NIS2 and CER Regulations – questions answered

Network and Information Systems Directive 2 (NIS2) Regulation and the Critical Entities Resilience (CER) Regulations

This page has details of the Network and Information Systems Directive 2 (NIS2) Regulation  and the Critical Entities Resilience (CER) Regulations

What is the Network and Information Systems Directive 2 (NIS2)  Regulation?

The NIS2 Directive (Directive (EU) 2022/2555) is the European Union’s cybersecurity legislation designed to achieve a high common level of security of network and information systems across the EU. It establishes cybersecurity risk management, governance, incident reporting, business continuity and supply chain security requirements for organisations operating in sectors that are important to society and the economy. The number of sectors of high criticality increases from 7 to 11 and the number of other critical sectors increases from 1 to 7.

Further details NIS2

Details are in the attached “NIS2 FAQ – NTA” covering responses to questions including:

  • Who are the National Competent Authorities (NCAs) under NIS2?
  • Who will be the competent authority for the NIS2 road transport subsector in Ireland?
  • What does the road transport subsector cover under NIS2?
  • Which organisations may need to assess whether they are in scope?
  • How will entities be classified “Essential” vs “Important”?
  • What role is the NTA expected to perform?
  • What is the NTA doing to prepare for its role as NCA?
  • Where can the legal instruments and official guidance be found?
  • When and how do road‑sector entities register?
  • What are the incident reporting expectations?
  • What sanctions does NIS2 provide for?
  • How does NIS2 interact with the CER Directive (critical entities)?
  • Which Member State supervises an organisation operating in more than one EU country?
  • How can a road entity check if it is in scope right now?
  • What’s the current status of NIS2 transposition in Ireland?
  • What should road‑sector organisations do now (practical steps)?

The document also includes:

  • NIS2 DIRECTIVE INFORMATION
  • NCSC (National Cyber Security Centre)
  • ENISA (European Union Agency for Cybersecurity) (historically European Network and Information Security Agency)

 

What are the Critical Entities Resilience (CER) Regulations?

The CER Regulations implement the CER Directive (EU) 2022/2557 in Ireland through the EU (Resilience of Critical Entities) Regulations 2024 (S.I. 559/2024). They establish a national framework to identify Critical Entities and require them to assess risks, prepare resilience plans and take measures to ensure the continuity of essential services.

CER FAQ

Details are in the attached CER FAQ – NTA  covering responses to:

  • Who are the Competent Authorities (CA) for CER in Ireland?
  • What are the NTA’s primary functions under CER?
  • Which “Essential Services” is the NTA the CA for under CER?
  • How will entities be classified Critical Entities by the NTA?
  • My organisation has been designated as a Critical Entity – what happens now?
  • What are the incident reporting requirements?
  • What are the possible fines and penalties?
  • Where can I find more information to support my actions as a Critical Entity?
  • How does CER interact with the NIS2 Directive?

Details and further links and connections are also contained on:

  • CER INFORMATION, LEGISLATION AND GUIDANCE

NIS2 FAQs - NTA

File type
PDF
File size
- 155 KB

CER FAQs - NTA

File type
PDF
File size
- 142 KB