farbbalken
European Economic Area (EU + Iceland, Lichtenstein, Norway)
ESS EEA Cybersecurity - Essential and important entities
IT; OT; Operational technology (OT) controls devices; Information technology (IT) controls data; Threat modelling; Threat modeling; vulnerability; incident; handling; ISMS; data privacy; security asset; network asset, privacy asset; financial asset

59.00 € NET

30-Tages-Lizenz

Anwendungsbereich des Regulatory Essentials

This ESSENTIAL introduces some cyberescurity aspects outlined by the NIS-2 Directive. For product related requirements see:

Stakeholder:

Manufacturer, Importer, B2C products, B2B products

Geltende Rechtsvorschriften:

NIS-2-Directive (EU) 2022/2555 Publication in OJEU on 27.12.2022. Brief description of NIS-2 Directive (EU) 2022/2555 Scope: - significantly expanded compared to NIS. - companies that employ more than 50 people AND - have an annual turnover or an annual balance sheet of more than EUR 10 million AND - belong to a critical or most important sector. - covered sectors are being massively expanded. - critical health sector will include healthcare providers, for example, and in particular laboratories, medical research and pharmaceuticals, and manufacturers of medical devices. - critical “digital infrastructure” sector, which in future will also include cloud providers, data centers and content delivery networks in particular, will be significantly expanded. - important sectors will include the entire industrial sector and in particular manufacturers of medical devices and computers, but also the mechanical engineering and mobility sectors. Obligations: - NIS 2 directive provides for various risk management measures and reporting obligations for companies - in particular the creation of risk analysis and security concepts for the information systems, the management of incidents, the disclosure of weak points and ensuring security in the supply chain. - two-step approach is envisaged for reporting. - after becoming aware of an incident, companies have 24 hours to submit a preliminary report, followed by a final report no later than one month later. Entities & Sectors: - in NIS 2 more entities and sectors will have to take measures to protect themselves: - “Essential sectors” such as the energy, transport, banking, health, digital infrastructure, public administration and space sectors will be covered by the new security provisions. - “Important sectors” (NEW) also fall under NIS 2 such as postal services, waste management, chemicals, food, manufacturing of medical devices, electronics, machinery, motor vehicles and digital providers. All medium-sized and large companies in selected sectors would fall under the legislation.

Nationale Anwendungsebene:

Länder:

 

European Economic Area (EU + Iceland, Lichtenstein, Norway)

Status:

Published 2024-07-04 by Anne Barsuhn and Benjamin Kerger
Last change 2026-01-22 by Anne Barsuhn: Legislation in force for this PCT, Cybersecurity

ID:

#g373


Inhalt des Regulatory Essentials

Legislation in force for this PCT
Hier erhalten sie eine Tabelle

Are legal provisions regulates the product compliance topic? If yes, what is the reference (title, number)?

Scope of legislation
Subject: Measures that aim to achieve a high common level of cybersecurity
- Obligations for Member States (strategies, authorities, contact points, incident response teams
- Cybersecurity risk-management measures and reporting obligations for entities “CSIRTs”
- Rules and obligations
- Supervisory and enforcement obligations on Member States.'

Scope of legislation
Hier erhalten Sie verlinkte Dokumente zu dieser Thematik

Responsible actors
Hier erhalten Sie textbasierte Informationen

Which actor(s) are responsible for compliance with the legal provisions: e. g. - economic operators (manufacturer, importer, distributor, fulfilment service provider), - user (commercial/industrial/professional), - user (private, consumer)?

Responsible actors
Hier finden Sie ein thematisch passendes Dokument in ATERIOS
(Zugang nur mit erweiterter ATERIOS Lizenz)

Which actor(s) are responsible for compliance with the legal provisions: e. g. - economic operators (manufacturer, importer, distributor, fulfilment service provider), - user (commercial/industrial/professional), - user (private, consumer)?

Process-related requirements?
Hier erhalten Sie textbasierte Informationen

Product-related requirements?
Hier erhalten Sie textbasierte Informationen

Product-related requirements?
Hier erhalten Sie zugehörige weiterführende Links

Regulatory market access conditions for the actor(s)
Hier erhalten Sie textbasierte Informationen

What are the main regulatory requirements (e. g. conformity assessment fulfilment of essential requirements of Annex I 2006/42/EC) prior placing on the market, importation and putting into service (brief description)

Penalty by this legislation
Hier erhalten Sie textbasierte Informationen

What are the possible penalties (e. g. sales ban, fines) in the case of non-compliance?

Exemption clauses
Hier erhalten Sie textbasierte Informationen

Exempted devices/products or industry sectors.

Sub-federal legislation of states/counties
Hier erhalten Sie textbasierte Informationen

E. g. by 2019 an Inter-Governmental Agreement (IGA) on governance of the Electrical Equipment Safety System (EESS) has been signed by Queensland, Victoria, Western Australia and Tasmania.

FTA/MRA status with EU
Hier erhalten Sie textbasierte Informationen

Has the country signed a Free Trade Agreement (FTA) or a Mutual recognition agreement (MRA) with EU?

Adequate third countries to transfer data
Hier erhalten Sie textbasierte Informationen

Authority
Hier erhalten Sie textbasierte Informationen

Name of the authority for approval, registration, market surveillance and/or enforcement

Market surveillance authority
Hier erhalten Sie zugehörige weiterführende Links

Name of the authority for market surveillance and/or enforcement

Hints
Hier erhalten Sie zugehörige weiterführende Links

Specific recommendations, information or most common mistakes

User instructions language(s)
Hier erhalten sie eine Tabelle

Regulated by the legal provisions

Route to compliance

Formal and administrative requirements

Registration at related authority required?
Hier erhalten Sie textbasierte Informationen

Product registration? Manufacturer registration? Importer / Representative registration? if required.

Local representative legally required?
Hier erhalten Sie textbasierte Informationen

[Yes/No]

Hints
Hier erhalten Sie textbasierte Informationen

Specific recommendations, information or most common mistakes

Equipment authorization (approval process)

Approval process (conformity assessment procedure)
Hier erhalten Sie textbasierte Informationen

Means each legally required approval process prior placing on the market, importation or putting into service

Testing & Standards

Specific requirements for testing
Hier erhalten Sie textbasierte Informationen

e. g. is an accredited test lab. mandatory, limits, test samples, product description

Source for standards for conformity assessment
Hier erhalten Sie textbasierte Informationen

Hints
Hier erhalten Sie zugehörige weiterführende Links

Specific recommendations, information or most common mistakes

Regulatory labelling, markings and user information

Regulatory label (mandatory)
Hier erhalten Sie textbasierte Informationen

e. g. product label


Allgemeine Informationen

   
European Economic Area (EU + Iceland, Lichtenstein, Norway)

Code, Kontinent, Wirtschaftsraum

EEA,

Wirtschaftsraum

Offizielle Amtssprache

24 official languages

Normen Institut

HS Codemitglied

Full width

Sind noch fragen offen?

Wir freuen uns zu helfen:
essentials@globalnorm.de +49 30 3229027-50

LIZENZIEREN SIE DIESES REGULATORY ESSENTIAL
für 59.00 € NET

 

Oder kaufen über Buy a 30 day license for 59.00 € net now ....

Ihre persönlichen Daten werden von GLOBALNORM verarbeitet.

Weiter Informationen können in unsere Datenschutzerklärung.