DIRECTIVE (EU) 2022/2555 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL | 32022L2555 — European Union law | Esheria

DIRECTIVE (EU) 2022/2555 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

This part explains the Directive’s cybersecurity framework: who may fall in scope, which national authorities Member States should set up, and how entities and authorities should share information and cooperate.

AI-assisted research synopsis — verify against the official legal text below.

Jurisdiction
European Union
Instrument
Directive
Citation
32022L2555
Status
In force
Version
Undated source snapshot
Language
en
Official source
View official record ↗
WHOIS data access to registration data administrative fines cross-border cooperation cyber governance cyber risk management cybersecurity risk management data verification delegated acts domain name registration incident reporting incident response information sharing mutual assistance public communications security publication and disclosure procedures risk management scope and entity registration supervision and enforcement supervisory measures transposition vulnerability disclosure

Publicly available, excluded from search-engine indexing

This page remains available for direct access and API use, but this release emits noindex,follow for the following reason:

  • The record does not meet this release's canonical indexing criteria. (market-indexing-disabled)

Statute overview

About this statute

This part explains the Directive’s cybersecurity framework: who may fall in scope, which national authorities Member States should set up, and how entities and authorities should share information and cooperate. This provision says Member States should support SME cybersecurity, set up vulnerability disclosure arrangements, and require major incident reporting and certain security measures for key entities. TLD name registries and domain name registration service providers must collect, verify, publish, and disclose domain name registration data under specified rules, and Member States must ensure some access is free of charge. This provision defines key cybersecurity terms and requires Member States to adopt, notify, review, and update a national cybersecurity strategy, while also setting up competent authorities and a single point of contact. This provision sets rules for cybersecurity peer reviews, incident reporting, domain registration data, voluntary information sharing, and supervision of essential and important entities.