Report Your Business According to the Cybersecurity Act (NIS2)

The Cybersecurity Act, implementing the EU NIS2 directive, entails a clearly strengthened responsibility for organizations whose operations are vital to society's functions. The basis for assessment is found in the Cybersecurity Act, Annexes 1 and 2 of the EU directive, and the regulation on reporting and identification. Upcoming guidance will also support operators in identifying and analyzing the scope. Does the activity fall under the Cybersecurity Act (ncsc.se)? All operators covered by the Cybersecurity Act must register, regardless of sector. Organizations that identify themselves as operators based on sector(s), type of activity, size, jurisdiction, and significant/vital operator according to the Cybersecurity Act must report their operations to the Civil Defense Agency. There are two purposes: firstly, Sweden must compile and maintain a list of all operators covered by the Cybersecurity Act (NIS2), and secondly, the relevant supervisory authority must have access to this information. On February 20 at 10:30, the Civil Defense Agency will review the consultation responses regarding the regulations on security measures and training.

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source