What Will Change in the NIS2 Directive?

NIS2 Is About Critical infrastructures
(photo by Denkrahm, CC BY 2.0)

 

The European Union (EU) is implementing a so-called digital omnibus. Depending on a viewpoint, it is about regulatory simplification, deregulation, or something in-between. Also the second network and information security (NIS2 or NIS 2, as it should be officially abbreviated) directive, Directive (EU) 2022/2555, is a part of the digital omnibus. Therefore, it is worth taking a look on what changes can be expected.

The NIS2 directive together with other recent EU regulations impose various obligations for reporting cyber security incidents. The digital omnibus will streamline the reporting obligations by providing a single entry point for incident reporting. The single entry-point will apply also to reporting of personal data breaches under the GDPR, the General Data Protection Regulation.

What else? A recent proposal from the European Commission includes six targeted amendments to the NIS2 directive. To begin with, (1) definitions and the directive’s scope will be clarified, and (2) micro- and small-sized domain name system (DNS) providers will be excluded from the scope entirely. To reduce compliance burden, (3) a new category of small mid-cap enterprises will also appear. Furthermore, (4) the NIS2’s all-embracing risk management obligations – the “all-hazards” approach specified in Article 21 – will be supported by implementing acts involving technical and methodological requirements and guidance.

The last two amendments proposed are perhaps the most interesting ones. The national cyber security strategies of the member states, which were obliged by the NIS2 directive, (5) should be altered by adopting policies for the migration to post-quantum cryptography. Although it is impossible to say when conventional cryptography will start breaking, the preparations seem to be thus well-underway.

Then, (6) a harmonized scheme will be introduced for collecting data on ransomware attacks. On the operational side, data will be collected on the detection of ransomware attacks, their attack vectors, and the presence (or a lack thereof) of mitigation measures. With respect to significant incidents, which has a specific definition in NIS2, data will be collected on who received a ransom demand and, if possible, by whom, as well as on any payments made, amounts paid, means of payment, recipients, and any cryptocurrencies and their service providers involved. Confidentiality is emphasized in the proposal. In other words, data will flow only between victims and national computer security incident response teams. Given that ransomware is a global menace, open and regular releasing of statistical data can nevertheless be hoped for. After all, the EU is a member of the International Counter Ransomware Initiative.

Finally, it should be emphasized and understood that the digital omnibus is still being negotiated. As always, nothing is absolutely certain in politics. For instance, some have criticized the streamlining of incident reporting, whereas others have signaled a preference for national entry points for incident reporting instead of a single EU-wide reporting platform. Despite these political preferences, in overall, the changes proposed seem rather noncontroversial and sensible. The political battlegrounds are largely elsewhere.