dokumendiregister.ee
OtsingAsutusedMCP
Otsing›Majandus- ja Kommunikatsiooniministeerium
Sissetulev kiriAvalik

Ettevõtlusliitude ühispöördumine

Majandus- ja Kommunikatsiooniministeerium · 30. september 2024
Viit
9-2/2455-1
Registreeritud
30. september 2024
Dokumendi liik
Sissetulev kiri
Adressaat
Eesti Infotehnoloogia ja Telekommunikatsiooni Liit
Saabumis/saatmisviis
e-post
Funktsioon
9 Digiarengu korraldamine
Sari
9-2 Küberturvalisuse kavandamise ning korraldamise kirjavahetus
Toimik
9-2/2024
Vastutaja
Raavo Palu (Majandus- ja Kommunikatsiooniministeerium, Kantsleri valdkond, Digiarengu valdkond, Riikliku küberturvalisuse osakond)
Lahendamise tähtaeg
30. oktoober 2024

Failid

  • 📎Call-for-harmonised-NIS-transposition-to-safeguard-the-single-market.pdf274 KB
  • 📎Infoks ettevõtlusliitude ühispöördumine NIS2 teemal.msg310 KB

Sisu (failidest)

26 September 2024 A call for harmonised NIS2 transposition to safeguard the single market The updated Directive on measures for a high common level of cybersecurity across the Union (NIS2 Directive)1 is the cornerstone of Europe’s cybersecurity. Its enactment into national laws, due 17 October 2024, comes at a pivotal moment for the EU’s single market. Unfortunately, nearly all Member States are choosing to diverge from the common EU rules in their own manner. They are expanding the rules’ scope, imposing stricter minimum requirements, establishing a multitude of overseeing agencies, and establishing different compliance timelines. Discrepancies in Member States’ cyber laws translating the NIS2 Directive result in a fragmented and less cybersecure single market.2 We call on Member States to: ▪ Preserve NIS2’s boundaries: Surpassing the common EU rules on scope and requirements will hurt companies’ ability to scale up across Europe, particularly SMEs. Cybersecurity risk management measures should be constricted to those strictly necessary, based on the risk assessment companies must carry out. ▪ Establish reliable entity classification: Predictability is vital for business planning. The EU criteria for important and essential entities should be adopted without deviation, and engaging directly with affected companies. If expanding the scope is necessary, clear reclassification criteria should be provided to allow companies to prepare for compliance. ▪ Keep compliance proportional: NIS2 introduces significant new obligations, especially for entities previously outside the scope of EU cyber rules. These companies will often need to build their cybersecurity compliance efforts from scratch. Member States should provide guidance to entities and establish clear, efficient and minimally burdensome compliance procedures. For multinational companies, mutual recognition of compliance and a one-stop-shop approach should be prioritised. 1 Directive (EU) 2022/25555. 2 See DIGITALEUROPE, The Single Market Love Story: 10 digital actions to save the 30-year marriage, available at https://cdn.digitaleurope.org/uploads/2024/02/DIGITAL-EUROPE-THE-SINGLE-MARKET- LOVE-STORY-FINAL-WEB.pdf. ▪ Limit supervisory complexity: Involving multiple competent authorities in NIS2 enforcement can cause confusion and delays. Minimising the number of authorities is crucial to streamline oversight and incident response. In addition to a one-stop-shop approach, looking ahead we advocate for the exploration of a 28th regime at the EU level for future cyber legislation reforms to further harmonise regulations, enhance competitiveness and strengthen the single market. ▪ Provide adequate time for transition: Companies need sufficient time to implement cybersecurity measures. National laws should allow a phased approach, including submission of system security plans with action milestones to meet compliance over time. ▪ Ensure coherence between NIS2 and the Directive on the resilience of critical entities (CER Directive):3 National authorities should coordinate the transposition of NIS2 and CER to avoid overlapping obligations and streamline cybersecurity and critical infrastructure protections for entities covered by both Directives. By maintaining clear standards and adopting measures such as one-stop shops for compliance, we can enhance cybersecurity across the EU whilst preserving the integrity of the single market. A coordinated approach, both now and in future reforms, is essential to strengthening Europe’s digital resilience and competitiveness. List of signatories AAVIT, Association for Applied Research in IT, aavit.cz IT-Branchen, itb.dk Adigital, Spanish Association for the Digital Economy, ITL, Estonian Association of Information Technology and adigital.org Telecommunications, itl.ee Agoria, agoria.be Numeum, France’s Digital Association, numeum.fr ANIS, Romanian Employers’ Association of the Software NLdigital, nldigital.nl and Services Industry, anis.ro KIGEiT, Polish Chamber of Commerce for Electronics and Anitec-Assinform, anitec-assinform.it Telecommunications, kigeit.org.pl Bitkom, Germany’s Digital Association, bitkom.org SEPE, Federation of Hellenic Information Technology & Communications Enterprises, sepe.gr Danish Chamber of Commerce, danskerhverv.dk Technology Ireland, ibec.ie DI Digital, Danish ICT and Electronics Federation, danskindustri.dk/brancher/di-digital/ Technology Industries of Finland, teknologiateollisuus.fi DIGITALEUROPE, digitaleurope.org Teknikföretagen, Technology Industries of Sweden, teknikforetagen.se Digitaloffensive Österreich, Digital Association Austria, digitaloffensive.at ZVEI, German Association of Electro and Digital Industries, www.zvei.org Infobalt, DigiTech Sector Association Lithuania, infobalt.lt 3 Directive (EU) 2022/2557. Teema: FW: Infoks: ettevõtlusliitude ühispöördumine NIS2 teemal From: Keilin Tammepärg (ITL) <[email protected] <mailto:[email protected]> > Sent: Monday, September 30, 2024 4:00 PM To: Raavo Palu - MKM <[email protected] <mailto:[email protected]> >; Silver Lusti <[email protected] <mailto:[email protected]> >; Seiko Kuik <[email protected] <mailto:[email protected]> >; Irina Klementi - MKM <[email protected] <mailto:[email protected]> >; Erik Janson - MKM <[email protected] <mailto:[email protected]> > Subject: Infoks: ettevõtlusliitude ühispöördumine NIS2 teemal Tere ITL allkirjastas koos teiste Euroopa IT ja tehnoloogia liitudega ühispöördumise (vt manust), milles kutsume üles arvestama NIS2 direktiivi siseriiklikku õigusesse üle võtmisel siseturu eesmärkidega. Mitmed kirjas toodud punktid on ka Eestis olulised, näiteks väga selged kriteeriumid kohaldamisalas olevate ettevõtete määramiseks, proportsionaalsed kohustused ja piisav rakendamisaeg seaduse subjektidele. Heade soovidega Keilin Tammepärg ITL
Allikas: Majandus- ja Kommunikatsiooniministeerium dokumendiregister →
dokumendiregister.eeAsutusedEesti avalike dokumendiregistrite otsing · nimistu.ee andmetel