The Network and Information Systems (Amendment) Regulations 2018

Type Statutory-Instrument
Publication 2018-05-23
State In force
Department King's Printer of Acts of Parliament
PDF Download
articles Not indexed
Reform history JSON API

Made: 23rd May 2018

Laid before Parliament: 24th May 2018

Coming into force: 20th June 2018

The Secretary of State makes the following Regulations in exercise of the powers conferred by section 2(2) of, and paragraph 1A[^f00003] of Schedule 2 to, the 1972 Act.

Citation and commencement

1

These Regulations may be cited as the Network and Information Systems (Amendment) Regulations 2018 and come into force on 20th June 2018.

Amendment of the Network and Information Systems Regulations 2018

2

(a) an Article, Annex or paragraph of an Article or Annex is a reference to the Article, Annex or paragraph as numbered in Directive 2016/1148.

(a) “a material contravention” means— (i) a failure to take steps, or any adequate steps, within the stipulated time period to rectify a failing that is described in regulation 17(1)(a) to (d) or (2)(a) to (d); or (ii) where no steps were required to be taken, a failing that is described in regulation 17(1)(a) to (d) or (2)(a) to (d);

(3) Section 30(3) of the Small Business, Enterprise and Employment Act 2015[^f00005] requires that a review carried out under this regulation must, so far as is reasonable, have regard to how Directive 2016/1148[^f00006] is implemented in other Member States. (4) Section 30(4) of that Act requires that reports published under this regulation must, in particular— (a) set out the objectives intended to be achieved by the regulatory provision referred to in paragraph (1)(a); (b) assess the extent to which those objectives are achieved; (c) assess whether those objectives remain appropriate; and (d) if those objectives remain appropriate, assess the extent to which they could be achieved in another way which involves less onerous regulatory provision. (5) In this regulation “regulatory provision” has the same meaning as in sections 28 to 32 of that Act.

Signed

Margot James — Minister for Digital and the Creative Industries — Department for Digital, Culture, Media and Sport — 23rd May 2018

Explanatory note

(This note is not part of the Regulations)

EXPLANATORY NOTE

The Network and Information Services Regulations 2018 (S.I. 2018/506, the “2018 Regulations”) implement Directive (EU) 2016/1148 of the European Parliament and of the Council concerning measures for a high common level of security of network and information systems across the European Union (OJ L 194, 19.7.2016, p. 1).

These Regulations amend the 2018 Regulations so as to correct a number of defects and errors.

An impact assessment for the 2018 Regulations has been produced by the Department for Digital, Culture, Media and Sport, and is published alongside that instrument on www.legislation.gov.uk. These Regulations do not affect the costs as set out in that impact assessment.

The Directive referred to above is published at http://eur-lex.europa.eu.

Footnotes

[^f00001]: S.I. 2001/3495. See article 2 of, and Schedule 1, to these Regulations. There are amendments not relevant to these Regulations.

[^f00002]: 1972 c. 68. Section 2(2) was amended by section 27(1)(a) of the Legislative and Regulatory Reform Act 2006 (c. 51) and by Part 1 of the Schedule to the European Union (Amendment) Act 2008 (c. 7). In so far as these Regulations deal with matters that are within the devolved competence of Scottish Ministers, the power of the Secretary of State to make regulations in relation to those matters in or as regards Scotland is preserved by section 57(1) of the Scotland Act 1998 (c. 46).

[^f00003]: Paragraph 1A of Schedule 2 was inserted by section 28 of the Legislative and Regulatory Reform Act 2006, and amended by Part 1 of the Schedule to the European Union (Amendment) Act 2008, and by article 3 of, and paragraph 1 to, Schedule 1 to S.I. 2007/1388.

[^f00004]: S.I. 2018/506.

[^f00005]: 2015 c. 26.

[^f00006]: Directive 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union, OJ No. L 194, 19.7.2016, p. 1.

Reading this document does not replace reading the official text published on legislation.gov.uk. Contains public sector information licensed under the Open Government Licence v3.0. We assume no responsibility for any inaccuracies arising from the conversion of the original CLML XML to this format.

This text is published under legislation.gov.uk's own terms of reuse, not a Legalize or public-domain licence. legislation.gov.uk
Open Government Licence v3.0 (attribution required)
© Crown and database right. Derived from content available under the Open Government Licence v3.0 from legislation.gov.uk.