
Entities are recognized as operators of essential services by way of an administrative decision issued by a competent authority for ensuring cybersecurity. An operator of essential services is an entity providing a given essential service that relies on information systems, whereas an incident, seen as an event that has or might have a negative impact on cybersecurity, would have a substantial adverse
effect on the provisions of an essential service by the said operator. An information system through which a given essential service is provided should be resilient to disruptions. If it serves the purpose of protecting services of strategic significance (including economic importance) to the state and society, it must be duly secured. Responsibilities in respect of security management within information systems are imposed on the operators of essential services.