Art.1 | Subject matter | 0 |
Art.10 | Computer security incident response teams (CSIRTs) | 0 |
Art.11 | Requirements, technical capabilities and tasks of CSIRTs | 0 |
Art.12 | Coordinated vulnerability disclosure and a European vulnerability database | 0 |
Art.13 | Cooperation at national level | 0 |
Art.14 | Cooperation Group | 0 |
Art.15 | CSIRTs network | 0 |
Art.16 | European cyber crisis liaison organisation network (EU-CyCLONe) | 0 |
Art.17 | International cooperation | 0 |
Art.18 | Report on the state of cybersecurity in the Union | 0 |
Art.19 | Peer reviews | 0 |
Art.20.1 | Management body approves the cybersecurity risk-management measures and oversees their implementation | 18 |
Art.20.2 | Train the management body, and offer equivalent training to staff on a regular basis | 18 |
Art.21.1 | Take proportionate all-hazards measures calibrated to the entity's own risk exposure | 18 |
Art.21.2.a | Policies on risk analysis and on information system security | 19 |
Art.21.2.b | Incident handling | 20 |
Art.21.2.c | Business continuity, backup management, disaster recovery and crisis management | 19 |
Art.21.2.d | Supply chain security, covering the relationship with each direct supplier and service provider | 19 |
Art.21.2.e | Security in acquisition, development and maintenance, including vulnerability handling and disclosure | 20 |
Art.21.2.f | Policies and procedures to assess the effectiveness of the cybersecurity risk-management measures | 20 |
Art.21.2.g | Basic cyber hygiene practices and cybersecurity training | 19 |
Art.21.2.h | Policies and procedures on the use of cryptography and, where appropriate, encryption | 19 |
Art.21.2.i | Human resources security, access control policies and asset management | 20 |
Art.21.2.j | Multi-factor or continuous authentication, secured communications and secured emergency communications | 16 |
Art.21.3 | Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments | 18 |
Art.21.4 | Take corrective measures without undue delay on finding that the measures are not met | 20 |
Art.22 | Union level coordinated security risk assessments of critical supply chains | 0 |
Art.23.1 | Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients | 19 |
Art.23.2 | Tell affected service recipients about significant cyber threats and the remedies open to them | 15 |
Art.23.4.a | Submit an early warning within 24 hours of becoming aware of a significant incident | 3 |
Art.23.4.b | Submit an incident notification within 72 hours, with an initial assessment and indicators of compromise | 8 |
Art.23.4.c | Provide an intermediate report on status when the CSIRT or competent authority requests one | 6 |
Art.23.4.d | Submit a final report within one month, and a progress report where the incident is still running | 7 |
Art.24 | Use certified ICT products, services and processes where the Member State requires it | 12 |
Art.25 | Standardisation | 0 |
Art.26 | Establish which Member State has jurisdiction, and designate a Union representative if not established in the Union | 6 |
Art.27 | Registry of entities | 0 |
Art.27.2 | Submit the ENISA registry information required of digital infrastructure and digital service providers | 1 |
Art.28 | Maintain accurate domain name registration data and answer lawful access requests within 72 hours | 3 |
Art.29.4 | Notify the competent authority of entry into and withdrawal from information-sharing arrangements | 11 |
Art.3 | Essential and important entities | 0 |
Art.3.4 | Submit and maintain entity registration information with the competent authority | 6 |
Art.30 | Voluntary notification of relevant information | 0 |
Art.31 | General aspects concerning supervision and enforcement | 0 |
Art.32 | Cooperate with supervision: inspections, security audits, scans and requests for information and evidence | 18 |
Art.33 | Supervisory and enforcement measures in relation to important entities | 0 |
Art.34 | General conditions for imposing administrative fines | 0 |
Art.35 | Infringements entailing a personal data breach | 0 |
Art.36 | Penalties | 0 |
Art.37 | Mutual assistance | 0 |
Art.38 | Exercise of the delegation | 0 |
Art.39 | Committee procedure | 0 |
Art.4 | Sector-specific Union legal acts | 0 |
Art.40 | Review | 0 |
Art.41 | Transposition | 0 |
Art.42 | Amendment of Regulation (EU) No 910/2014 | 0 |
Art.43 | Amendment of Directive (EU) 2018/1972 | 0 |
Art.44 | Repeal | 0 |
Art.45 | Entry into force | 0 |
Art.46 | Addressees | 0 |
Art.5 | Minimum harmonisation | 0 |
Art.7 | National cybersecurity strategy | 0 |
Art.8 | Competent authorities and single points of contact | 0 |
Art.9 | National cyber crisis management frameworks | 0 |