Source: OJ L 333, 27.12.2022, p. 80–152

Current language: DE

Artikel 22 Koordinierte Risikobewertungen in Bezug auf die Sicherheit kritischer Lieferketten auf Ebene der Union


Summary What does Article 22 of the NIS 2 directive say?

This article establishes a mechanism for coordinated, Union-level security risk assessments of critical ICT supply chains.

It connects directly to Article 21, which requires entities to consider supply chain security as part of their risk-management measures — Article 22 is the upstream process that informs those considerations at a collective, cross-border level.

The Cooperation Group leads these assessments in cooperation with the Commission and ENISA, and both technical and non-technical risk factors are within scope.

Important points:

  • The Cooperation Group, together with the Commission and ENISA, may carry out coordinated security risk assessments of specific critical ICT services, systems, or product supply chains.
  • The Commission is responsible for identifying which specific critical ICT services, systems, or products are subject to these assessments, after consulting the Cooperation Group, ENISA, and where necessary, relevant stakeholders.
  • These assessments feed directly into the supply chain security obligations placed on entities under Article 21.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. Die Kooperationsgruppe kann in Zusammenarbeit mit der Kommission und der ENISA koordinierte Risikobewertungen in Bezug auf die Sicherheit der Lieferketten bestimmter kritischer IKT-Dienste, -Systeme oder -Produkte unter Berücksichtigung technischer und erforderlichenfalls nichttechnischer Risikofaktoren durchführen.

    1. Die Kommission legt nach Konsultation der Kooperationsgruppe und der ENISA sowie gegebenenfalls einschlägiger Interessenträger fest, welche spezifischen kritischen IKT-Dienste, -Systeme oder -Produkte der koordinierten Risikobewertung in Bezug auf die Sicherheit nach Absatz 1 unterzogen werden können

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod