Emtract Ingest
API
EN
EN
DE
Dashboard
Regulations
Crawlers
Attributes
Topics
Home
/
Regulations
/
NIS2
/
Edit obligation
Edit obligation
Title (English)
Title (German)
Kind
Approval
Due Diligence
Governance
Other
Record Keeping
Reporting
Stakeholder Engagement
Frequency
Annual
Biennial
Continuous
Event-triggered
Monthly
One-time
Other
Quarterly
Weekly
Check frequency
Annual
Biennial
Continuous
Event-triggered
Monthly
One-time
Other
Quarterly
Weekly
Rule set
Regulation-wide (no rule set)
Entity of a type listed in Annex I or II, medium-sized or larger, active in the Union
Entity covered irrespective of its size
Essential entity
Important entity
Providers of DNS, TLD, domain registration, cloud, data centre and content delivery services, managed (security) services, online marketplaces, online search engines and social networks
TLD name registries and entities providing domain name registration services
Essential or important entity
Providers of DNS, TLD, domain registration, cloud, data centre and content delivery services, managed (security) services, online marketplaces, online search engines and social networks without an establishment in the Union
Company in NACE Rev. 2 Section C divisions 26 to 30, medium-sized or larger, active in the Union
Complexity (0–5)
Business functions
Communications
Compliance
Executive
Finance
Human Resources
Legal
Operations
Other
Procurement
Product
Sales
Sustainability
Description (English)
The management body of the entity approves the cybersecurity risk-management measures taken to comply with Article 21 and oversees their implementation. Approval is not a formality: members of the management body can be held personally liable for infringements of Article 21, and for an essential entity the competent authority may request that natural persons at managing director or legal representative level be temporarily prohibited from exercising managerial functions (Article 32(5), point (b)). In practice the duty calls for a documented decision on the cybersecurity policy, regular reporting to the management body and a traceable engagement with the results. For public administration entities national liability rules for public officials remain unaffected. The duty applies to essential and important entities alike.
Description (German)
Das Leitungsorgan der Einrichtung — Geschäftsführung oder Vorstand — billigt die zur Einhaltung des Artikels 21 ergriffenen Risikomanagementmaßnahmen im Bereich der Cybersicherheit und überwacht deren Umsetzung. Die Billigung ist keine Formalie: Die Mitglieder des Leitungsorgans können für Verstöße gegen Artikel 21 persönlich verantwortlich gemacht werden, und die zuständige Behörde kann einer wesentlichen Einrichtung gegenüber verlangen, dass natürlichen Personen auf Geschäftsführungs- oder Vorstandsebene vorübergehend untersagt wird, Leitungsaufgaben wahrzunehmen (Artikel 32 Absatz 5 Buchstabe b). Praktisch verlangt die Pflicht einen dokumentierten Beschluss über das Cybersicherheitskonzept, eine turnusmäßige Berichterstattung an das Leitungsorgan und eine nachvollziehbare Befassung mit den Ergebnissen. Für Einrichtungen der öffentlichen Verwaltung bleiben die nationalen Haftungsregelungen für öffentliche Bedienstete und Amtsträger unberührt. Die Pflicht trifft wesentliche und wichtige Einrichtungen gleichermaßen — also auch Einrichtungen, die nach Artikel 2 Absatz 2 unabhängig von ihrer Größe erfasst sind (Regelwerk „Wesentliche oder wichtige Einrichtung“).
Affected products/services (English)
Affected products/services (German)
Checking responsibility (English)
The management body of the entity; supervision of compliance lies with the competent authority designated under the national transposing act.
Checking responsibility (German)
Das Leitungsorgan der Einrichtung; die Überwachung der Einhaltung obliegt der nach dem Umsetzungsgesetz zuständigen Behörde.
Check method (English)
Evidence in the form of documented decisions of the management body, reporting lines and engagement with the results of security audits.
Check method (German)
Nachweis über dokumentierte Beschlüsse des Leitungsorgans, Berichtswege und die Befassung mit den Ergebnissen von Sicherheitsprüfungen.
Withdrawn at
Cancel
Delete this obligation