Annexes to COM(2020)823 - Measures for a high common level of cybersecurity across the Union

Please note

This page contains a limited version of this dossier in the EU Monitor.

dossier COM(2020)823 - Measures for a high common level of cybersecurity across the Union.
document COM(2020)823 EN
date December 14, 2022
ANNEX I

SECTORS OF HIGH CRITICALITY

SectorSubsectorType of entity
1.Energy
(a)Electricity
Electricity undertakings as defined in Article 2, point (57), of Directive (EU) 2019/944 of the European Parliament and of the Council (1), which carry out the function of ‘supply’ as defined in Article 2, point (12), of that Directive
Distribution system operators as defined in Article 2, point (29), of Directive (EU) 2019/944
Transmission system operators as defined in Article 2, point (35), of Directive (EU) 2019/944
Producers as defined in Article 2, point (38), of Directive (EU) 2019/944
Nominated electricity market operators as defined in Article 2, point (8), of Regulation (EU) 2019/943 of the European Parliament and of the Council (2)

Market participants as defined in Article 2, point (25), of Regulation (EU) 2019/943 providing aggregation, demand response or energy storage services as defined in Article 2, points (18), (20) and (59), of Directive (EU) 2019/944

Operators of a recharging point that are responsible for the management and operation of a recharging point, which provides a recharging service to end users, including in the name and on behalf of a mobility service provider
(b)District heating and cooling
Operators of district heating or district cooling as defined in Article 2, point (19), of Directive (EU) 2018/2001 of the European Parliament and of the Council (3)
(c)Oil
Operators of oil transmission pipelines
Operators of oil production, refining and treatment facilities, storage and transmission
Central stockholding entities as defined in Article 2, point (f), of Council Directive 2009/119/EC (4)
(d)Gas
Supply undertakings as defined in Article 2, point (8), of Directive 2009/73/EC of the European Parliament and of the Council (5)
Distribution system operators as defined in Article 2, point (6), of Directive 2009/73/EC
Transmission system operators as defined in Article 2, point (4), of Directive 2009/73/EC
Storage system operators as defined in Article 2, point (10), of Directive 2009/73/EC
LNG system operators as defined in Article 2, point (12), of Directive 2009/73/EC
Natural gas undertakings as defined in Article 2, point (1), of Directive 2009/73/EC
Operators of natural gas refining and treatment facilities
(e)Hydrogen
Operators of hydrogen production, storage and transmission
2.Transport
(a)Air
Air carriers as defined in Article 3, point (4), of Regulation (EC) No 300/2008 used for commercial purposes
Airport managing bodies as defined in Article 2, point (2), of Directive 2009/12/EC of the European Parliament and of the Council (6), airports as defined in Article 2, point (1), of that Directive, including the core airports listed in Section 2 of Annex II to Regulation (EU) No 1315/2013 of the European Parliament and of the Council (7), and entities operating ancillary installations contained within airports
Traffic management control operators providing air traffic control (ATC) services as defined in Article 2, point (1), of Regulation (EC) No 549/2004 of the European Parliament and of the Council (8)
(b)Rail
Infrastructure managers as defined in Article 3, point (2), of Directive 2012/34/EU of the European Parliament and of the Council (9)
Railway undertakings as defined in Article 3, point (1), of Directive 2012/34/EU, including operators of service facilities as defined in Article 3, point (12), of that Directive
(c)Water
Inland, sea and coastal passenger and freight water transport companies, as defined for maritime transport in Annex I to Regulation (EC) No 725/2004 of the European Parliament and of the Council (10), not including the individual vessels operated by those companies
Managing bodies of ports as defined in Article 3, point (1), of Directive 2005/65/EC of the European Parliament and of the Council (11), including their port facilities as defined in Article 2, point (11), of Regulation (EC) No 725/2004, and entities operating works and equipment contained within ports
Operators of vessel traffic services (VTS) as defined in Article 3, point (o), of Directive 2002/59/EC of the European Parliament and of the Council (12)
(d)Road
Road authorities as defined in Article 2, point (12), of Commission Delegated Regulation (EU) 2015/962 (13) responsible for traffic management control, excluding public entities for which traffic management or the operation of intelligent transport systems is a non-essential part of their general activity
Operators of Intelligent Transport Systems as defined in Article 4, point (1), of Directive 2010/40/EU of the European Parliament and of the Council (14)
3.Banking
Credit institutions as defined in Article 4, point (1), of Regulation (EU) No 575/2013 of the European Parliament and of the Council (15)
4.Financial market infrastructures
Operators of trading venues as defined in Article 4, point (24), of Directive 2014/65/EU of the European Parliament and of the Council (16)
Central counterparties (CCPs) as defined in Article 2, point (1), of Regulation (EU) No 648/2012 of the European Parliament and of the Council (17)
5.Health
Healthcare providers as defined in Article 3, point (g), of Directive 2011/24/EU of the European Parliament and of the Council (18)
EU reference laboratories referred to in Article 15 of Regulation (EU) 2022/2371 of the European Parliament and of the Council (19)
Entities carrying out research and development activities of medicinal products as defined in Article 1, point (2), of Directive 2001/83/EC of the European Parliament and of the Council (20)

Entities manufacturing basic pharmaceutical products and pharmaceutical preparations referred to in section C division 21 of NACE Rev. 2

Entities manufacturing medical devices considered to be critical during a public health emergency (public health emergency critical devices list) within the meaning of Article 22 of Regulation (EU) 2022/123 of the European Parliament and of the Council (21)
6.Drinking water
Suppliers and distributors of water intended for human consumption as defined in Article 2, point (1)(a), of Directive (EU) 2020/2184 of the European Parliament and of the Council (22), excluding distributors for which distribution of water for human consumption is a non-essential part of their general activity of distributing other commodities and goods
7.Waste water
Undertakings collecting, disposing of or treating urban waste water, domestic waste water or industrial waste water as defined in Article 2, points (1), (2) and (3), of Council Directive 91/271/EEC (23), excluding undertakings for which collecting, disposing of or treating urban waste water, domestic waste water or industrial waste water is a non-essential part of their general activity
8.Digital infrastructure
Internet Exchange Point providers
DNS service providers, excluding operators of root name servers
TLD name registries
Cloud computing service providers
Data centre service providers
Content delivery network providers
Trust service providers
Providers of public electronic communications networks
Providers of publicly available electronic communications services
9.ICT service management (business-to-business)
Managed service providers

Managed security service providers
10.Public administration
Public administration entities of central governments as defined by a Member State in accordance with national law
Public administration entities at regional level as defined by a Member State in accordance with national law
11.Space
Operators of ground-based infrastructure, owned, managed and operated by Member States or by private parties, that support the provision of space-based services, excluding providers of public electronic communications networks



(1) Directive (EU) 2019/944 of the European Parliament and of the Council of 5 June 2019 on common rules for the internal market for electricity and amending Directive 2012/27/EU (OJ L 158, 14.6.2019, p. 125).

(2) Regulation (EU) 2019/943 of the European Parliament and of the Council of 5 June 2019 on the internal market for electricity (OJ L 158, 14.6.2019, p. 54).

(3) Directive (EU) 2018/2001 of the European Parliament and of the Council of 11 December 2018 on the promotion of the use of energy from renewable sources (OJ L 328, 21.12.2018, p. 82).

(4) Council Directive 2009/119/EC of 14 September 2009 imposing an obligation on Member States to maintain minimum stocks of crude oil and/or petroleum products (OJ L 265, 9.10.2009, p. 9).

(5) Directive 2009/73/EC of the European Parliament and of the Council of 13 July 2009 concerning common rules for the internal market in natural gas and repealing Directive 2003/55/EC (OJ L 211, 14.8.2009, p. 94).

(6) Directive 2009/12/EC of the European Parliament and of the Council of 11 March 2009 on airport charges (OJ L 70, 14.3.2009, p. 11).

(7) Regulation (EU) No 1315/2013 of the European Parliament and of the Council of 11 December 2013 on Union guidelines for the development of the trans-European transport network and repealing Decision No 661/2010/EU (OJ L 348, 20.12.2013, p. 1).

(8) Regulation (EC) No 549/2004 of the European Parliament and of the Council of 10 March 2004 laying down the framework for the creation of the single European sky (the framework Regulation) (OJ L 96, 31.3.2004, p. 1).

(9) Directive 2012/34/EU of the European Parliament and of the Council of 21 November 2012 establishing a single European railway area (OJ L 343, 14.12.2012, p. 32).

(10) Regulation (EC) No 725/2004 of the European Parliament and of the Council of 31 March 2004 on enhancing ship and port facility security (OJ L 129, 29.4.2004, p. 6).

(11) Directive 2005/65/EC of the European Parliament and of the Council of 26 October 2005 on enhancing port security (OJ L 310, 25.11.2005, p. 28).

(12) Directive 2002/59/EC of the European Parliament and of the Council of 27 June 2002 establishing a Community vessel traffic monitoring and information system and repealing Council Directive 93/75/EEC (OJ L 208, 5.8.2002, p. 10).

(13) Commission Delegated Regulation (EU) 2015/962 of 18 December 2014 supplementing Directive 2010/40/EU of the European Parliament and of the Council with regard to the provision of EU-wide real-time traffic information services (OJ L 157, 23.6.2015, p. 21).

(14) Directive 2010/40/EU of the European Parliament and of the Council of 7 July 2010 on the framework for the deployment of Intelligent Transport Systems in the field of road transport and for interfaces with other modes of transport (OJ L 207, 6.8.2010, p. 1).

(15) Regulation (EU) No 575/2013 of the European Parliament and of the Council of 26 June 2013 on prudential requirements for credit institutions and amending Regulation (EU) No 648/2012 (OJ L 176, 27.6.2013, p. 1).

(16) Directive 2014/65/EU of the European Parliament and of the Council of 15 May 2014 on markets in financial instruments and amending Directive 2002/92/EC and Directive 2011/61/EU (OJ L 173, 12.6.2014, p. 349).

(17) Regulation (EU) No 648/2012 of the European Parliament and of the Council of 4 July 2012 on OTC derivatives, central counterparties and trade repositories (OJ L 201, 27.7.2012, p. 1).

(18) Directive 2011/24/EU of the European Parliament and of the Council of 9 March 2011 on the application of patients’ rights in cross-border healthcare (OJ L 88, 4.4.2011, p. 45).

(19) Regulation (EU) 2022/2371 of the European Parliament and of the Council of 23 November 2022 on serious cross-border threats to health and repealing Decision No 1082/2013/EU (OJ L 314, 6.12.2022, p. 26).

(20) Directive 2001/83/EC of the European Parliament and of the Council of 6 November 2001 on the Community code relating to medicinal products for human use (OJ L 311, 28.11.2001, p. 67).

(21) Regulation (EU) 2022/123 of the European Parliament and of the Council of 25 January 2022 on a reinforced role for the European Medicines Agency in crisis preparedness and management for medicinal products and medical devices (OJ L 20, 31.1.2022, p. 1).

(22) Directive (EU) 2020/2184 of the European Parliament and of the Council of 16 December 2020 on the quality of water intended for human consumption (OJ L 435, 23.12.2020, p. 1).

(23) Council Directive 91/271/EEC of 21 May 1991 concerning urban waste water treatment (OJ L 135, 30.5.1991, p. 40).



ANNEX II

OTHER CRITICAL SECTORS

SectorSubsectorType of entity
1.Postal and courier services
Postal service providers as defined in Article 2, point (1a), of Directive 97/67/EC, including providers of courier services
2.Waste management
Undertakings carrying out waste management as defined in Article 3, point (9), of Directive 2008/98/EC of the European Parliament and of the Council (1), excluding undertakings for whom waste management is not their principal economic activity
3.Manufacture, production and distribution of chemicals
Undertakings carrying out the manufacture of substances and the distribution of substances or mixtures, as referred to in Article 3, points (9) and (14), of Regulation (EC) No 1907/2006 of the European Parliament and of the Council (2) and undertakings carrying out the production of articles, as defined in Article 3, point (3), of that Regulation, from substances or mixtures
4.Production, processing and distribution of food
Food businesses as defined in Article 3, point (2), of Regulation (EC) No 178/2002 of the European Parliament and of the Council (3) which are engaged in wholesale distribution and industrial production and processing
5.Manufacturing
(a)Manufacture of medical devices and in vitro diagnostic medical devices
Entities manufacturing medical devices as defined in Article 2, point (1), of Regulation (EU) 2017/745 of the European Parliament and of the Council (4), and entities manufacturing in vitro diagnostic medical devices as defined in Article 2, point (2), of Regulation (EU) 2017/746 of the European Parliament and of the Council (5) with the exception of entities manufacturing medical devices referred to in Annex I, point 5, fifth indent, of this Directive
(b)Manufacture of computer, electronic and optical products
Undertakings carrying out any of the economic activities referred to in section C division 26 of NACE Rev. 2
(c)Manufacture of electrical equipment
Undertakings carrying out any of the economic activities referred to in section C division 27 of NACE Rev. 2
(d)Manufacture of machinery and equipment n.e.c.
Undertakings carrying out any of the economic activities referred to in section C division 28 of NACE Rev. 2
(e)Manufacture of motor vehicles, trailers and semi-trailers
Undertakings carrying out any of the economic activities referred to in section C division 29 of NACE Rev. 2
(f)Manufacture of other transport equipment
Undertakings carrying out any of the economic activities referred to in section C division 30 of NACE Rev. 2
6.Digital providers
Providers of online marketplaces
Providers of online search engines
Providers of social networking services platforms
7.Research
Research organisations



(1) Directive 2008/98/EC of the European Parliament and of the Council of 19 November 2008 on waste and repealing certain Directives (OJ L 312, 22.11.2008, p. 3).

(2) Regulation (EC) No 1907/2006 of the European Parliament and of the Council of 18 December 2006 concerning Registration, Evaluation, Authorisation and Restriction of Chemicals (REACH), establishing a European Chemicals Agency, amending Directive 1999/45/EC and repealing Council Regulation (EEC) No 793/93 and Commission Regulation (EC) No 1488/94 as well as Council Directive 76/769/EEC and Commission Directives 91/155/EEC, 93/67/EEC, 93/105/EC and 2000/21/EC (OJ L 396, 30.12.2006, p. 1).

(3) Regulation (EC) No 178/2002 of the European Parliament and of the Council of 28 January 2002 laying down the general principles and requirements of food law, establishing the European Food Safety Authority and laying down procedures in matters of food safety (OJ L 31, 1.2.2002, p. 1).

(4) Regulation (EU) 2017/745 of the European Parliament and of the Council of 5 April 2017 on medical devices, amending Directive 2001/83/EC, Regulation (EC) No 178/2002 and Regulation (EC) No 1223/2009 and repealing Council Directives 90/385/EEC and 93/42/EEC (OJ L 117, 5.5.2017, p. 1).

(5) Regulation (EU) 2017/746 of the European Parliament and of the Council of 5 April 2017 on in vitro diagnostic medical devices and repealing Directive 98/79/EC and Commission Decision 2010/227/EU (OJ L 117, 5.5.2017, p. 176).



ANNEX III

CORRELATION TABLE

Directive (EU) 2016/1148This Directive
Article 1(1)Article 1(1)
Article 1(2)Article 1(2)
Article 1(3)-
Article 1(4)Article 2(12)
Article 1(5)Article 2(13)
Article 1(6)Article 2(6) and (11)
Article 1(7)Article 4
Article 2Article 2(14)
Article 3Article 5
Article 4Article 6
Article 5
Article 6
Article 7(1)Article 7(1) and (2)
Article 7(2)Article 7(4)
Article 7(3)Article 7(3)
Article 8(1) to (5)Article 8(1) to (5)
Article 8(6)Article 13(4)
Article 8(7)Article 8(6)
Article 9(1), (2) and (3)Article 10(1), (2) and (3)
Article 9(4)Article 10(9)
Article 9(5)Article 10(10)
Article 10(1), (2) and (3), first subparagraphArticle 13(1), (2) and (3)
Article 10(3), second subparagraphArticle 23(9)
Article 11(1)Article 14(1) and (2)
Article 11(2)Article 14(3)
Article 11(3)Article 14(4), first subparagraph, points (a) to (q) and (s), and paragraph (7)
Article 11(4)Article 14(4), first subparagraph, point (r), and second subparagraph
Article 11(5)Article 14(8)
Article 12(1) to (5)Article 15(1) to (5)
Article 13Article 17
Article 14(1) and (2)Article 21(1) to (4)
Article 14(3)Article 23(1)
Article 14(4)Article 23(3)
Article 14(5)Article 23(5), (6) and (8)
Article 14(6)Article 23(7)
Article 14(7)Article 23(11)
Article 15(1)Article 31(1)
Article 15(2), first subparagraph, point (a)Article 32(2), point (e)
Article 15(2), first subparagraph, point (b)Article 32(2), point (g)
Article 15(2), second subparagraphArticle 32(3)
Article 15(3)Article 32(4), point (b)
Article 15(4)Article 31(3)
Article 16(1) and (2)Article 21(1) to (4)
Article 16(3)Article 23(1)
Article 16(4)Article 23(3)
Article 16(5)
Article 16(6)Article 23(6)
Article 16(7)Article 23(7)
Article 16(8) and (9)Article 21(5) and Article 23(11)
Article 16(10)
Article 16(11)Article 2(1), (2) and (3)
Article 17(1)Article 33(1)
Article 17(2), point (a)Article 32(2), point (e)
Article 17(2), point (b)Article 32(4), point (b)
Article 17(3)Article 37(1), points (a) and (b)
Article 18(1)Article 26(1), point (b), and paragraph (2)
Article 18(2)Article 26(3)
Article 18(3)Article 26(4)
Article 19Article 25
Article 20Article 30
Article 21Article 36
Article 22Article 39
Article 23Article 40
Article 24
Article 25Article 41
Article 26Article 45
Article 27Article 46
Annex I, point (1)Article 11(1)
Annex I, points (2)(a)(i) to (iv)Article 11(2), points (a) to (d)
Annex I, point (2)(a)(v)Article 11(2), point (f)
Annex I, point (2)(b)Article 11(4)
Annex I, points (2)(c)(i) and (ii)Article 11(5), point (a)
Annex IIAnnex I
Annex III, points (1) and (2)Annex II, point (6)
Annex III, point (3)Annex I, point (8)