Article 1: Subject matter
Article 2: Scope
Article 3: Essential and important entities
Article 4: Sector-specific Union legal acts
Article 5: Minimum harmonisation
Article 6: Definitions
Article 7: National cybersecurity strategy
Article 8: Competent authorities and single points of contact
Article 9: National cyber crisis management frameworks
Article 10: Computer security incident response teams (CSIRTs)
Article 11: Requirements, technical capabilities and tasks of CSIRTs
Article 12: Coordinated vulnerability disclosure and a European vulnerability database
Article 13: Cooperation at national level
Article 14: Cooperation Group
Article 15: CSIRTs network
Article 16: European cyber crisis liaison organisation network (EU-CyCLONe)
Article 17: International cooperation
Article 18: Report on the state of cybersecurity in the Union
Article 19: Peer reviews
Article 20: Governance
Article 21: Cybersecurity risk-management measures
Article 22: Union level coordinated security risk assessments of critical supply chains
Article 23: Reporting obligations
Article 24: Use of European cybersecurity certification schemes
Article 25: Standardisation
Article 26: Jurisdiction and territoriality
Article 27: Registry of entities
Article 28: Database of domain name registration data
Article 29: Cybersecurity information-sharing arrangements
Article 30: Voluntary notification of relevant information
Article 31: General aspects concerning supervision and enforcement
Article 32: Supervisory and enforcement measures in relation to essential entities
Article 33: Supervisory and enforcement measures in relation to important entities
Article 34: General conditions for imposing administrative fines on essential and important entities
Article 35: Infringements entailing a personal data breach
Article 36: Penalties
Article 37: Mutual assistance
Article 38: Exercise of the delegation
Article 39: Committee procedure
Article 40: Review
Article 41: Transposition
Article 42: Amendment of Regulation (EU) No 910/2014
Article 43: Amendment of Directive (EU) 2018/1972
Article 44: Repeal
Article 45: Entry into force
Article 46: Addressees
Recitals
Recital 1
Recital 2
Recital 3
Recital 4
Recital 5
Recital 6
Recital 7
Recital 8
Recital 9
Recital 10
Recital 11
Recital 12
Recital 13
Recital 14
Recital 15
Recital 16
Recital 17
Recital 18
Recital 19
Recital 20
Recital 21
Recital 22
Recital 23
Recital 24
Recital 25
Recital 26
Recital 27
Recital 28
Recital 29
Recital 30
Recital 31
Recital 32
Recital 33
Recital 34
Recital 35
Recital 36
Recital 37
Recital 38
Recital 39
Recital 40
Recital 41
Recital 42
Recital 43
Recital 44
Recital 45
Recital 46
Recital 47
Recital 48
Recital 49
Recital 50
Recital 51
Recital 52
Recital 53
Recital 54
Recital 55
Recital 56
Recital 57
Recital 58
Recital 59
Recital 60
Recital 61
Recital 62
Recital 63
Recital 64
Recital 65
Recital 66
Recital 67
Recital 68
Recital 69
Recital 70
Recital 71
Recital 72
Recital 73
Recital 74
Recital 75
Recital 76
Recital 77
Recital 78
Recital 79
Recital 80
Recital 81
Recital 82
Recital 83
Recital 84
Recital 85
Recital 86
Recital 87
Recital 88
Recital 89
Recital 90
Recital 91
Recital 92
Recital 93
Recital 94
Recital 95
Recital 96
Recital 97
Recital 98
Recital 99
Recital 100
Recital 101
Recital 102
Recital 103
Recital 104
Recital 105
Recital 106
Recital 107
Recital 108
Recital 109
Recital 110
Recital 111
Recital 112
Recital 113
Recital 114
Recital 115
Recital 116
Recital 117
Recital 118
Recital 119
Recital 120
Recital 121
Recital 122
Recital 123
Recital 124
Recital 125
Recital 126
Recital 127
Recital 128
Recital 129
Recital 130
Recital 131
Recital 132
Recital 133
Recital 134
Recital 135
Recital 136
Recital 137
Recital 138
Recital 139
Recital 140
Recital 141
Recital 142
Recital 143
Recital 144
Definitions
cloud computing service
content delivery network
data centre service
digital service
DNS service provider
domain name system’ or ‘DNS
entity
entity providing domain name registration services
incident
incident handling
internet exchange point
large-scale cybersecurity incident
managed security service provider
managed service provider
national cybersecurity strategy
near miss
online marketplace
public administration entity
qualified trust service
qualified trust service provider
representative
research organisation
risk
security of network and information systems
significant cyber threat
technical specification
top-level domain name registry’ or ‘TLD name registry
trust service
trust service provider
vulnerability
Annexes
SECTORS OF HIGH CRITICALITY
OTHER CRITICAL SECTORS
CORRELATION TABLE
Footnote p0: Done at Strasbourg, 14 December 2022.