The load-bearing definitions (incident, significant incident, near miss, supply chain) and how NIS2 interacts with sector-specific acts — when lex specialis (e.g. financial-sector rules) displaces NIS2 obligations.
NIS2 defines "network and information system" across three limbs: electronic communications networks, any device or group of interconnected or related devices, one or more of which, pursuant to a programme, carry out automatic processing of digital data, and the data itself stored, processed, retrieved or transmitted by those elements for the purposes of their operation, use, protection and maintenance 32022L2555 Article 6@2022-12-27. "Security of network and information systems" is then defined as the ability of those systems to resist, at a given level of confidence, any event that may compromise the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, those systems 32022L2555 Article 6@2022-12-27. These four attributes — the AAIC quartet — are not incidental; they define exactly what harm must occur for an event to qualify as an incident, and they recur throughout the directive's obligations.
Three terms define different points on the harm spectrum, and their boundaries matter operationally.
Incident is "an event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems" 32022L2555 Article 6@2022-12-27. The definition turns on actual compromise — at least one of the four AAIC attributes must have been damaged or disrupted; a potential or averted disruption does not qualify.
Near miss is "an event that could have compromised the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems, but that was successfully prevented from materialising or that did not materialise" 32022L2555 Article 6@2022-12-27. The distinction is causal: a near miss came close to causing compromise but either was stopped or collapsed on its own. Near misses do not themselves trigger the incident-notification clock.
Large-scale cybersecurity incident means an incident causing disruption that exceeds a Member State's capacity to respond, or that has a significant impact on at least two Member States 32022L2555 Article 6@2022-12-27.
Significant incident — the threshold that triggers the Article 23 notification duty — is referenced in Article 4 as the benchmark against which sector-specific notification regimes are tested for equivalence 32022L2555 Article 4@2022-12-27. The precise threshold criteria are set out in Article 23, which is not covered by the provided regulation units for this lesson.
A definition of supply chain relationships relevant to NIS2 risk-management obligations is not covered by the provided regulation units. Supply-chain security obligations appear in Article 21, not in Article 6's definitional register.
Where a sector-specific Union legal act already requires essential or important entities to adopt cybersecurity risk-management measures or to notify significant incidents, and where those requirements are at least equivalent in effect to NIS2 obligations, the relevant NIS2 provisions — including the supervision and enforcement regime in Chapter VII — shall not apply to those entities 32022L2555 Article 4@2022-12-27. This is the lex specialis principle applied by the directive itself: the more specific, sector-tailored instrument displaces the general-purpose directive for entities within its scope.
Equivalence is not self-certifying. Article 4 specifies two alternative routes 32022L2555 Article 4@2022-12-27:
Both routes use "equivalent in effect" — the comparison is functional, not textual. A sector instrument that achieves the same protective outcome through different procedural means can still satisfy the test.
Article 4 addresses partial overlap explicitly: where a sector-specific act does not cover all entities within a sector falling under NIS2's scope, NIS2 continues to apply to the uncovered entities 32022L2555 Article 4@2022-12-27. Displacement is never wholesale by sector label — it operates entity by entity, depending on whether the sector instrument actually reaches that entity. An entity in the financial sector that falls outside the personal scope of a sector regulation remains subject to NIS2 in full.
The Commission was required to publish guidelines clarifying the application of Article 4 by 17 July 2023, taking into account any observations of the Cooperation Group and ENISA, with regular review thereafter 32022L2555 Article 4@2022-12-27.
This block connects to your organisation's own information-security policies (ISMS). In the full product it shows, cited to your policy set, how YOUR organisation implements the obligation above — private to your organisation. (Demo placeholder.)
The following items are labeled illustrative context, not regulation.
No recent cases are cached for this topic.
1. Which four attributes define "security of network and information systems" under NIS2?
NIS2 defines security as the ability of systems to resist events compromising availability, authenticity, integrity or confidentiality — the AAIC quartet — which sets the exact harm threshold that must be met for an event to qualify as an incident. 32022L2555 Article 6@2022-12-27
2. A security team detects malware that was completely blocked before it could alter or expose any data. Under NIS2, this event is best classified as:
A near miss is an event that could have compromised AAIC attributes but was successfully prevented from materialising, and near misses do not themselves start the incident-notification clock. 32022L2555 Article 6@2022-12-27
3. Under NIS2, a "large-scale cybersecurity incident" is defined by which threshold?
NIS2 defines a large-scale cybersecurity incident as one causing disruption that exceeds a Member State's capacity to respond or that has a significant impact on at least two Member States — no financial or data-volume threshold is involved. 32022L2555 Article 6@2022-12-27
4. A financial-sector entity falls outside the personal scope of the applicable sector-specific Union regulation. What follows under Article 4?
Where a sector-specific act does not cover all entities within a sector falling under NIS2's scope, NIS2 continues to apply to the uncovered entities — displacement is never wholesale by sector. 32022L2555 Article 4@2022-12-27
5. Under Article 4's notification route, a sector-specific act satisfies the equivalence test if:
The notification route requires immediate access — where appropriate automatic and direct — to incident notifications by CSIRTs, competent authorities, or single points of contact, with notification requirements at least equivalent in effect (not textually identical) to Article 23(1) to (6). 32022L2555 Article 4@2022-12-27