Skip to main content
PolicySpeak
← All files

2020/0359(COD) · In Force

A high common level of cybersecurity

129 submissions from 115 organizations told the European Commission what they think about this file. Here is what each of them said, in their own words.

The Commission lists 373 submissions on this file. Shown here: the 129 from organizations. Not shown, by design: submissions from private individuals, which we never publish, and anything filed since our last weekly refresh.

Who showed up

106 submissions from industry — companies and their trade associations — against 8 from civil society: NGOs, consumer organizations, environmental groups and trade unions. That is 13.3 industry submissions for every one from civil society.

Industry 106Civil society 8Public authorities, academia, other 15

Groupings use the respondent type each organization selected when filing. Counting submissions, not organizations — a body that filed twice is counted twice.

What the room declares

65 of 115
in the EU Register
368
full-time lobbying staff
€68.6M+
declared costs a year
308
EP accreditations declared

Self-declared to the EU Transparency Register (snapshot 2 Sept 2026). The cost figure sums band floors, so the true total is higher.

The file, right now

The consultation closed on 21 Mar 2021 — it ran from 16 Dec 2020.

Policy area
Digital & tech (DG CNECT)
Where it stands
Awaiting adoption
Legislative stage
In Force
Commission reference
COM(2020)823

How it got here

  1. Impact assess incep13 Aug 2020
  2. Public consultation2 Oct 2020
  3. Prop dir21 Mar 2021

Showing 25 of 129 submissions.

A

APPLiA

· · filed 19 Mar 2021 · source

PDF

APPLiA appreciates the opportunity to provide this feedback. While a condensed version of our comments is below, please see the attached document for our full comments. APPLiA understands the need for comprehensive rules for a high level of cybersecurity within the European Union. APPLiA’s first concern lies in the fact that NIS2 is a Directive rather than a regulation.

LinkedInX
I

InfoNetworks

· · filed 18 Mar 2021 · source

PDF

InfoNetworks welcomes the opportunity to submit these comments in connection with the draft Network and Information Security 2.0 directive. Article 2 InfoNetworks agrees that top-level domain name registries are essential “digital infrastructure” entities.

LinkedInX
C

CrowdStrike

· · filed 18 Mar 2021 · source

PDF

Dear Sirs and Madams, Please find attached CrowdStrike's feedback to your Proposal for a Directive of the European Parliament and of the Council on measures for a high common level of cybersecurity across the Union, repealing Directive (EU) 2016/1148, as of 12/16/20 (COM(2020) 823 final). Sincerely Dr. [name removed]Strike

LinkedInX
CF

Coalition for Online Accountability ("COA")

· · filed 18 Mar 2021 · source

PDF

The Coalition for Online Accountability (“COA”) consists of seven leading copyright industry companies, trade associations and member organizations of copyright owners. COA's goal is to enhance and strengthen online transparency and accountability, with a particular focus on the domain name system ("DNS").

LinkedInX
HT

Huawei Technologies

· · filed 18 Mar 2021 · source

PDF

As a leading provider of computing and connectivity solutions for European companies, the security of ICT infrastructures and services of our consumers is the most important concern of Huawei operations in Europe.

LinkedInX
EE

Europol EC3 Advisory Group on Internet Security

· · filed 18 Mar 2021 · source

PDF

The Europol EC3 Advisory Group on Internet Security (EC3 AG IS) welcomes the opportunity to contribute its collective expertise in the realm of European and global cybersecurity to the proposed update to Directive (EU) 2016/1148 (NIS2). We provide the following feedback on a few key areas covered in the proposed text.

LinkedInX
CL

Com Laude Group

· · filed 18 Mar 2021 · source

We note that the proposed NIS2 Directive lays down cybersecurity risk management and reporting obligations for entities considered to be essential entities and important entities, and that whilst it is expressly not applicable to micro and small enterprises, there are no size qualifications for top level domain name registries (Article 2 (2)(a)(iii)).

LinkedInX
EI

ECPAT International

· · filed 18 Mar 2021 · source

PDF

I am making the attached submission on behalf of ECPAT International. This is a global NGO based in Bangkok, Thailand, with national chapters in over half of the EU's Member States. You will see that we address issues connected with the inaccuracy of WHOIS data. The high levels of inaccuracy represent a significant threat to the long term stability and security of the internet.

LinkedInX
S

Salesforce

· · filed 18 Mar 2021 · source

PDF

Salesforce.com (Salesforce) welcomes the European Commission’s initiative to enhance Europe’s resilience to cyber threats and respectfully submits the following comments on the Commission’s proposal for a revised Directive on Security of Network and Information Systems (NIS 2 Directive). Please see the attachment for further details.

LinkedInX
TA

The At-Large Advisory Committee within ICANN

· · filed 18 Mar 2021 · source

PDF

This comment is being submitted on behalf of the ICANN’s At-Large Advisory Committee (ALAC). The ALAC is responsible for representing the interests of individual Internet users within ICANN. As currently written, there are a number of gaps that will not allow NIS2, and particularly Article 23, to fulfill its intended function.

LinkedInX
IC

Internet Corporation for Assigned Names and Numbers

· · filed 18 Mar 2021 · source

PDF

ICANN org welcomes the opportunity to submit comments to the consultation on the Proposal for a Directive on Measures for a High Common Level of Cybersecurity Across the Union, repealing Directive (EU) 2016/1148 (NIS 2 Directive). Please find attached our contribution.

LinkedInX
ZG

ZVEI - German Electrical and Electronic Manufacturers’ Association

· · filed 18 Mar 2021 · source

PDF

The ‘ZVEI, the German Electrical and Electronic Manufacturers’ Association’ appreciates the opportunity to comment on the EU Commission’s proposal for a Directive on measures for a high common level of cybersecurity across the Union, repealing Directive (EU) 2016/1148.

LinkedInX

CLECAT, the European Association for Forwarding, Transport, Logistics and Customs Services, considers that it is of key importance to ensure the security of logistics supply chains at all times and supports measures in the field of cybersecurity which can assist companies to become more resilient against cyberthreats.

LinkedInX
VK

Verband kommunaler Unternehmen e.V.

· · filed 18 Mar 2021 · source

PDF

Dear Sir/Madam, the Federal Association of Municipal Leadership Associations (BV) and the Verband kommunaler Unternehmen e.V. (VKU) welcome the fact that the NIS 2 Directive is intended to raise cybersecurity standards throughout the European Union.

Filed in German · English published by the European Commission

LinkedInX
ES

Enel SpA

· · filed 18 Mar 2021 · source

PDF

Dear Members of European Commission, DG CNECT Unit H.2; Enel SpA, a multinational company in the energy sector highly appreciates the EC prompt revision of the Directive on the security of network and information systems (EU) 2016/1148. Please find the Enel Group feedback in the attachment.

LinkedInX
IP

Intellectual Property Constituency of ICANN

· · filed 18 Mar 2021 · source

PDF

The Intellectual Property Constituency (IPC) is one of the stakeholder groups and constituencies of the Generic Names Supporting Organisation (GNSO) of the Internet Corporation for Assigned Names and Numbers (ICANN).

LinkedInX
CL

Chanel Ltd

· · filed 18 Mar 2021 · source

As a right holder, we are the victim of scamming, phishing and cybersquatting. There are also thousands of stand-alone websites selling counterfeit products of our brand. As a result, we frequently need to know the identity of domain names registrants to be able to take appropriate, and rapid legal action. Identifying the registrants used to be relatively straightforward with the WHOIS database.

LinkedInX
E

ENGIE

· · filed 18 Mar 2021 · source

PDF

ENGIE welcomes the proposal for a directive on cybersecurity. We believe it is important to give the entities targeted by NIS2 the ability to define which essential services and activities need to be better protected and which are the most important computer systems and networks that support them.

LinkedInX
IW

ICT4Water Cluster - Cybersecurity Action Group

· · filed 18 Mar 2021 · source

PDF

The Cybersecurity Action Group of the ICT4Water cluster welcomes the revised NIS Directive and the efforts of the EC in developing common rules and policy tools with the aim of increasing cyber resilience in the European critical infrastructure.

LinkedInX
UF

Union Française de l'Electricité (UFE)

· · filed 18 Mar 2021 · source

PDF

A high level of cybersecurity across the EU can only be achieved through a systemic approach UFE supports the extension of the scope to more (sub)sectors. The introduction of a new distinction between essential and important entities with identical risk management and reporting obligations is a significant improvement.

LinkedInX
FO

Federation of Risk Management Associations (FERMA)

· · filed 18 Mar 2021 · source

PDF

The Federation of European Risk Management Associations (FERMA) is pleased to have the opportunity to provide the Commission with its comments on the proposal for NISD 2.0. Broadly speaking we see it as a step forward that could benefit with some clarification and additional guidance in some places.

LinkedInX
I

IBM

· · filed 18 Mar 2021 · source

PDF

In a time of turmoil, and with recent unprecedented cyber breaches such as Solarwinds, the EU’s revision of the NIS Directive certainly is a timely one. As a leading cybersecurity services provider, IBM believes the Revision should focus on increasing collaboration between government and industry and global industry-led initiatives, prioritise fixing a cyber breach over reporting it, positively incentivise companies…

LinkedInX
CO

Charter of Trust

· · filed 18 Mar 2021 · source

PDF

The Charter of Trust welcomes the European Commission’s intention to strengthen cybersecurity throughout the European Union and its Single Market. As the Commission acknowledged in its communication on the EU Security Union Strategy, member states and its citizens are facing an ever-changing security threat landscape, with increasing dependence on digitalisation and the complexity of interdependent global markets…

LinkedInX
TI

TECH IN France

· · filed 18 Mar 2021 · source

PDF

The acceleration of the digital transformation in industry has led to the introduction of new information systems or bricks on existing systems, leading to increased potential vulnerabilities and more exposure to cyber attacks from all types of malicious actors (states, cyber criminals, hackers, etc.).

Filed in French · English published by the European Commission

LinkedInX
SN

Syntec Numérique

· · filed 18 Mar 2021 · source

PDF

The acceleration of the digital transformation in industry has led to the introduction of new information systems or bricks on existing systems, leading to increased potential vulnerabilities and more exposure to cyber attacks from all types of malicious actors (states, cyber criminals, hackers, etc.).

Filed in French · English published by the European Commission

LinkedInX
Take the dataCSV — all 129 submissionsJSONFull text, not the excerpt. Free to cite.Search every submission →

Follow this file

Get an email when a new organization files a position here: one email on Tuesdays, only when there is something new. Free.

We use your email for updates on this file, and PolicySpeak may contact you about the product. Unsubscribe in one click. Privacy policy.

Method. Every quote is verbatim from the organization’s own submission to the European Commission, trimmed to its opening passage and never summarized by a model. Where a submission was filed in another EU language we show the English text the European Commission publishes alongside it, labeled on the quote; the original is one click away at the source. Groupings use the respondent type the organization itself selected when filing. We deliberately do not label anyone “supportive” or “opposed” — you read what they wrote and draw your own conclusion. Organizations only, never individuals. Reused under Commission Decision 2011/833/EU; the European Commission is not liable for this reuse.