Network and Information Security Directive
Applies to essential and important entities, and reaches their suppliers through contract. Management bodies are personally accountable for approving risk-management measures.
- Scope and entity classification
- Incident notification within 24 hours
- Supply-chain security clauses
- Management liability and board reporting