Reference

Glossary

Terms and acronyms used across the EU cyber rulebook and this site.

Glossary

  • Regulation — EU law applying directly and identically in all Member States (GDPR, DORA, CRA).
  • Directive — EU law setting objectives; each Member State must transpose it (NIS2, CER).
  • Transposition — turning a directive into national law by its deadline.
  • Delegated / Implementing act — secondary Commission legislation filling in technical detail (NIS2 Impl. Reg. 2024/2690; RED Delegated Reg. 2022/30).
  • Lex specialis — “specific law beats general law”: a sector act (DORA) displaces a general one (NIS2) on the same matter.
  • CELEX number — unique EUR-Lex identifier of a legal act (32022L2555 = NIS2).
  • Trilogue — Commission/Parliament/Council negotiation to finalise a text.
  • Infringement procedure — Commission enforcement against a state: letter of formal notice → reasoned opinion → referral to the CJEU.
  • Vacatio legis — gap between a law’s publication and entry into force.

Core NIS2 / CER concepts

  • Essential vs Important entity — the two NIS2 categories; essential entities face proactive supervision and higher fines (€10M/2% vs €7M/1.4%).
  • Significant incident — NIS2 reporting trigger (severe disruption, financial loss, or considerable damage to others).
  • 24/72/one-month cascade — NIS2 reporting rhythm: 24h early warning, 72h notification, one-month final report.
  • Main establishment — NIS2 Art. 26: the Member State where cyber risk-management decisions are predominantly taken; sets the primary competent authority.
  • CSIRT — Computer Security Incident Response Team; each state designates one or more, networked at EU level.
  • Critical entity — the CER Directive’s category, focused on physical/all-hazards resilience.

Product & certification concepts

  • Product with digital elements (PDE) — CRA term: any hardware/software with a data connection, plus its remote data processing.
  • Security by design / by default — build security in from conception (CRA Annex I), not patch it on later.
  • Support period — CRA duty to provide security updates, in principle ≥ 5 years.
  • CE marking — manufacturer’s declaration a product meets EU requirements; CRA adds cybersecurity to it.
  • ECCF — European Cybersecurity Certification Framework (Cybersecurity Act); voluntary schemes at basic / substantial / high assurance.
  • EUCC / EUCS / EU5G — first schemes: ICT products (adopted), cloud (draft), 5G (draft).
  • Cyber posture certification — CSA2 proposal: certifying an organisation’s overall NIS2 compliance, not just a product.
  • SBOM — Software Bill of Materials; inventory of components (CRA vulnerability-handling requirement).

Financial sector (DORA)

  • ICT third-party risk — DORA pillar governing outsourcing to tech providers.
  • CTPP — Critical ICT Third-Party Provider (e.g. hyperscale cloud) under direct ESA oversight.
  • TLPT — Threat-Led Penetration Testing; ≥ every 3 years for significant entities (TIBER-EU aligned).
  • Register of Information — mandatory inventory of all ICT contractual arrangements.
  • ESAs — the three European Supervisory Authorities: EBA (banking), ESMA (markets), EIOPA (insurance/pensions).

Institutions & networks

  • ENISA — EU Agency for Cybersecurity; technical hub, certification scheme manager, future SEP operator.
  • CSIRTs Network / EU-CyCLONe — EU operational cooperation (technical level / crisis-liaison level).
  • NIS Cooperation Group — strategic cooperation body (Member States, Commission, ENISA).
  • ECCG — European Cybersecurity Certification Group (national certification authorities).
  • National competent authority — the body a state designates to supervise NIS2/CER entities (ACN Italy, BSI Germany, ANSSI France, CCB Belgium…).

The 2026 reform vocabulary

  • Cybersecurity Package (2026) — CSA2 proposal + targeted NIS2 amendments (20 Jan 2026).
  • CSA2 — proposed revised Cybersecurity Act (COM(2026) 11).
  • Digital Omnibus — Nov-2025 simplification package amending several digital laws at once.
  • SEP — Single Entry Point — proposed ENISA-run platform: one report satisfying NIS2/GDPR/DORA/CER/eIDAS/CRA (“report once, share many”).
  • High-risk supplier — CSA2 concept: suppliers restricted/excluded on technical and non-technical risk (e.g. third-country influence).
  • Small mid-cap (SMC) — new enterprise category in the NIS2 amendment proposal, to lower compliance costs.