Retained EU Law SI 2018/151 United Kingdom

Commission Implementing Regulation (EU) 2018/151 of 30 January 2018 laying down rules for application of Directive (EU) 2016/1148 of the European Parliament and of the Council as regards further specification of the elements to be taken into account by RDSPs for managing the risks posed to the security of network and information systems and of the parameters for determining whether an incident has a substantial impact

Status
In Force
Penalty ceiling
Regulated

Does it bind you?

Business-side roles with duties under this instrument.

Any Person1 Operator1

Other Acts binding the same actors

If a role above is yours, these are the other instruments that most often bind it.

Any Person — also bound by 2340 other Acts
Operator — also bound by 746 other Acts

What it requires

Regulations creating concrete business duties or carrying penalties, grouped as the instrument is structured. Titles link to the source text — blue means you’re leaving for legislation.gov.uk.

s.art002 Security elements Regulated
  • Manage security of network and information systems in line with NIS RegulationsOperator
s.art003 Parameters to be taken into account to determine whether the impact of an incident is substantial Regulated
  • Be able to estimate impact of security incidentsAny Person
4 other provisions — procedural and definitional
s.art001 Subject matter
s.art001 Interpretation
s.art004 Substantial impact of an incident
s.art005 Entry into force

Duty extraction and severity labels are Guvnor’s analysis of the instrument, not the instrument itself. Always verify against the linked source text.