NIS2 DirectiveEU 2022/2555
Digiphile

Recitals

Recital 83


Recital 83

Security of Private Network and Information Systems Unofficial title


Essential and important entities should ensure the security of the network and information systems which they use in their activities. Those systems are primarily private network and information systems managed by the essential and important entities’ internal IT staff or the security of which has been outsourced. The cybersecurity risk-management measures and reporting obligations laid down in this Directive should apply to the relevant essential and important entities regardless of whether those entities maintain their network and information systems internally or outsource the maintenance thereof.