LawyersForPeace.Online

a curated map of the law of peace in the cyber & information sphere

User Tools

Site Tools


law:eu:nis2_cer

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
law:eu:nis2_cer [2026/09/27 19:07] – Matrix position replaced by subject area lfpolaw:eu:nis2_cer [2026/10/01 14:09] (current) – Disclaimer reference added lfpo
Line 1: Line 1:
-====== Directive (EU) 2022/2555 (NIS2 Directive) and Directive (EU) 2022/2557 (Critical Entities Resilience Directive) ======+====== EU NIS2 and CER Directives (2022) ======
  
-//Draft – editorial review pending. As of 27 September 2026.//+//As of 30 September 2026. Information only, not legal advice – see the [[about:disclaimer|disclaimer]].//
  
 +^ Full title | Directive (EU) 2022/2555 (NIS2 Directive) and Directive (EU) 2022/2557 (Critical Entities Resilience Directive) |
 ^ Type | EU directives | ^ Type | EU directives |
 ^ Adopted by | European Parliament and Council of the European Union | ^ Adopted by | European Parliament and Council of the European Union |
Line 25: Line 26:
 The directives do not address attribution or State responsibility; they regulate preparedness, resilience and incident handling. They form part of the EU's internal framework alongside the external measures of the [[law:eu:cyber_sanctions|EU cyber sanctions regime and Cyber Diplomacy Toolbox]]. The directives do not address attribution or State responsibility; they regulate preparedness, resilience and incident handling. They form part of the EU's internal framework alongside the external measures of the [[law:eu:cyber_sanctions|EU cyber sanctions regime and Cyber Diplomacy Toolbox]].
  
-**Germany.** The NIS2 Directive was transposed by the "Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung" (NIS2UmsuCG) of 2 December 2025, promulgated in BGBl. 2025 I Nr. 301 on 5 December 2025; it entered into force on 6 December 2025 and substantially amends the BSI Act (BSIG). The CER Directive was transposed by the "Gesetz zur Umsetzung der Richtlinie (EU) 2022/2557 und zur Stärkung der Resilienz kritischer Anlagen" (KRITIS-Dachgesetz), promulgated in BGBl. 2026 I Nr. 66 on 16 March 2026 [to be verified: entry-into-force date(s)].+**Germany.** The NIS2 Directive was transposed by the "Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung" (NIS2UmsuCG) of 2 December 2025, promulgated in BGBl. 2025 I Nr. 301 on 5 December 2025; it entered into force on 6 December 2025 and substantially amends the BSI Act (BSIG). The CER Directive was transposed by the "Gesetz zur Umsetzung der Richtlinie (EU) 2022/2557 und zur Stärkung der Resilienz kritischer Anlagen" (KRITIS-Dachgesetz), of 11 March 2026, promulgated in BGBl. 2026 I Nr. 66 on 16 March 2026; according to the Federal Government it entered into force on 17 March 2026, with certain provisions applying from later dates.
  
 ===== Recent developments ===== ===== Recent developments =====
Line 31: Line 32:
   * 2025-05-07: Commission reasoned opinions to 19 Member States (including Germany) for failure to notify complete transposition of NIS2 (European Commission).   * 2025-05-07: Commission reasoned opinions to 19 Member States (including Germany) for failure to notify complete transposition of NIS2 (European Commission).
   * 2025-12-06: German NIS2UmsuCG enters into force (BGBl. 2025 I Nr. 301).   * 2025-12-06: German NIS2UmsuCG enters into force (BGBl. 2025 I Nr. 301).
-  * 2026-03-16: German KRITIS-Dachgesetz promulgated (BGBl. 2026 I Nr. 66). +  * 2026-03-16: German KRITIS-Dachgesetz promulgated (BGBl. 2026 I Nr. 66); in force since 17 March 2026. 
-  * 2026-07: Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failure to notify complete transposition of NIS2 [to be verified against official Commission release].+  * 2026-07-08: Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify complete transposition of NIS2 (Commission press release IP/26/1499).
  
 ===== Related entries ===== ===== Related entries =====
Line 39: Line 40:
   * [[law:national:germany]]   * [[law:national:germany]]
   * [[gaps:nc3]]   * [[gaps:nc3]]
 +  * [[law:eu:cyber_resilience_act]]
  
 ===== Sources ===== ===== Sources =====
Line 46: Line 48:
   * [[https://www.bmi.bund.de/SharedDocs/gesetzgebungsverfahren/DE/CI1/nis2umsucg.html|Federal Ministry of the Interior: NIS2UmsuCG legislative procedure]], accessed 2026-09-27   * [[https://www.bmi.bund.de/SharedDocs/gesetzgebungsverfahren/DE/CI1/nis2umsucg.html|Federal Ministry of the Interior: NIS2UmsuCG legislative procedure]], accessed 2026-09-27
   * [[https://www.recht.bund.de/bgbl/1/2026/66/VO.html|BGBl. 2026 I Nr. 66 (KRITIS-Dachgesetz)]], accessed 2026-09-27   * [[https://www.recht.bund.de/bgbl/1/2026/66/VO.html|BGBl. 2026 I Nr. 66 (KRITIS-Dachgesetz)]], accessed 2026-09-27
 +  * [[https://www.bundesregierung.de/breg-de/aktuelles/kritis-dachgesetz-2383682|Federal Government: Stärkerer Schutz kritischer Infrastrukturen (KRITIS-Dachgesetz)]], accessed 2026-09-30
 +  * [[https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1499|European Commission: Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose the rules on cybersecurity (IP/26/1499)]], accessed 2026-09-30
   * [[https://digital-strategy.ec.europa.eu/en/news/commission-calls-19-member-states-fully-transpose-nis2-directive|European Commission: Commission calls on 19 Member States to fully transpose NIS2]], accessed 2026-09-27   * [[https://digital-strategy.ec.europa.eu/en/news/commission-calls-19-member-states-fully-transpose-nis2-directive|European Commission: Commission calls on 19 Member States to fully transpose NIS2]], accessed 2026-09-27
  
 ===== Change log ===== ===== Change log =====
   * 2026-09-27: Entry created (draft).   * 2026-09-27: Entry created (draft).
 +  * 2026-09-30: Entry reviewed and finalised.
 +  * 2026-10-01: Cross-reference to the Cyber Resilience Act added.
  
law/eu/nis2_cer.1790536042.txt.gz · Last modified: by lfpo