Emtract Ingest
API
EN
EN
DE
Dashboard
Regulations
Crawlers
Attributes
Topics
Home
/
Regulations
/
NIS2
/
Edit obligation
Edit obligation
Title (English)
Title (German)
Kind
Approval
Due Diligence
Governance
Other
Record Keeping
Reporting
Stakeholder Engagement
Frequency
Annual
Biennial
Continuous
Event-triggered
Monthly
One-time
Other
Quarterly
Weekly
Check frequency
Annual
Biennial
Continuous
Event-triggered
Monthly
One-time
Other
Quarterly
Weekly
Rule set
Regulation-wide (no rule set)
Entity of a type listed in Annex I or II, medium-sized or larger, active in the Union
Entity covered irrespective of its size
Essential entity
Important entity
Providers of DNS, TLD, domain registration, cloud, data centre and content delivery services, managed (security) services, online marketplaces, online search engines and social networks
TLD name registries and entities providing domain name registration services
Essential or important entity
Providers of DNS, TLD, domain registration, cloud, data centre and content delivery services, managed (security) services, online marketplaces, online search engines and social networks without an establishment in the Union
Company in NACE Rev. 2 Section C divisions 26 to 30, medium-sized or larger, active in the Union
Complexity (0–5)
Business functions
Communications
Compliance
Executive
Finance
Human Resources
Legal
Operations
Other
Procurement
Product
Sales
Sustainability
Description (English)
Where appropriate, the entity informs the recipients of its services without undue delay of significant incidents that are liable to adversely affect the provision of that service (Article 23(1), first subparagraph, second sentence). In addition, the entity communicates without undue delay to the recipients of its services that are potentially affected by a significant cyber threat any measures or remedies that those recipients are able to take in response, and where appropriate informs them of the significant cyber threat itself (Article 23(2)). The competent authority may in addition order the entity to inform the persons potentially affected (Article 32(4), point (e), and Article 33(4), point (e)), and the CSIRT may request the entity to inform the public (Article 23(7)).
Description (German)
Die Einrichtung unterrichtet gegebenenfalls die Empfänger ihrer Dienste unverzüglich über erhebliche Sicherheitsvorfälle, die die Erbringung des jeweiligen Dienstes beeinträchtigen könnten (Artikel 23 Absatz 1 Unterabsatz 1 Satz 2). Darüber hinaus teilt die Einrichtung den potenziell von einer erheblichen Cyberbedrohung betroffenen Empfängern ihrer Dienste unverzüglich alle Maßnahmen oder Abhilfemaßnahmen mit, die diese Empfänger als Reaktion auf die Bedrohung ergreifen können; gegebenenfalls informiert sie die Empfänger auch über die erhebliche Cyberbedrohung selbst (Artikel 23 Absatz 2). Die zuständige Behörde kann die Einrichtung zusätzlich anweisen, die potenziell betroffenen Personen zu unterrichten (Artikel 32 Absatz 4 Buchstabe e, Artikel 33 Absatz 4 Buchstabe e), und das CSIRT kann die Einrichtung auffordern, die Öffentlichkeit zu informieren (Artikel 23 Absatz 7).
Affected products/services (English)
All services of the entity whose provision could be adversely affected by the incident, and all recipients potentially affected by the cyber threat.
Affected products/services (German)
Alle Dienste der Einrichtung, deren Erbringung durch den Sicherheitsvorfall beeinträchtigt werden könnte, und alle Empfänger, die potenziell von der Cyberbedrohung betroffen sind.
Checking responsibility (English)
Checking responsibility (German)
Check method (English)
Check method (German)
Withdrawn at
Cancel
Delete this obligation