Recitals
The 144 recitals of NIS 2
Recitals are not binding, but they say why the text reads as it does. Regulators and courts rely on them to interpret an ambiguous article — that is often where a reading is decided.
- 1. Directive (EU) 2016/1148 of the European Parliament and the Council...
- 2. Since the entry into force of Directive (EU) 2016/1148, significant...
- 3. Network and information systems have developed into a central feature...
- 4. The legal basis of Directive (EU) 2016/1148 was Article 114 of the...
- 5. All those divergences entail a fragmentation of the internal market...
- 6. With the repeal of Directive (EU) 2016/1148, the scope of application...
- 7. Under Directive (EU) 2016/1148, Member States were responsible for...
- 8. The exclusion of public administration entities from the scope of...
- 9. Member States should be able to take the necessary measures to ensure...
- 10. Although this Directive applies to entities carrying out activities...
- 11. Some entities carry out activities in the areas of national security,...
- 12. Postal service providers as defined in Directive 97/67/EC of the...
- 13. Given the intensification and increased sophistication of cyber...
- 14. Union data protection law and Union privacy law applies to any...
- 15. Entities falling within the scope of this Directive for the purpose...
- 16. In order to avoid entities that have partner enterprises or that are...
- 17. Member States should be able to decide that entities identified...
- 18. In order to ensure a clear overview of the entities falling within...
- 19. Member States should be responsible for submitting to the Commission...
- 20. The Commission should, in cooperation with the Cooperation Group and...
- 21. The Commission could provide guidance to assist Member States in...
- 22. This Directive sets out the baseline for cybersecurity...
- 23. Where a sector-specific Union legal act contains provisions requiring...
- 24. Where provisions of a sector-specific Union legal act require...
- 25. Sector-specific Union legal acts which provide for cybersecurity...
- 26. Where sector-specific Union legal acts require or provide incentives...
- 27. Future sector-specific Union legal acts should take due account of...
- 28. Regulation (EU) 2022/2554 of the European Parliament and of the...
- 29. In order to avoid gaps between or duplications of cybersecurity...
- 30. In view of the interlinkages between cybersecurity and the physical...
- 31. Entities belonging to the digital infrastructure sector are in...
- 32. Upholding and preserving a reliable, resilient and secure domain name...
- 33. Cloud computing services should cover digital services that enable...
- 34. Given the emergence of innovative technologies and new business...
- 35. Services offered by data centre service providers may not always be...
- 36. Research activities play a key role in the development of new...
- 37. The growing interdependencies are the result of an increasingly...
- 38. In view of the differences in national governance structures and in...
- 39. In order to facilitate cross-border cooperation and communication...
- 40. The single points of contact should ensure effective cross-border...
- 41. Member States should be adequately equipped, in terms of both...
- 42. The CSIRTs are tasked with incident handling. This includes the...
- 43. As regards personal data, the CSIRTs should be able to provide, in...
- 44. The CSIRTs should have the ability, upon an essential or important...
- 45. Given the importance of international cooperation on cybersecurity,...
- 46. Ensuring adequate resources to meet the objectives of this Directive...
- 47. The CSIRTs network should continue to contribute to strengthening...
- 48. For the purpose of achieving and maintaining a high level of...
- 49. Cyber hygiene policies provide the foundations for protecting network...
- 50. Cybersecurity awareness and cyber hygiene are essential to enhance...
- 51. Member States should encourage the use of any innovative technology,...
- 52. Open-source cybersecurity tools and applications can contribute to a...
- 53. Utilities are increasingly connected to digital networks in cities,...
- 54. In recent years, the Union has faced an exponential increase in...
- 55. Public-private partnerships (PPPs) in the field of cybersecurity can...
- 56. Member States should, in their national cybersecurity strategies,...
- 57. As part of their national cybersecurity strategies, Member States...
- 58. Since the exploitation of vulnerabilities in network and information...
- 59. The Commission, ENISA and the Member States should continue to foster...
- 60. Member States, in cooperation with ENISA, should take measures to...
- 61. Member States should designate one of its CSIRTs as a coordinator,...
- 62. Access to correct and timely information about vulnerabilities...
- 63. Although similar vulnerability registries or databases exist, they...
- 64. The Cooperation Group should support and facilitate strategic...
- 65. When developing guidance documents, the Cooperation Group should...
- 66. The Cooperation Group should remain a flexible forum and be able to...
- 67. The competent authorities and the CSIRTs should be able to...
- 68. Member States should contribute to the establishment of the EU...
- 69. In accordance with the Annex to Recommendation (EU) 2017/1584, a...
- 70. Large-scale cybersecurity incidents and crises at Union level require...
- 71. EU-CyCLONe should work as an intermediary between the technical and...
- 72. Cyberattacks are of a cross-border nature, and a significant incident...
- 73. The Union can, where appropriate, conclude international agreements,...
- 74. In order to facilitate the effective implementation of this Directive...
- 75. Peer reviews should be introduced to help learn from shared...
- 76. The Cooperation Group should establish a self-assessment methodology...
- 77. Responsibility for ensuring the security of network and information...
- 78. Cybersecurity risk-management measures should take into account the...
- 79. As threats to the security of network and information systems can...
- 80. For the purpose of demonstrating compliance with cybersecurity...
- 81. In order to avoid imposing a disproportionate financial and...
- 82. Cybersecurity risk-management measures should be proportionate to the...
- 83. Essential and important entities should ensure the security of the...
- 84. Taking account of their cross-border nature, DNS service providers,...
- 85. Addressing risks stemming from an entity’s supply chain and its...
- 86. Among service providers, managed security service providers in areas...
- 87. The competent authorities, in the context of their supervisory tasks,...
- 88. Essential and important entities should also address risks stemming...
- 89. Essential and important entities should adopt a wide range of basic...
- 90. To further address key supply chain risks and assist essential and...
- 91. The coordinated security risk assessments of critical supply chains,...
- 92. In order to streamline the obligations imposed on providers of public...
- 93. The cybersecurity obligations laid down in this Directive should be...
- 94. Member States can assign the role of the competent authorities for...
- 95. Where appropriate and in order to avoid unnecessary disruption,...
- 96. Given the growing importance of number-independent interpersonal...
- 97. The internal market is more reliant on the functioning of the...
- 98. In order to safeguard the security of public electronic...
- 99. In order to safeguard the security, and to prevent abuse and...
- 100. In order to safeguard the functionality and integrity of the internet...
- 101. This Directive lays down a multiple-stage approach to the reporting...
- 102. Where essential or important entities become aware of a significant...
- 103. Where applicable, essential and important entities should...
- 104. Providers of public electronic communications networks or of publicly...
- 105. A proactive approach to cyber threats is a vital component of...
- 106. In order to simplify the reporting of information required under this...
- 107. Where it is suspected that an incident is related to serious criminal...
- 108. Personal data are in many cases compromised as a result of incidents....
- 109. Maintaining accurate and complete databases of domain name...
- 110. The availability and timely accessibility of domain name registration...
- 111. In order to ensure the availability of accurate and complete domain...
- 112. TLD name registries and entities providing domain name registration...
- 113. Entities falling within the scope of this Directive should be...
- 114. In order to take account of the cross-border nature of the services...
- 115. Where a publicly available recursive DNS service is provided by a...
- 116. Where a DNS service provider, a TLD name registry, an entity...
- 117. In order to ensure a clear overview of DNS service providers, TLD...
- 118. Where information which is classified in accordance with Union or...
- 119. With cyber threats becoming more complex and sophisticated, good...
- 120. Entities should be encouraged and assisted by Member States to...
- 121. The processing of personal data, to the extent necessary and...
- 122. In order to strengthen the supervisory powers and measures that help...
- 123. The execution of supervisory tasks by the competent authorities...
- 124. In the exercise of ex ante supervision, the competent authorities...
- 125. The competent authorities should ensure that their supervisory tasks...
- 126. In duly substantiated cases where it is aware of a significant cyber...
- 127. In order to make enforcement effective, a minimum list of enforcement...
- 128. This Directive does not require Member States to provide for criminal...
- 129. In order to ensure effective enforcement of the obligations laid down...
- 130. Where an administrative fine is imposed on an essential or important...
- 131. Member States should be able to lay down the rules on criminal...
- 132. Where this Directive does not harmonise administrative penalties or...
- 133. In order to further strengthen the effectiveness and dissuasiveness...
- 134. For the purpose of ensuring entities’ compliance with their...
- 135. In order to ensure effective supervision and enforcement, in...
- 136. This Directive should establish cooperation rules between the...
- 137. This Directive should aim to ensure a high level of responsibility...
- 138. In order to ensure a high common level of cybersecurity across the...
- 139. In order to ensure uniform conditions for the implementation of this...
- 140. The Commission should periodically review this Directive, after...
- 141. This Directive creates new tasks for ENISA, thereby enhancing its...
- 142. Since the objective of this Directive, namely to achieve a high...
- 143. This Directive respects the fundamental rights, and observes the...
- 144. The European Data Protection Supervisor was consulted in accordance...