Guidelines clarify the application of Article 4(1) and (2) of NIS2, which concern the relationship between Directive (EU) 2022/2555 and current and future sector-specific Union legal acts addressing cybersecurity risk-management measures or incident reporting requirements. The Appendix to the Guidelines lists the sector-specific Union legal acts that the Commission considers to fall within the scope of Article 4 of Directive (EU) 2022/2555.
Author: European Commission
Status: Adopted / Published
Adoption date: 2023-09-13
Last updated: 08 Aug 2025
Category: Guidance
Subcategory: Official guidance