NIS2 · CELEX 02022L2555-20221227
Article 7
Verbatim text of the current consolidated version (consolidated 2022-12-27) · status: in force. Check it on EUR-Lex ↗
NIS2, Article 7(1) — National cybersecurity strategy
Each Member State shall adopt a national cybersecurity strategy that provides for the strategic objectives, the resources required to achieve those objectives, and appropriate policy and regulatory measures, with a view to achieving and maintaining a high level of cybersecurity. The national cybersecurity strategy shall include:
NIS2, Article 7(1)(a) — National cybersecurity strategy
objectives and priorities of the Member State’s cybersecurity strategy covering in particular the sectors referred to in Annexes I and II;
NIS2, Article 7(1)(b) — National cybersecurity strategy
a governance framework to achieve the objectives and priorities referred to in point (a) of this paragraph, including the policies referred to in paragraph 2;
NIS2, Article 7(1)(c) — National cybersecurity strategy
a governance framework clarifying the roles and responsibilities of relevant stakeholders at national level, underpinning the cooperation and coordination at the national level between the competent authorities, the single points of contact, and the CSIRTs under this Directive, as well as coordination and cooperation between those bodies and competent authorities under sector-specific Union legal acts;
NIS2, Article 7(1)(d) — National cybersecurity strategy
a mechanism to identify relevant assets and an assessment of the risks in that Member State;
NIS2, Article 7(1)(e) — National cybersecurity strategy
an identification of the measures ensuring preparedness for, responsiveness to and recovery from incidents, including cooperation between the public and private sectors;
NIS2, Article 7(1)(f) — National cybersecurity strategy
a list of the various authorities and stakeholders involved in the implementation of the national cybersecurity strategy;
NIS2, Article 7(1)(g) — National cybersecurity strategy
a policy framework for enhanced coordination between the competent authorities under this Directive and the competent authorities under Directive (EU) 2022/2557 for the purpose of information sharing on risks, cyber threats, and incidents as well as on non-cyber risks, threats and incidents and the exercise of supervisory tasks, as appropriate;
NIS2, Article 7(1)(h) — National cybersecurity strategy
a plan, including necessary measures, to enhance the general level of cybersecurity awareness among citizens.
NIS2, Article 7(2) — National cybersecurity strategy
As part of the national cybersecurity strategy, Member States shall in particular adopt policies:
NIS2, Article 7(2)(a) — National cybersecurity strategy
addressing cybersecurity in the supply chain for ICT products and ICT services used by entities for the provision of their services;
NIS2, Article 7(2)(b) — National cybersecurity strategy
on the inclusion and specification of cybersecurity-related requirements for ICT products and ICT services in public procurement, including in relation to cybersecurity certification, encryption and the use of open-source cybersecurity products;
NIS2, Article 7(2)(c) — National cybersecurity strategy
managing vulnerabilities, encompassing the promotion and facilitation of coordinated vulnerability disclosure under Article 12(1);
NIS2, Article 7(2)(d) — National cybersecurity strategy
related to sustaining the general availability, integrity and confidentiality of the public core of the open internet, including, where relevant, the cybersecurity of undersea communications cables;
NIS2, Article 7(2)(e) — National cybersecurity strategy
promoting the development and integration of relevant advanced technologies aiming to implement state-of-the-art cybersecurity risk-management measures;
NIS2, Article 7(2)(f) — National cybersecurity strategy
promoting and developing education and training on cybersecurity, cybersecurity skills, awareness raising and research and development initiatives, as well as guidance on good cyber hygiene practices and controls, aimed at citizens, stakeholders and entities;
NIS2, Article 7(2)(g) — National cybersecurity strategy
supporting academic and research institutions to develop, enhance and promote the deployment of cybersecurity tools and secure network infrastructure;
NIS2, Article 7(2)(h) — National cybersecurity strategy
including relevant procedures and appropriate information-sharing tools to support voluntary cybersecurity information sharing between entities in accordance with Union law;
NIS2, Article 7(2)(i) — National cybersecurity strategy
strengthening the cyber resilience and the cyber hygiene baseline of small and medium-sized enterprises, in particular those excluded from the scope of this Directive, by providing easily accessible guidance and assistance for their specific needs;
NIS2, Article 7(2)(j) — National cybersecurity strategy
promoting active cyber protection.
NIS2, Article 7(3) — National cybersecurity strategy
Member States shall notify their national cybersecurity strategies to the Commission within three months of their adoption. Member States may exclude information which relates to their national security from such notifications.
NIS2, Article 7(4) — National cybersecurity strategy
Member States shall assess their national cybersecurity strategies on a regular basis and at least every five years on the basis of key performance indicators and, where necessary, update them. ENISA shall assist Member States, upon their request, in the development or the update of a national cybersecurity strategy and of key performance indicators for the assessment of that strategy, in order to align it with the requirements and obligations laid down in this Directive.
This text is not written by an AI. It is rendered from a corpus built from the official EUR-Lex source, where every fragment is content-hashed and signed at ingestion — which is what lets you cite it and defend the citation. Ask a question about this article →
Other articles of the NIS2
Art. 1Art. 2Art. 3Art. 4Art. 5Art. 6Art. 7Art. 8Art. 9Art. 10Art. 11Art. 12Art. 13Art. 14Art. 15Art. 16Art. 17Art. 18Art. 19Art. 20Art. 21Art. 22Art. 23Art. 24Art. 25Art. 26Art. 27Art. 28Art. 29Art. 30Art. 31Art. 32Art. 33Art. 34Art. 35Art. 36Art. 37Art. 38Art. 39Art. 40Art. 41Art. 42Art. 43Art. 44Art. 45Art. 46
Acquis returns official sources verbatim with citations; it is not legal advice. Texts © European Union, reuse permitted (Decision 2011/833/EU) — only the EUR-Lex original is authentic. Why legal AI fails · Coverage