The European Cyber Security Organisation (ECSO), representing over 300 members, has expressed its perspectives on the newly released NIS2 Implementing Act. ECSO appreciates the advancements in fortifying cybersecurity throughout Europe but has identified multiple areas needing improvement and has proposed recommendations to enhance the Act’s efficacy.
Concerns about Implementation Costs and Requirements
ECSO’s main concern is the potential for excessive costs related to the cybersecurity requirements mandated by the Act. They advocate for risk-based, tailored measures that address specific threats and vulnerabilities faced by individual entities. This tailored approach aims to prevent unnecessary financial strain on organizations while ensuring adequate protection against cyber threats. ECSO also points out the ambiguity in some security requirements, which could impede effective implementation and result in inconsistent rule application across different entities, possibly compromising overall security objectives.
Incident Reporting Challenges
ECSO has highlighted the extensive criteria for defining significant incidents as another critical issue. The organization cautions that this might lead to over-reporting, which would increase the financial and administrative burden on affected entities. They suggest that an incident should be considered significant only if it meets two or more criteria, advocating for a more balanced approach. Additionally, ECSO recommends aligning the Act’s requirements with existing compliance frameworks like ISO/IEC 27001 to streamline implementation and alleviate the burden on entities, especially those with technical constraints.
Need for Clearer Incident Reporting Guidelines
ECSO calls for more detailed and actionable technical guidelines for cybersecurity teams, rather than high-level, legal, or managerial directives. There is a need for clarity on whether incidents should be reported in the entities’ primary country of establishment or in all member states impacted by the incident. Furthermore, the term “becoming aware,” used to trigger an early warning within 24 hours, requires a formal definition. ECSO also notes that criteria such as “reputational damage” and “complaints from users” could be manipulated and should be revised or removed.
Recommendations for Improved Risk Management
ECSO advises that the criteria for defining significant incidents should be tied to the requirements of digital service providers, rather than the entities using the services, since providers may lack visibility into key incident information from their customers. They also recommend extending the duration of operational disruption considered significant and clarifying whether incidents affecting both a digital service provider and its users should be reported by one or both parties.
In conclusion, while ECSO recognizes the progress achieved with the NIS2 Implementing Act, it urges several adjustments to ensure the measures are practical, proportionate, and effectively strengthen cybersecurity across Europe.



