Reference
Glossary
Terms and acronyms used across the EU cyber rulebook and this site.
Glossary
Legal machinery
- Regulation — EU law applying directly and identically in all Member States (GDPR, DORA, CRA).
- Directive — EU law setting objectives; each Member State must transpose it (NIS2, CER).
- Transposition — turning a directive into national law by its deadline.
- Delegated / Implementing act — secondary Commission legislation filling in technical detail (NIS2 Impl. Reg. 2024/2690; RED Delegated Reg. 2022/30).
- Lex specialis — “specific law beats general law”: a sector act (DORA) displaces a general one (NIS2) on the same matter.
- CELEX number — unique EUR-Lex identifier of a legal act (32022L2555 = NIS2).
- Trilogue — Commission/Parliament/Council negotiation to finalise a text.
- Infringement procedure — Commission enforcement against a state: letter of formal notice → reasoned opinion → referral to the CJEU.
- Vacatio legis — gap between a law’s publication and entry into force.
Core NIS2 / CER concepts
- Essential vs Important entity — the two NIS2 categories; essential entities face proactive supervision and higher fines (€10M/2% vs €7M/1.4%).
- Significant incident — NIS2 reporting trigger (severe disruption, financial loss, or considerable damage to others).
- 24/72/one-month cascade — NIS2 reporting rhythm: 24h early warning, 72h notification, one-month final report.
- Main establishment — NIS2 Art. 26: the Member State where cyber risk-management decisions are predominantly taken; sets the primary competent authority.
- CSIRT — Computer Security Incident Response Team; each state designates one or more, networked at EU level.
- Critical entity — the CER Directive’s category, focused on physical/all-hazards resilience.
Product & certification concepts
- Product with digital elements (PDE) — CRA term: any hardware/software with a data connection, plus its remote data processing.
- Security by design / by default — build security in from conception (CRA Annex I), not patch it on later.
- Support period — CRA duty to provide security updates, in principle ≥ 5 years.
- CE marking — manufacturer’s declaration a product meets EU requirements; CRA adds cybersecurity to it.
- ECCF — European Cybersecurity Certification Framework (Cybersecurity Act); voluntary schemes at basic / substantial / high assurance.
- EUCC / EUCS / EU5G — first schemes: ICT products (adopted), cloud (draft), 5G (draft).
- Cyber posture certification — CSA2 proposal: certifying an organisation’s overall NIS2 compliance, not just a product.
- SBOM — Software Bill of Materials; inventory of components (CRA vulnerability-handling requirement).
Financial sector (DORA)
- ICT third-party risk — DORA pillar governing outsourcing to tech providers.
- CTPP — Critical ICT Third-Party Provider (e.g. hyperscale cloud) under direct ESA oversight.
- TLPT — Threat-Led Penetration Testing; ≥ every 3 years for significant entities (TIBER-EU aligned).
- Register of Information — mandatory inventory of all ICT contractual arrangements.
- ESAs — the three European Supervisory Authorities: EBA (banking), ESMA (markets), EIOPA (insurance/pensions).
Institutions & networks
- ENISA — EU Agency for Cybersecurity; technical hub, certification scheme manager, future SEP operator.
- CSIRTs Network / EU-CyCLONe — EU operational cooperation (technical level / crisis-liaison level).
- NIS Cooperation Group — strategic cooperation body (Member States, Commission, ENISA).
- ECCG — European Cybersecurity Certification Group (national certification authorities).
- National competent authority — the body a state designates to supervise NIS2/CER entities (ACN Italy, BSI Germany, ANSSI France, CCB Belgium…).
The 2026 reform vocabulary
- Cybersecurity Package (2026) — CSA2 proposal + targeted NIS2 amendments (20 Jan 2026).
- CSA2 — proposed revised Cybersecurity Act (COM(2026) 11).
- Digital Omnibus — Nov-2025 simplification package amending several digital laws at once.
- SEP — Single Entry Point — proposed ENISA-run platform: one report satisfying NIS2/GDPR/DORA/CER/eIDAS/CRA (“report once, share many”).
- High-risk supplier — CSA2 concept: suppliers restricted/excluded on technical and non-technical risk (e.g. third-country influence).
- Small mid-cap (SMC) — new enterprise category in the NIS2 amendment proposal, to lower compliance costs.