The Act is the same for everyone. The route to compliance is not.
Every sector has its own competent authority, its own CSIRT and its own typical findings.
The areas we cover
Healthcare
Hospitals and healthcare, a special category of data.OPEN →Energy
Electricity, gas, oil and heating.OPEN →Transport
Road, rail, maritime and air transport.OPEN →Public administration
State bodies and local government.OPEN →Banking and finance
Alongside the law, DORA applies as lex specialis.OPEN →Water
Small institutions with obligations equal to the largest.OPEN →Digital infrastructure
Data centres, networks, DNS and cloud services.OPEN →ICT services
Obligations under the law and towards obliged clients.OPEN →Important entities
The same measures, self-assessment and audit on request.OPEN →The sector sets the authority, the size sets the category
Three things get mixed up: the sector, the entity category and the level of measures. They are three different things, set in three different ways.
The sector follows from the activity and from the annexes to the Act. Annex I lists the sectors of high criticality, among them energy, transport, banking, healthcare, water, digital infrastructure, ICT service management, the public sector and space. Annex II lists the other critical sectors, postal services, waste management, manufacturing, food, research and the education system for instance.
The category, essential or important, follows from the annex and the size, with exceptions that apply regardless of size. Essential are Annex I entities above the ceilings for medium-sized enterprises; important are medium-sized Annex I entities and medium and large Annex II entities. The exception is providers of public electronic communications networks and services, which are essential even when medium-sized. An entity classified as both is treated as essential, under Article 16 of the Act.
The level of measures, basic, medium or advanced, follows from neither the sector nor the category. It is set by the national risk assessment during categorisation, under Article 38 of the Regulation. An essential entity at low risk may therefore sit at the basic level, and an important entity at high risk at the advanced one.
What the sector does determine is who supervises you and where you report an incident. For each sector, Annex III of the Act names the authority competent for cyber security requirements, the body competent for sectoral legislation, and the competent CSIRT.
Competent authorities and CSIRTs by sector
Under Annex III of the Act. A dash means the Annex names no body in that column for that sector.
Each sector page names the competent authority, the competent CSIRT, who from the sector falls in scope and where the work usually gets stuck. Open your own sector from the grid at the top of this page.
The Information Systems Security Bureau is neither a supervisory authority under the Act nor a CSIRT for any sector. It is the central state authority for the technical areas of information security; it certifies managed security service providers and audits state administration bodies and other state bodies, under Article 32(3) of the Act.
Frequently asked questions
The questions we are asked most often before we start.
How do we know which sector we are in?
By the activity listed in the annexes to the Act, not by the activity code in the companies register. Where the line is unclear, what counts is which service is essential for users. The final word rests with the competent authority, which notifies you of the categorisation within thirty days.Can we be in two sectors?
You can, and the stricter category then applies. An entity classified as both essential and important is treated as essential, under Article 16 of the Act, and therefore faces a mandatory audit rather than a self-assessment.Do the measures differ by sector?
There are thirteen measures and they apply to every categorised entity. What differs is the level of implementation, set by the national risk assessment, and who the competent authority and CSIRT are. The exception is digital infrastructure, for which Annex III of the Regulation sets an extended set of physical security measures.Which CSIRT is ours?
For most sectors the national cyber security centre. For banking, financial market infrastructure, the top-level domain name registry, and research and the education system, it is the national CERT.What if nobody has notified us of a categorisation?
The notice is delivered by the competent authority within thirty days of the categorisation being carried out or the list being updated, under Article 19(4) of the Act. Until it arrives, the deadlines do not run for you, but that is no reason not to prepare, because the one-year clock starts on delivery.Do sectoral rules apply alongside the Act?
They do. In finance the Act sits alongside the digital operational resilience regulation, in healthcare alongside health data legislation, and in energy and transport alongside critical infrastructure rules. The first task is to separate what falls under which, so the same record is not written twice.Does the category change over time?
It does, because the list of entities is updated. On a change of category the authority sets a compliance deadline in the notice, which can be no shorter than sixty days and no longer than six months, under Article 26(6) and (7) of the Act.Are micro and small entities in scope?
In principle no, but there are exceptions that apply regardless of size: qualified trust service providers, the TLD registry and DNS providers, information intermediaries for electronic invoicing, critical entities, the public sector and the education system. Also important regardless of size are non-qualified trust service providers and providers of public electronic communications networks and services that are not essential. In addition, the authority may classify an entity under the special criteria of Article 11.Where to go next
Whatever the sector, the work is the same: measures, evidence and deadlines.
Not sure which category you fall into?
Half an hour, no obligation. We go through your activity and size and tell you what follows from it.
