NIS1 Directive
Also known as: NIS1, NIS Directive, Directive (EU) 2016/1148
The first EU-wide cybersecurity law, from 2016, which set security and reporting duties for key service providers until NIS2 replaced it.
Draft - this entry has not been reviewed yet.
Formal
Directive (EU) 2016/1148, written into each member state's own law by May 2018, covering operators of essential services in sectors such as energy, transport, banking, health and drinking water, plus online marketplaces, search engines and cloud services.
In plain English
Like the first edition of a book of rules - it set the idea that firms society leans on must guard their systems, but left each country free to decide who had to follow it.
In practice
In 2018 a Danish energy company was named an operator of essential services, so it had to take suitable security measures and report incidents that seriously disrupted its supply to the national authority.
Why it matters
It was the first time the EU made cyber risk a legal duty across borders; because countries drew the lines so differently, it was repealed and replaced by NIS2 from 18 October 2024.
Technical deep dive
Directive (EU) 2016/1148 was adopted on 6 July 2016 with a transposition deadline of 9 May 2018, and member states then had until 9 November 2018 to identify their operators of essential services (OES). Identification was the heart of the design and also its weakness. Under Article 5(2) an entity was an OES if it provided a service essential for critical societal or economic activities, the service depended on network and information systems, and an incident would have significant disruptive effects; Article 6 listed factors for judging that effect, such as the number of users relying on the service, dependency of other sectors, market share and geographic spread. Each country applied these criteria itself, so comparable companies were in scope in one state and outside it in the next.
The directive had two tiers of obligations. OES in the Annex II sectors (energy, transport, banking, financial market infrastructures, health, drinking water supply and digital infrastructure) had to take appropriate and proportionate security measures and notify significant incidents to the competent authority or CSIRT without undue delay (Article 14). Digital service providers (online marketplaces, online search engines and cloud computing services) faced a lighter regime under Article 16, were supervised only after the fact (Article 17), came under the jurisdiction of the member state of their main establishment (Article 18), and micro and small enterprises were exempt. Commission Implementing Regulation (EU) 2018/151 specified the security elements and incident parameters for them.
Beyond duties for companies, NIS1 built the institutional layer that NIS2 later inherited: national strategies (Article 7), competent authorities and single points of contact (Article 8), national CSIRTs (Article 9), the Cooperation Group of member states (Article 11) and the network of CSIRTs (Article 12). Penalties were left to national law, which only had to make them effective, proportionate and dissuasive (Article 21), and amounts varied widely. Public administration was not covered, and there was no explicit duty for management bodies.
The Commission's review found fragmented scope, uneven supervision and weak enforcement, which led to NIS2: a uniform size-cap rule instead of national identification, 18 sectors instead of seven plus three digital services, staged reporting deadlines, harmonised fine maxima and personal accountability for management. NIS2 Article 44 repealed NIS1 with effect from 18 October 2024. In Denmark NIS1 had been implemented through several sector-specific acts rather than one horizontal law, a split that partly survives in the separate Danish rules for energy, telecommunications and finance under NIS2.
What to learn first
Everything this builds on, foundations first.
- Cyber and information security
- →NIS1 Directive
Relationships
- A kind of
- EU directive
- Requires
- Cyber and information security
- Superseded by
- NIS2 Directive
Sources & further reading
Standards & official texts
- Directive (EU) 2016/1148 (NIS Directive) · European Union
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…