APPLiA appreciates the opportunity to provide this feedback. While a condensed version of our comments is below, please see the attached document for our full comments. APPLiA understands the need for comprehensive rules for a high level of cybersecurity within the European Union. APPLiA’s first concern lies in the fact that NIS2 is a Directive rather than a regulation.
2020/0359(COD) · In Force
A high common level of cybersecurity
129 submissions from 115 organizations told the European Commission what they think about this file. Here is what each of them said, in their own words.
The Commission lists 373 submissions on this file. Shown here: the 129 from organizations. Not shown, by design: submissions from private individuals, which we never publish, and anything filed since our last weekly refresh.
Who showed up
106 submissions from industry — companies and their trade associations — against 8 from civil society: NGOs, consumer organizations, environmental groups and trade unions. That is 13.3 industry submissions for every one from civil society.
Groupings use the respondent type each organization selected when filing. Counting submissions, not organizations — a body that filed twice is counted twice.
What the room declares
- 65 of 115
- in the EU Register
- 368
- full-time lobbying staff
- €68.6M+
- declared costs a year
- 308
- EP accreditations declared
Self-declared to the EU Transparency Register (snapshot 2 Sept 2026). The cost figure sums band floors, so the true total is higher.
The file, right now
The consultation closed on 21 Mar 2021 — it ran from 16 Dec 2020.
- Policy area
- Digital & tech (DG CNECT)
- Where it stands
- Awaiting adoption
- Legislative stage
- In Force
- Procedure
- 2020/0359(COD)
- Commission reference
- COM(2020)823
How it got here
- Impact assess incep13 Aug 2020
- Public consultation2 Oct 2020
- Prop dir21 Mar 2021
Showing 25 of 129 submissions.
InfoNetworks welcomes the opportunity to submit these comments in connection with the draft Network and Information Security 2.0 directive. Article 2 InfoNetworks agrees that top-level domain name registries are essential “digital infrastructure” entities.
Dear Sirs and Madams, Please find attached CrowdStrike's feedback to your Proposal for a Directive of the European Parliament and of the Council on measures for a high common level of cybersecurity across the Union, repealing Directive (EU) 2016/1148, as of 12/16/20 (COM(2020) 823 final). Sincerely Dr. [name removed]Strike
The Coalition for Online Accountability (“COA”) consists of seven leading copyright industry companies, trade associations and member organizations of copyright owners. COA's goal is to enhance and strengthen online transparency and accountability, with a particular focus on the domain name system ("DNS").
As a leading provider of computing and connectivity solutions for European companies, the security of ICT infrastructures and services of our consumers is the most important concern of Huawei operations in Europe.
The Europol EC3 Advisory Group on Internet Security (EC3 AG IS) welcomes the opportunity to contribute its collective expertise in the realm of European and global cybersecurity to the proposed update to Directive (EU) 2016/1148 (NIS2). We provide the following feedback on a few key areas covered in the proposed text.
Com Laude Group
· · filed 18 Mar 2021 · source
We note that the proposed NIS2 Directive lays down cybersecurity risk management and reporting obligations for entities considered to be essential entities and important entities, and that whilst it is expressly not applicable to micro and small enterprises, there are no size qualifications for top level domain name registries (Article 2 (2)(a)(iii)).
I am making the attached submission on behalf of ECPAT International. This is a global NGO based in Bangkok, Thailand, with national chapters in over half of the EU's Member States. You will see that we address issues connected with the inaccuracy of WHOIS data. The high levels of inaccuracy represent a significant threat to the long term stability and security of the internet.
Salesforce.com (Salesforce) welcomes the European Commission’s initiative to enhance Europe’s resilience to cyber threats and respectfully submits the following comments on the Commission’s proposal for a revised Directive on Security of Network and Information Systems (NIS 2 Directive). Please see the attachment for further details.
This comment is being submitted on behalf of the ICANN’s At-Large Advisory Committee (ALAC). The ALAC is responsible for representing the interests of individual Internet users within ICANN. As currently written, there are a number of gaps that will not allow NIS2, and particularly Article 23, to fulfill its intended function.
ICANN org welcomes the opportunity to submit comments to the consultation on the Proposal for a Directive on Measures for a High Common Level of Cybersecurity Across the Union, repealing Directive (EU) 2016/1148 (NIS 2 Directive). Please find attached our contribution.
ZVEI - German Electrical and Electronic Manufacturers’ Association
· · filed 18 Mar 2021 · source
The ‘ZVEI, the German Electrical and Electronic Manufacturers’ Association’ appreciates the opportunity to comment on the EU Commission’s proposal for a Directive on measures for a high common level of cybersecurity across the Union, repealing Directive (EU) 2016/1148.
CLECAT - European association for forwarding, transport, logistic and Customs services
· · filed 18 Mar 2021 · source
CLECAT, the European Association for Forwarding, Transport, Logistics and Customs Services, considers that it is of key importance to ensure the security of logistics supply chains at all times and supports measures in the field of cybersecurity which can assist companies to become more resilient against cyberthreats.
Dear Sir/Madam, the Federal Association of Municipal Leadership Associations (BV) and the Verband kommunaler Unternehmen e.V. (VKU) welcome the fact that the NIS 2 Directive is intended to raise cybersecurity standards throughout the European Union.
Filed in German · English published by the European Commission
Dear Members of European Commission, DG CNECT Unit H.2; Enel SpA, a multinational company in the energy sector highly appreciates the EC prompt revision of the Directive on the security of network and information systems (EU) 2016/1148. Please find the Enel Group feedback in the attachment.
The Intellectual Property Constituency (IPC) is one of the stakeholder groups and constituencies of the Generic Names Supporting Organisation (GNSO) of the Internet Corporation for Assigned Names and Numbers (ICANN).
Chanel Ltd
· · filed 18 Mar 2021 · source
As a right holder, we are the victim of scamming, phishing and cybersquatting. There are also thousands of stand-alone websites selling counterfeit products of our brand. As a result, we frequently need to know the identity of domain names registrants to be able to take appropriate, and rapid legal action. Identifying the registrants used to be relatively straightforward with the WHOIS database.
ENGIE welcomes the proposal for a directive on cybersecurity. We believe it is important to give the entities targeted by NIS2 the ability to define which essential services and activities need to be better protected and which are the most important computer systems and networks that support them.
The Cybersecurity Action Group of the ICT4Water cluster welcomes the revised NIS Directive and the efforts of the EC in developing common rules and policy tools with the aim of increasing cyber resilience in the European critical infrastructure.
A high level of cybersecurity across the EU can only be achieved through a systemic approach UFE supports the extension of the scope to more (sub)sectors. The introduction of a new distinction between essential and important entities with identical risk management and reporting obligations is a significant improvement.
The Federation of European Risk Management Associations (FERMA) is pleased to have the opportunity to provide the Commission with its comments on the proposal for NISD 2.0. Broadly speaking we see it as a step forward that could benefit with some clarification and additional guidance in some places.
In a time of turmoil, and with recent unprecedented cyber breaches such as Solarwinds, the EU’s revision of the NIS Directive certainly is a timely one. As a leading cybersecurity services provider, IBM believes the Revision should focus on increasing collaboration between government and industry and global industry-led initiatives, prioritise fixing a cyber breach over reporting it, positively incentivise companies…
The Charter of Trust welcomes the European Commission’s intention to strengthen cybersecurity throughout the European Union and its Single Market. As the Commission acknowledged in its communication on the EU Security Union Strategy, member states and its citizens are facing an ever-changing security threat landscape, with increasing dependence on digitalisation and the complexity of interdependent global markets…
The acceleration of the digital transformation in industry has led to the introduction of new information systems or bricks on existing systems, leading to increased potential vulnerabilities and more exposure to cyber attacks from all types of malicious actors (states, cyber criminals, hackers, etc.).
Filed in French · English published by the European Commission
The acceleration of the digital transformation in industry has led to the introduction of new information systems or bricks on existing systems, leading to increased potential vulnerabilities and more exposure to cyber attacks from all types of malicious actors (states, cyber criminals, hackers, etc.).
Filed in French · English published by the European Commission
The review of the Directive on Security of Network and Information Systems (NIS2) is an essential step towards a more resilient Europe, ensuring state-of-the-art risk management of current and emerging cyber threats to vital sectors of the EU economy and society.
VNO-NCW and MKB-Nederland support the efforts of the European Commission to increase cyber resilience. We believe that cybersecurity requires European coordination and alignment, given the strong interdependencies. The rapidly increasing threats posed by digitization justify this revision of the NIS directive. We regard the proposals on more European cooperation and information exchange as positive.
CISPE is a non-profit association that focuses on developing greater understanding and promoting the use of cloud infrastructure services in Europe. Security and data protection are cornerstones of the CISPE constitution.
Japan Business Council in Europe (JBCE) welcomes the opportunity to provide our feedback on the proposal for the Revised Directive on Security of Network and Information Systems (NIS2). The proposal is very important and timely as it supports the Commission’s efforts to address new challenges in the cybersecurity threat landscape in Europe.
UNIFAB - Union des Fabricants is the French association for the promotion and defense of intellectual property rights. It represents business from all economic sectors, and provides them with an association umbrella for promoting intellectual property and fighting against counterfeiting.
Companies themselves have a vital interest in the security of the data, applications, systems and infrastructures. Accordingly, the obligations which it is intended to introduce for companies should take greater account of the principle of appropriateness. The planned additional obligations are intended to apply to a group of companies that goes far beyond the current one.
Business & Science Poland welcomes and appreciates the European Commission’s efforts in strengthening the European cybersecurity system. We see an urgent need for the improvement of cyber threats awareness and the technical adaptation to current digital threats and challenges. In our opinion, the risk-based management approach suggested by the Commission in the NIS 2 proposal is a proper direction.
SGI Europe generally welcomes the opportunity to provide feedback to the recently adopted Directive on security of network and information systems (NIS 2 Directive) by the European Commission that introduces in our point of view significant and problematic changes compared with the first version of the Directive.
COCIR welcomes the opportunity to provide feedback to the European Commission’s proposal for a Directive on measures for a high common level of cybersecurity (hereafter the NIS 2 Directive proposal). COCIR appreciates that the NIS 2 Directive approval builds upon the strengths of the original framework and introduces additional measures to enhance the cybersecurity capacity and capabilities of Member States.
DIGITAL SME generally welcomes the clarifications and revisions that have been made to the Directive. As noted in our previous response to the open consultation, DIGITAL SME was in favour of the efforts to strengthen the harmonisation of the Digital Single Market but remained wary of the negative impact that varying implementations between Member States could have on the level playing field and spread of…
Established on the 24th September 2007, the French Telecoms Federation (Fédération Française des Télécoms, hereinafter “the FFTélécoms”) represents the electronic communications operators in France. Its missions are to promote an innovative and responsible industry with respect to society, the environment, people and businesses, to protect the economic interests of the sector and to promote the image of its members…
The European Internet Services Providers Association (EuroISPA) is the world's largest association of Internet Services Providers (ISPs), representing over 2,000 ISPs across the EU and EFTA countries. EuroISPA is recognised as the voice of the EU ISP industry, reflecting the views of ISPs of all sizes from across its member base. You will find our contribution attached.
The speed in which society is digitised and experience from the existing NIS Directive justify the new proposal as part of the EU's efforts to create the necessary cybersecurity in the Union. At the same time, numerous examples of the harm that hacker attacks and cybercrime can inflict on our society continue to be seen.
EDF welcomes the European Commission proposal for a revised Directive on Security of Network and Information Systems (NIS 2 Directive) that will improve the EU’s overall cybersecurity, including in a strategic sector such as energy.
DENIC eG, founded in 1996, is the DNS registry for .de, Germany’s country code top level domain (ccTLD). DENIC operates most of the DNS name servers for .de and provides name service for other TLDs, within and outside the European Union. DENIC welcomes the Commission’s proposal for an enhanced NIS Directive to support the common goal of strengthening and enhancing cybersecurity across the EU.
The French insurance sector welcomes the European Commission’s willingness to strengthen the level of cybersecurity across the Union as it has been identified by our industry as a major challenge. A clarification of the interaction between NIS2 and DORA is however needed to allow for a harmonised framework across Europe.
As a matter of fact cyber threats have increased manifold since the adoption of the first NIS Directive. That's why we see the imperative need for a more harmonised and future-proofed European cybersecurity framework. The proposal already strikes a reasonable balance between targeted regulatory interventions and strengthening the EU's cyber-resilience holistically.
GRTgaz is fully committed to the Paris Agreement and as a leading gas infrastructure operator, we are ready to assume our responsibility and put our infrastructure to good use in service of the energy and ecological transition. The objective of climate neutrality goes hand in hand with the need for a digital transformation of the energy sector.
currENT is an industry association that represents the voice of Europe’s innovative grid technology companies. currENT welcomes the Commission´s initiative to review the existing Network and Information Security (NIS) Directive. Safe and reliable electric service has long been understood to be a fundamental underpinning of modern society.
Arthur Strategies & Systems is part of Arthur’s Legal. It has handpicked experienced interdisciplinary experts to focus on ability to navigate, enable, facilitate as well as execute and systemize. Our core team consists of attorneys at law, senior legal counsels, governmental advisors, strategists, innovation, policy & standardisation experts, community & competence builders, technologists, all well-connected in the…
Dear Madam or Sir, We are pleased to share ITI's views on the proposal for a revision of the NIS Directive. Please find our detailed comments in the submission attached. Kind regards, [name removed] on behalf of ITI, the Information Technology Industry Council
We welcome the NIS 2 Directive proposal as an improvement over the current NIS Directive. Relevant sectoral guidance could promote further harmonisation and clarity on how to act when cyberincidents are putting healthcare and patient safety at risk.
European Data Centre Association (EUDCA) represents the European data centre (DC) operator community. EUDCA is happy to submit feedback on the revision of EU rules on the security of network and information systems and wants to draw attention to three main remarks that it identified concerning the NIS2 Directive proposal which are the following: 1) Inconsistencies in the implementation of the Directive in Member…
RIPE Cooperation Working Group Co-Chairs
· · filed 18 Mar 2021 · source
Response to the NIS 2 Directive from the RIPE Cooperation Working Group Co-Chairs ************** RIPE is an open community that has played an important role, through technical coordination, in developing the Internet in the EU since 1989.
Netnod have in the attached PDF comments on the proposed directive. A summary: Regarding CSIRTs Netnod believe it is not only the reporting to a CSIRT that is important, but also what a CSIRT produces with the help of that information. The directive because of this should include requirements for CSIRTs to produce good reports. Regarding the domain name system (DNS) the definitions must be much more clear.
Messaging, Malware and Mobile Anti-Abuse Working Group ( M3AAWG )
· · filed 18 Mar 2021 · source
M3AAWG, the Messaging, Malware and Mobile Anti-Abuse Working Group supports the additions and updates as reflected in the NIS2 draft and notes that many of the new and updated concepts included are key to M3AAWG members who require access to registration data in order to detect threats, investigate new attack vectors and to understand trends aimed at protecting users and the Internet as a whole.
MEDEF welcomes this European cybersecurity strategy because it seems today, more than ever, necessary to strengthen the level of cybersecurity of the entire European ecosystem, be it companies, but also and above all States and public authorities.
Internet Systems Consortium, Inc, (ISC) is grateful for the opportunity to comment on the NIS2 proposal. We make this submission for one purpose only: to comment on the potential impact of NIS2 on the operation of DNS root name servers. ISC is one of the world’s 12 globally recognized operators of authoritative Internet DNS root name servers.
Dear Sir or Madam, We highly appreciate the opportunity to provide input to the review of the EU rules on the security of network and information systems. Please find enclosed our position paper on the following topics: (A) Classification of small and non-complex credit institutions as important entities according to Annex 2 (B) Reference to DORA in order to increase legal certainty (C) Clarification on the…
Facebook Ireland Limited (“Facebook”) is pleased to submit these comments in response to the European Commission’s public consultation on the Network and Information Systems Directive review (referred to in the attached document as the “Proposal” and/or “NISD2”). Facebook’s mission is to give people the power to build community and bring the world closer together.
Vodafone welcomes the European Commission’s attempt to achieve a higher level of harmonisation and consistency with other legal instruments in its revised Directive on Security of Network and Information Systems (NIS2). Full feedback in the accompanying attachment.
WindEurope welcomes the initiative to update the NIS Directive to address evolving security needs, and the opportunity to review and provide feedback to the European Commission's current proposal. We want to raise your attention to the following points about the scope and the measures targeted for operators and technology vendors of distributed renewable energy assets: Detailed guidance at EU level about the type of…
The Estonian Information Technology and Telecommunications Association (ITL), representing Estonian ICT companies and organisations, makes the following comments and views on the new proposal for a Directive on the security of network and information systems (NIS 2) of the European Commission: 1) Scope. Article 2(1) and (2) of the NIS 2 Directive provides for entities falling within the scope of the Directive.
Filed in Estonian · English published by the European Commission
Enedis welcomes the ambitious work of the European Commission in the recast of NIS Directive. The new perimeter widens its scope of application to new sectors and to new and numerous entities among them. It will have a critical impact and could imply negative effects (positioning and processing capabilities of national competent authorities, lack of cyber-skilled workers, levelling down requirements applying to…
The Danish Rights Alliance is pleased to refer to the submissions by the Coalition for Online Accountability as attached. We will further recall the Danish model as Denmark has determined that the public interest in accessible WHOIS data for its .dk ccTLD merits that such information be publicly available, even when the registrant is a natural person.
The members of UP KRITIS (Public Private Partnership of the German Critical Infrastructure Managers) welcomed the revision of the NIS Directive 2.0. With a view to increasing network and information security in the European internal market in an effective and cost-effective manner, we would like to draw attention to the following possible improvements to the Commission’s legislative proposal of 16.12.2020 and ask it…
Filed in German · English published by the European Commission
AIM, the European Brands Association, thanks the Commission for the specific inclusion of domain name registration data in this draft Directive. We fully agree with Recital 59, that “maintaining accurate and complete databases of domain names and registration data (so called ‘WHOIS data’) and providing lawful access to such data is essential to ensure the security, stability and resilience of the DNS, which in turn…
JPRS Feedback on the European Commission’s Proposed NIS 2 Directive Japan Registry Services Co., Ltd. (JPRS) is a ccTLD manager of .JP, one of the operators of Root DNS services, and also a provider of other Internet-related services.
As an organisation tasked with operating one of the world’s 13 global DNS root servers (K-root), the RIPE NCC appreciates the opportunity to share its views on the proposed text of the European Commission’s NIS 2 Directive and to express some concerns about how we understand the proposed legislation would affect global domain name system (DNS) operations.
Aktionskreis gegen Produkt- und Markenpiraterie e.V.
· · filed 18 Mar 2021 · source
The Anti-Counterfeiting Trade Association (APM) has been working for more than 20 years as a cross-industry association for the protection of intellectual property. Founded as a joint initiative of the Chamber of Commerce and Industry (DIHK), the Bundesverband der Deutschen Industrie (BDI) and the Trade Mark Association, a large number of well-known companies from different sectors are involved in the APM in an…
Filed in German · English published by the European Commission
From ANDEMA, we celebrate the proposal for a NIS 2.0 Directive that includes a new strategy on cybersecurity with the aim of provide legal measures to boost the overall level of cybersecurity in the Union. The Article 23 about databases of domain names and registration data is fit for purpose. We fundamentally agree with the question of data accuracy. This is essential.
Comments on the Implementation of Article 23 Verisign commends the European Commission for recognizing that the security, stability and resiliency of the DNS contributes to high overall levels of cybersecurity, not only within the European Union but globally.
The International Trademark Association (INTA) is pleased to provide the following comments and suggestions to the Proposal for a Directive of the European Parliament and the Council on measures for a high common level of cybersecurity across the Union, repealing Directive (EU) 2016/1148 or (hereafter “NIS2 Directive”).
INDICAM - the Italian Association for the protection of Intellectual Property
· · filed 17 Mar 2021 · source
We appreciate the effort made by the Commission in recognizing the importance of improving the current domain name system to effectively fight online illegal activities. It is crucial to acknowledge that GDPR provisions are not in conflict with the necessity to protect users’ safety and were never intended to shield criminal actors.
Open-Xchange would like to thank for the opportunity to provide comments on the Commission’s proposal for a new directive enhancing cybersecurity measures, replacing the previous NIS directive. Given our field of expertise and market experience, we will be focusing our comments on the following topics: A. Cybersecurity requirements for email, including end-to-end encryption; B.
AMETIC endorses the European Commission's priority and legal approach to cybersecurity. Highlight the relevance of preserving the one-stop-shop incident reporting and supervision mechanism for all cross-border service providers, thus supporting the internal market, and strengthening the European economy. If a company is being monitored by one law, it should not report to others, except in the case of the GDPR.
DIN, the German national standardization body, welcomes and supports the proposal for an update of the directive on measures for a high common level of cybersecurity across the Union (NIS2 Directive) that seeks to improve resilience and incident response capacities of public and private entities as well as competent authorities.
This response is provided on behalf of ICANN’s Business Constituency (BC), which is the voice of commercial Internet users within ICANN, and represents the interests of small, medium, large and multinational enterprises as users of the domain name system (DNS). Thank you for the opportunity to provide detailed feedback on the draft Revised Directive on Security of Network and Information Systems (NIS2).
CLEPA – European Association of Automotive Suppliers and ACEA – European Automobile Manufacturers Association welcome the opportunity to provide feedback on the Commission’s proposal for a Directive on high common level of cybersecurity across the Union (NIS 2 Directive). The proposal is timely and an important initiative to address the emerging threats to the European Digital Single Market.
CSC - IT Center for Science
· · filed 17 Mar 2021 · source
CSC welcomes the Commission’s proposal and especially its ambition to further harmonise the level of cybersecurity across the EU by expanding the scope of the Directive, spelling out many of its requirements in more detail and equipping the Member States with more stringent supervision and enforcement powers.
BSA | The Software Alliance (BSA) welcomes the opportunity to comment on the Commission’s revised Directive on security of network and information systems (herewith “NIS 2.0 Directive”). BSA is the leading advocate for the global software industry.
In two centuries, technology has changed the nature of what it takes to defend a nation. A comprehensive and multistakeholder approach through renewed strategies, legislation, global cooperation, and shared values is needed to improve the security posture of organizations across the European ecosystem and further strengthen the EU’s role as a leader on cybersecurity.
City of Stockholm
· · filed 17 Mar 2021 · source
The City of Stockholm urges the Commission to: - broaden the definition of “information security” to include a reference to the performance of "conducting systematic and risk-based safety work" - create precondition for secure incident reporting, making sure that sensitive information is duly protected - include a classification scale to help local actors identify which parts of an organisation should be considered…
Community of European Railway and Infrastructure Companies (CER aisbl)
· · filed 17 Mar 2021 · source
The Community of European Railway and Infrastructure Companies (CER aisbl) supports the overall intention of the proposed NIS-2 Directive. In our opinion it is fully justified that the EU and the entities in the critical sectors pay more attention to and harmonise the efforts for cyber security.
ECCIA welcomes the Commission’s proposal for the NIS2 Directive, which will enhance the EU citizens’ security in the digital environment. Maintaining the accuracy and accessibility of domain name registration data for the upholding and preservation of a reliable, resilient and secure domain name system, is particularly important in this context in order to allow consumers, rights owners and Member States to enforce…
ACEA and CLEPA welcome the opportunity to provide feedback on the Commission’s proposal for a Directive on high common level of cybersecurity across the Union (NIS 2 Directive). The proposal is timely and an important initiative to address the emerging threats to the European Digital Single Market.
Cetome is an independent cyber security advisory specialised in the NIS Directive. Cetome has developed and delivered training courses to regulators and operators of essential services. Cetome has also provided several assessment and driven improvement plans for operators of essential services in Europe.
Please find attached the feedback of ACT | The App Association (Transparency Reg. # 72029513877-54) to the European Commission’s Directorate-General for Communications Networks, Content and Technology on its proposal for a directive on measures for a high common level of cybersecurity across the Union, repealing Directive (EU) 2016/1148. Anna Bosch Policy Associate ACT | The App Association (Transparency Reg.
The Comité Colbert welcomes the Commission’s proposal for the NIS2 Directive, which will enhance the EU citizens’ security in the digital environment. Article 23 which addresses the importance of maintaining the accuracy and accessibility of domain name registration data for the upholding and preservation of a reliable, resilient and secure domain name system, is particularly important in this context in order to…
The Swedish Post and Telecom Authority (PTS) would like to give feedback on the NIS 2 proposal with two attached memorandums. The first (1) memorandum contains the initial positions of PTS regarding trust services being included in the NIS 2 framework, and so has a specific eIDAS focus.
The Swedish Post and Telecom Authority (PTS) would like to give feedback on the NIS 2 proposal with two attached memorandums. The first (1) memorandum contains the initial positions of PTS regarding trust services being included in the NIS 2 framework, and so has a specific eIDAS focus.
VDMA, the German Mechanical Engineering Association, appreciates the opportunity to comment on the legislative proposal for a directive on measures for a high common level of cybersecurity across the Union. As producers of connected and digitized machines and industrial equipment, our sector is one of the drivers of Industrie 4.0.
European Railway Infrastructure Managers (E.I.M.)
· · filed 16 Mar 2021 · source
EIM welcomes the Commission’s initiative to review the NIS Directive and takes into consideration the several policy options identified in the roadmap. Furthermore, EIM supports the policy option 3, which consists in introducing targeted changes to the current NIS in order to clarify certain provisions and improving harmonisation of the current rules to contribute to create the relevant unique framework, taking into…
Federation of German Industries / Bundesverband der Deutschen Industrie e.V.
· · filed 16 Mar 2021 · source
German industry welcomes the European Commission’s aim to significantly strengthen Europe's cyber-resilience and to create a level playing field for essential and important entities across the European Union. Cyber and IT security are the basis for a long-term secure digital transformation of the state, economy and society.
UNIFE - The European Rail Supply Industry
· · filed 8 Mar 2021 · source
UNIFE – the association of the European rail manufacturing industry – acknowledges that a revision of the ‘’Network and Information Security’’ Directive (‘’NIS’’) is nowadays necessary to make it fitter vis-à-vis current cyber-risks. Unprecedented pace in digitalisation, including a huge rise in the use of IoT devices, has substantially increased cyber security risks.
Kaspersky welcomes the Commission’s new proposal (further – proposal) on measures for a high common level of cybersecurity across the Union, which revises Directive 2016/1148 on the security of network and information systems (NIS Directive).
About eco With more than 1.100 member companies, eco is the largest association of the internet economy in Europe. Since 1995, eco has been shaping the Internet, promoting new technologies, creating framework conditions and representing the interests of its members vis-à-vis politics and in international fora.
Filed in German · English published by the European Commission
The draft NIS2 directive, aiming to improve the cybersecurity posture and risk management of organisations that provide essential and important services to the economy and society, includes in its definition of ‘essential’ entities of the Digital infrastructure all entities that run a domain-name system (DNS) service, of any kind and of any size.
BSA | The Software Alliance
· · filed 13 Aug 2020 · source
BSA | The Software Alliance (BSA) welcomes the opportunity to provide input to the Commission’s evaluation roadmap/ Inception Impact Assessment on the NIS Directive. BSA is the leading advocate for the global software industry. Our members are at the forefront of software-enabled innovation that is fueling global economic growth by helping enterprises in every sector of the economy operate more efficiently.
As the voice of digitally transforming industries in Europe, DIGITALEUROPE appreciates the opportunity to provide feedback on the European Commission’s roadmap consultation on the review of EU rules on the security of network and information systems.
SNCF welcomes the Commission’s initiative to review the Network and Information Security (NIS) Directive and takes note of the several policy options identified in the roadmap. SNCF supports the policy option 3, which consist in introducing targeted changes to the current NIS Directive with a view to clarifying certain provisions and improving harmonisation of the current rules.
The NIS Directive has been instrumental in increasing the cyber-resilience of the EU. As the first piece of legislation concerning EU-wide cybersecurity, the NIS Directive is the acknowledgment that incidents in one Member State can have significant cross-border impacts, hence requiring a common level of cybersecurity throughout the EU.
CCIA represents a wide range of suppliers and users of Digital Services and Essential Services, and we welcome the opportunity to contribute to the review of the Network and Information Security (NIS) Directive.
Huawei welcomes the Commission's approach to review the Directive on Security of Network and Information Systems (NIS). We take into account that now is a timely opportunity to review the NIS Directive with consideration for state-of-the-art technology and cybersecurity, industry and regulatory changes. The coronavirus pandemic has driven more individuals and businesses online to live and work digitally.
The Information Technology Industry Council (ITI) appreciates the opportunity to submit the attached comments to the European Commission on the NIS Directive combined evaluation roadmap/inception impact assessment. ITI is the global association of the tech industry.
Hangzhou Hikvision Digital Technology Co.
· · filed 13 Aug 2020 · source
Hangzhou Hikvision Digital Technology Co., Ltd is a leading provider of innovative security products in the EU, ranging from public security to smart home security solutions. We welcome the opportunity to respond to the European Commission’s public consultation on the revision of the EU’s Network and Information Systems (NIS) Directive. Hikvision takes cybersecurity and privacy very seriously.
UNIFE – the association of the European rail supply industry – welcomes the Commission’s initiative to review the Network and Information Security (NIS) Directive, in the framework of the ‘’Shaping Europe’s digital future’’ masterplan. The NIS Directive in 2016 marked one of the most important steps towards a more coherent and harmonised cybersecurity management in Europe.
DSNA French Air Navigation Service Provider
· · filed 13 Aug 2020 · source
The extension of the NIS Directive in scope (increase the number of essential operators) or sectors (inclusion of new sector of activity) would increase the problems already experienced: economic burden (esp. for small businesses), incomplete coverage of ecosystem in same sector, non-level playing field due to differences in Member States implementation, non-coordinated protection European wide… In our view, the NIS…
Bitkom e.V. (Federal Association for Information Technology, Telecommunications and New Media)
· · filed 13 Aug 2020 · source
Bitkom strongly welcomes the integration of relevant stakeholder opinions in order to streamline public and private efforts striving for an improved cybersecurity throughout the European Union (EU). That is why we would like to seize the opportunity and provide our feedback already at an early stage of the revision of the Directive (EU) 2016/1148 concerning measures for implementing an equivalent and commonly high…
The Federation of Finnish Enterprises
· · filed 13 Aug 2020 · source
The review of the Directive on Security of Network and Information Systems (the NIS Directive), passed in 2016, is in our mind welcome, given the rapid pace of the digital transition which keeps increasing the amount of cyber threats in essential sectors of the European societies and economies.
COCIR welcomes the opportunity to provide feedback to the combined roadmap and inception impact assessment on the revision of the Directive on Security of Network and Information Systems (NIS Directive) as published by the European Commission. Please refer to attached document for COCIR's response.
About eco: Eco is the largest association of internet industries in Europe, with over 1 100 member companies. Since 1995 eco has been instrumental in shaping the internet, promoting new technologies, creating framework conditions and representing the interests of its members vis-à-vis politics and in international fora.
Filed in German · English published by the European Commission
European Data Centre Association (EUDCA)
· · filed 11 Aug 2020 · source
The European Data Centre Association (EUDCA) represents the European data centre operator community. The EUDCA is happy to submit feedback on the the revison of the Network and Information Security Directive (NIS Directive) and wants to draw attention to the following key points: • There is embedded ambiguity in the directive in that it addresses Network & Information Services for Operators of Essential Services…
Liberty Global
· · filed 11 Aug 2020 · source
Liberty Global welcomes the opportunity to comment on the European Commission (Commission)’s roadmap for the review of the Union’s rules on the security of network and information systems (the roadmap). This is a valuable step towards a comprehensive evaluation of the NIS Directive.
The NIS Directive has helped establish a stronger common level of cybersecurity in the EU, and additional steps can be taken to further harmonize this effort, along with improving interoperability within and across the EU and among major global markets.
European Telecommunications Network Operators' Association (ETNO)
· · filed 11 Aug 2020 · source
ETNO Comments on the European Commission’s Inception Impact Assessment on the Review of the NIS Directive July 2020 ETNO welcomes the European Commission’s (EC) initiative to review the Network and Information Systems (NIS) Directive in light of current technological, market and regulatory developments. Ensuring an effective pan-European instrument for the security of network and information systems is paramount.
Federation of Craft Businesses in the automotive sector and in mobility services (FNA)
· · filed 11 Aug 2020 · source
Federation of Craft Businesses in the automotive sector and in mobility services (FNA) would like to thank the authors of the Evaluation Roadmap on Directive (EU) 2016/1148 concerning measures for a high common level of security of network and information systems across the Union (the NIS Directive).
FIGIEFA, the European Federation of Automotive Aftermarket Distributors, is part of Europe’s substantial automotive aftermarket and mobility value chain, accounting for over 4,5 million jobs in the wider ‘automobile use’, most of them being employed in over 500.000 SMEs.
European Banking Federation
· · filed 10 Aug 2020 · source
The European Banking Federation (EBF) shares the European Commission’s opinion that the different approaches of Member States in implementing the NIS Directive have led to significant inconsistencies and fragmentation in the regulatory landscape, which are in turn undermining the level playing field for some operators and leading to further fragmentation of the Single Market.
Federation of German Industries / Bundesverband der Deutschen Industrie e.V.
· · filed 10 Aug 2020 · source
German industry welcomes the European Commission’s aim to significantly strengthen Europe's cyber-resilience and to create a level playing field for operators of essential services (OES) across the European Union. Cyber and IT security are the basis for a long-term secure digital transformation of the state, economy and society.
SANET - Slovak Academic Network Association, highly welcomes EC initiative to revise the NIS directive. Its transposition in member states lead to significantly different and sometimes even confusing results, which definitely needs to be addressed shortly.
Dear Members of DG CNECT H2, Enel SpA, a multinational company in the energy sector highly appreciates the EC initiative to review the Directive (EU) 2016/1148. The first suggestion to revise the future legislation relates to the provisions allowing Member States to define essential services and identify operators of essential services in their territories.
ChargeUp Europe
· · filed 5 Aug 2020 · source
ChargeUp Europe welcomes the European Commission’s initiative to review the EU rules on the security of network and information systems. ChargeUp Europe is the voice of the electric vehicle (EV) charging infrastructure industry and has been formed accelerate the switch to zero-emission mobility and ensure a seamless driver experience with access to high quality, readily available charging infrastructure across…
DEKRA e.V.
· · filed 3 Aug 2020 · source
ELEMENTS TO BE INCORPORATED IN A REVISED NIS DIRECTIVE DEKRA recommends incorporating three major elements when revising the NIS Directive. Please find them outlined in the following: 1. UNIFICATION OF EVALUATION METHODOLOGIES, LIMITATION OF GRANULARITY Under the flexibility of the current NIS Directive, each country has identified various operators of essential services (OES) by use of different criteria.
EurEau - European Federation of Water Services
· · filed 3 Aug 2020 · source
EurEau welcomes the review of the NIS Directive and appreciates the possibility to input the process though the feedback to the Roadmap. Since the NIS Directive transposition period ended in May 2018, EurEau members think it is challenging to assess the provisions and how they have worked in practice so far. Concerning the options outlined in the roadmap, EurEau members have a preference for Option 2.
Zentralverband Elektrotechnik- und Elektronikindustrie e.V. (ZVEI)
· · filed 31 Jul 2020 · source
Strengthening cyber-resilience is an important goal, so that all stakeholders involved can live and work peacefully with each other in an increasingly networked and digitalised world. Cyber incidents cause considerable damage to both companies and private individuals and are therefore a threat for the economy and society.
Palo Alto Networks
· · filed 29 Jul 2020 · source
NIS roadmap recommendations Palo Alto Networks is the global cybersecurity leader with a strong and continuously growing presence throughout Europe and around the world across the private, public, and Critical National Infrastructure sectors.
To whom may it concern: Please find attached the Andersen contribution to the NIS II Directive Feedback period. We wish to express the fully support of Andersen to this EU iniciative aimed to strenghten cybersecurity across Europe. We remain at your disposal for further information or inquire in order to cooperate with EU institutions in this quite decisive issue from legal approach.
BEUC welcomes the current initiative from the European Commission to review the Directive on security of network and information systems (NIS Directive). Recent cyberattacks confirmed the need for strong IT security of critical infrastructure. In June 2019, a cyberattack hit four hospitals in Romania. This attack led to a slowing down of admissions, discharges and prescriptions.
Kaspersky strongly supports the EU in its efforts to substantially and sustainably strengthen the resilience of networks and systems against cybersecurity risks. We also see the need to harmonize the European Digital Single Market and to reduce the fragmentation that has resulted from different legislation, varying implementation of the Directive, and the numerous definitions that exist in the Member States.
GSMA Europe
· · filed 20 Jul 2020 · source
The GSMA welcomes the Commission’s initiative to review the Network and Information Systems (NIS) Directive, agrees that it needs to be reviewed in light of current technological, market and regulatory developments and shares its objectives. The Covid-19 pandemic has highlighted the criticality of maintaining secure connectivity.
Orange Comments on the European Commission’s Initiative for reviewing the NIS Directive Orange welcomes the Commission’s initiative to review the Network and Information Systems (NIS) Directive in light of current technological, market and regulatory developments and to provide an effective pan-European instrument for network security.
EuroUSC Italia ltd
· · filed 26 Jun 2020 · source
we might need: - some guidance for citizens to report security occurrences (in the domain of aviation safety we have mandatory and voluntary reporting based on Regulation 376/2014); - close the gap for security against drones, since Regulation 300/2008 covers only security at aerodromes, while drones take-off from everywhere; - stenghten the link between EASA and ENISA; -empower EASA to develop rules for security of…
SeaTopic SAS
· · filed 25 Jun 2020 · source
I guess the directive should be "sector" oriented. I take one example: maritime and shipping. That industry is ruled by IMO standards. These standards must be taken into account in the directive. Moreover, I suggest to associate funds (incentives such as R&D programs or grants more generally to such directives which can't be adopted by the most if not supported financially.
Method. Every quote is verbatim from the organization’s own submission to the European Commission, trimmed to its opening passage and never summarized by a model. Where a submission was filed in another EU language we show the English text the European Commission publishes alongside it, labeled on the quote; the original is one click away at the source. Groupings use the respondent type the organization itself selected when filing. We deliberately do not label anyone “supportive” or “opposed” — you read what they wrote and draw your own conclusion. Organizations only, never individuals. Reused under Commission Decision 2011/833/EU; the European Commission is not liable for this reuse.