NIS2 supervision: required documents
Which documents your country's law requires you to have, who the obligation applies to and in which situations they are submitted to the supervisory authority. Every statement refers to a provision of the law, and the text of the law is shown below it.
Source: S.L. 460.41
Which documents must exist
The security liaison officer appointed by the entity must ensure that the entity conducts and maintains appropriate risk assessments and maintains and exercises an operator security plan. (article 19(1)(c))
Text of the law
(ii) ensure that the essential or important entity conducts and maintains appropriate risk assessments; (iii) ensure that the essential or important entity maintains and exercises an operator security plan;
The security liaison officer must facilitate the development, implementation, maintenance and review of business continuity plans and, where necessary, termination plans. (article 19(1)(c)(i))
Text of the law
(i) facilitate the development, implementation, maintenance and review of business continuity plans and where necessary termination plans that include the preparedness, processes and solutions of the essential or important entity;
The cybersecurity risk-management measures must include at least policies on risk analysis and information system security. (article 19(2)(a))
Text of the law
and shall include at least the following: (a) policies on risk analysis and information system security; (b) incident handling;
Who the obligation applies to
The obligation to take cybersecurity risk-management measures applies to essential and important entities. (article 19(1))
Text of the law
shall ensure that essential and important entities: (a) take appropriate and proportionate technical, operational and organisational measures
The management bodies of essential and important entities approve the cybersecurity risk-management measures and oversee their implementation. (article 18(1))
Text of the law
shall ensure that management bodies of such essential and important entities approve the cybersecurity risk- management measures in accordance with article 19 and oversee their implementation.
When the documents are submitted to the supervisory authority
When supervising essential entities, the CIP Department or the designated competent authority may request information needed to assess the risk-management measures, including documented cybersecurity policies. (article 29(2)(e))
Text of the law
(e) requests for information necessary to assess the cybersecurity risk-management measures adopted by the essential entity concerned, including documented cybersecurity policies
The supervisory authority may also request evidence of operator security plans, business continuity plans and, where necessary, termination plans. (article 29(2)(j))
Text of the law
(j) requests for evidence of operator security plans, business continuity plans and where necessary termination plans;
The results of any targeted security audit must be made available to the CIP Department or the designated competent authority. (article 29(4))
Text of the law
(4) The results of any targeted security audit in sub-articles (2)(b) and (3), shall be made available to the CIP Department, or where designated the competent authority.
Prices of the document package and single documents: Pricing