• +48 786 088 383
  • 94-102 Lodz, Nowe Sady 4 lok.14

European Commission NIS2 Guidelines

The European Commission has published guidelines explaining how to apply Article 4 of NIS2—specifically, when NIS2 applies directly and when it is “superseded” by cybersecurity requirements from other sector-specific EU legislation. The document helps organizations and institutions understand the principles of equivalence of obligations (risk management and incident reporting) as well as the implications for supervision and enforcement.

1) What are these guidelines for and what do they cover

The guidelines explain the relationship between NIS2 and current and future EU sector-specific legal acts that introduce cybersecurity risk management measures or incident reporting obligations.

2) When NIS2 provisions “do not apply” (principle of equivalence)

If a sector-specific EU legal act requires entities to implement risk management measures or report incidents, and these requirements are at least equivalent “in terms of effect” to NIS2, then the relevant NIS2 provisions (including those on supervision and enforcement) do not apply to those entities.

3) What “equivalence” means for risk management

Sectoral requirements are considered equivalent if they are at least equivalent to the measures set out in Article 21(1) and (2) of NIS2 (they may also be more detailed).

4) Important principle: security measures apply to all operations, not just “critical systems”

The obligation to implement appropriate and proportionate measures (based on a risk analysis) applies to all of the entity’s operations and services, not just selected IT assets or individual critical services.

5) Scope of “security” and “systems” – CIA + hardware/software

The guidelines remind us that security encompasses resilience against incidents compromising availability, authenticity, integrity, and confidentiality, and that “networks and information systems” also include hardware, firmware, and software used in operations.

6) “All-hazards” approach – including physical and environmental risks

Risk management measures are intended to protect not only against cyberattacks, but also against events such as sabotage, theft, fire, flood, communication or power failure, and unauthorized physical access (as these can also lead to incidents).

7) How incident reporting works under NIS2 (stages and deadlines)

NIS2 provides for multi-stage reporting: an early warning within 24 hours, incident notification within 72 hours, and then a final report (as a rule) within one month—with the possibility of interim reports.

8) Effects of equivalence on supervision and enforcement + the DORA example

If sectoral requirements are equivalent, then not only do the NIS2 obligations regarding risk management/reporting not apply, but also the provisions on supervision and enforcement from Chapter VII of NIS2.

 

In addition, DORA, among others, is identified as the sector-specific legal act for financial entities—in this context, DORA “replaces” NIS2 with respect to the specified obligations.

READ THE FULL ACT

Our Adress

Nowe Sady 4 lok.14
94-102 Łódź

Call us

+48 786 088 383

Write to us

info@adq.com.pl
© 2026 ADQ Technologies | Wszystkie prawa zastrzeżone