NIS2 Directive (EU) 2022/2555

Article 7

National cybersecurity strategy

NIS2 Directive (EU) 2022/2555 – Article 7: National cybersecurity strategy

  1. (1) Each Member State shall adopt a national cybersecurity strategy that provides for the strategic objectives, the resources required to achieve those objectives, and appropriate policy and regulatory measures, with a view to achieving and maintaining a high level of cybersecurity. The national cybersecurity strategy shall include:
  2. (2) As part of the national cybersecurity strategy, Member States shall in particular adopt policies:
  3. (3) Member States shall notify their national cybersecurity strategies to the Commission within three months of their adoption. Member States may exclude information which relates to their national security from such notifications.
  4. (4) Member States shall assess their national cybersecurity strategies on a regular basis and at least every five years on the basis of key performance indicators and, where necessary, update them. ENISA shall assist Member States, upon their request, in the development or the update of a national cybersecurity strategy and of key performance indicators for the assessment of that strategy, in order to align it with the requirements and obligations laid down in this Directive.