A high common level of cybersecurity
The Directive asks Member States to regulate the entities whose services matter to society and the economy: risk management (Article 21), incident reporting (Article 23), registration and supervision by a national authority. Member States had to establish the list of essential and important entities by 17 April 2025 and review it at least every two years (Article 3(3)).