October 17, 2024, Marks the Official Directive Deadline for NIS2 Directive, But Not Everyone is Ready

For those who are not familiar, The Network and Information Security 2 (NIS2) directive introduces a range of obligations on manufacturers, importers, distributors, and other stakeholders in the digital ecosystem, including automation system suppliers and any company with greater than €10 million in revenues. Non-compliance can result in fines of up to 10 percent of annual revenues. NIS2 was to be adopted by the individual EU member states as of today, October 17, 2024.

NIS2 Logo

My colleague Thomas Menze provided a good writeup of the recent discussion around NIS2 at the ARC European Forum that you can read here. Some of the key points from that discussion include the requirement for automation system suppliers to ensure that their products comply with the new regulations. They will also need to conduct cyber risk assessments before a product is placed on the market. Additionally, suppliers will have additional due diligence requirements regarding their third-party suppliers of components, especially where those components may impact the overall security of the device. NIS2 also introduces stricter penalties for non-compliance, including fines of up to 10 percent of an entity’s annual turnover. For entities defined as “critical”, Member states are required to impose a fine of 10 million euros or 2 percent of the global annual turnover.

According to a statement from the European Commission yesterday:

"The Commission has adopted today the first implementing rules on cybersecurity of critical entities and networks under the Directive on measures for high common level of cybersecurity across the Union (NIS2 Directive). This implementing act details cybersecurity risk management measures as well as the cases in which an incident should be considered significant and companies providing digital infrastructures and services should report it to national authorities. This is another major step in boosting the cyber resilience of Europe's critical digital infrastructure. The implementing regulation adopted today will apply to specific categories of companies providing digital services, such as cloud computing service providers, data centre service providers, online marketplaces, online search engines and social networking platforms, to name a few. For each category of service providers, the implementing act also specifies when an incident is considered significant.* Today's adoption of the implementing regulation coincides with the deadline for Member States to transpose the NIS2 Directive into national law. As of tomorrow, 18 October 2024, all Member States must apply the measures necessary to comply with the NIS2 cybersecurity rules, including supervisory and enforcement measures."

What Automation Suppliers Must Do 

To ensure compliance with the NIS2 directive, automation suppliers can take several steps. They can establish a singular, centralized governance structure for their company security, educate their staff about the NIS2 Directive and its implications, assess their current security measures and identify areas for improvement, and determine which of their partners and suppliers will be affected by the NIS2 Directive.

End users are expected to become more aware of the cybersecurity measures in place for the digital products they use, and to manage their own responsibilities as system operators. System integrators will need to ensure that the systems they integrate comply with the new cybersecurity standards, and to conduct cyber risk assessments before their solution is placed on the market. Therefore, it is crucial for end users and system integrators to stay informed about the NIS2 directive and its implications, and to adopt best practices for cybersecurity governance, awareness training, security health check, and supply chain security.

Not Everyone is Ready

However, not all member states of the EU are prepared to adopt NIS2 today. According to a statement from the EU:

"Under Article 41 (Transposition) of the NIS2 Directive, by 17 October 2024, all EU Member States are required to adopt and publish the national measures necessary to ensure compliance with the directive. These measures are critical for aligning national legislation with the enhanced cybersecurity requirements introduced by NIS2. Following the adoption, these measures must be enforced starting from 18 October 2024, marking the beginning of a new era in cybersecurity across the EU. Many Member States have faced delays in transposing the directive into national law. This has raised concerns about the uniform implementation of the directive’s provisions and the readiness of essential and important sectors to comply with enhanced cybersecurity requirements."

In spite of these delays, it is only a matter of time before all states transpose the directive into national law, and the regulations will certainly be enforced. ARC expects the NIS2 directive to continue to boost investment in industrial cybersecurity, particularly for small- to medium-sized companies.

 

Engage with ARC Advisory Group

Representative End User Clients
Representative Automation Clients
Representative Software Clients