A Field Held Together by Five Instruments
There is no open EPSO competition dedicated to Security. What exists, and stays open on a rolling basis, is CAST Permanent — with profiles covering Security operations, Security operations including regional security, Technical security, Information and document security, and IT security. Security content also turns up inside IT and Law field-related MCQs.
The syllabus has two halves. One is institutional: Europol, Eurojust, Frontex, EU INTCEN, the Area of Freedom, Security and Justice, and the difference between CSDP civilian missions and military operations. The other is legislative: the body of EU law that now governs cybersecurity and resilience.
This guide covers the second half, in depth, because that is where the precise provisions live — deadlines measured in hours, defined categories, and instruments that deliberately overlap. The institutional half is examined too, and the official sources for it are listed at the end.
Five instruments do most of the work:
| Instrument | What it governs |
|---|---|
| Directive (EU) 2022/2555 (NIS2) | cybersecurity of network and information systems, essential and important entities |
| Directive (EU) 2022/2557 (CER) | resilience of critical entities; repealed Council Directive 2008/114/EC |
| Regulation (EU) 2019/881 (Cybersecurity Act) | ENISA's mandate and ICT cybersecurity certification; repealed Regulation (EU) No 526/2013 |
| Cyber Resilience Act | cybersecurity requirements for products with digital elements |
| DORA | digital operational resilience of financial entities, and oversight of critical ICT third-party providers |
For how field-related MCQs are structured across specialist tracks, see our guide to the EPSO specialist competitions FRMCQ. The IT track overlaps heavily — our IT specialist guide covers the digital regulatory framework from the other side.
The Format
30 questions in 40 minutes, 15 correct to pass. Under the current EPSO model the field-related MCQ is the ranking instrument; reasoning tests are pass-or-fail gates that do not feed your final score.
NIS2 — Directive (EU) 2022/2555
Adopted 14 December 2022, published in OJ L 333 of 27 December 2022.
Who Is Covered
Coverage is built from several routes, and questions test whether you know there is more than one:
- entities of a type referred to in Annex I or Annex II meeting the criteria;
- other entities of those types identified by a Member State as essential entities under the identification provisions;
- entities identified as critical entities under Directive (EU) 2022/2557;
- if the Member State so provides, entities it identified before 16 January 2023 as operators of essential services under Directive (EU) 2016/1148 or national law.
That last route is a transitional bridge from the first NIS Directive, and the date is specific enough to be a question on its own.
The Two Deadlines
Where essential or important entities become aware of a significant incident, they submit to the CSIRT or, where applicable, the competent authority:
- within 24 hours of becoming aware — an early warning, indicating where applicable whether the incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact;
- within 72 hours of becoming aware — an incident notification, updating the early warning and giving an initial assessment of the incident.
Both are qualified by "without undue delay and in any event within". The 24-hour step is a warning, not a report — its content is deliberately thin, because its job is speed. Conflating the two is the standard error.
Where an incident is suspected of relating to serious criminal activities, Member States should encourage entities to report it to the relevant law enforcement authorities, on the basis of applicable criminal proceedings rules and without prejudice to personal data protection rules.
EU-CyCLONe
The European cyber crisis liaison organisation network is composed of representatives of Member States' cyber crisis management authorities, and — in cases where a potential or ongoing large-scale cybersecurity incident has or is likely to have a significant impact on services and activities within the Directive's scope — the Commission. In other cases the Commission participates as an observer.
ENISA provides the secretariat of EU-CyCLONe, supports the secure exchange of information, and provides the tools to support cooperation.
Full participant when it is big, observer when it is not. That conditional is exactly the kind of detail that separates a prepared candidate from a well-read one.
ENISA's Reporting and Database Roles
ENISA establishes a European vulnerability database, where entities — regardless of whether they fall within the scope of the Directive — and their suppliers may register publicly known vulnerabilities. Access to correct and timely vulnerability information serves entities, their users, competent authorities and CSIRTs alike.
ENISA also adopts, in cooperation with the Cooperation Group, a report on the state of cybersecurity in the Union, including an assessment of the general level of cybersecurity awareness and cyber hygiene among citizens and entities including SMEs; an aggregated assessment of the outcome of the peer reviews; and an aggregated assessment of the maturity of cybersecurity capabilities and resources across the Union, including at sector level, and of how far national cybersecurity strategies are aligned. The report includes particular policy recommendations.
Third Countries
The Union may, where appropriate, conclude international agreements in accordance with Article 218 TFEU with third countries or international organisations, allowing and organising their participation in particular activities of the Cooperation Group, the CSIRTs network and EU-CyCLONe. Such agreements shall comply with Union data protection law.
Standards
To promote convergent implementation of the risk-management measures, Member States encourage the use of European and international standards — without imposing or discriminating in favour of the use of a particular type of technology. Technology neutrality is written into the encouragement.
Where no appropriate European cybersecurity certification scheme is available for the purposes of the relevant provision, the Commission may — after consulting the Cooperation Group and the European Cybersecurity Certification Group — request ENISA to prepare a candidate scheme under Article 48(2) of Regulation (EU) 2019/881.
The Cybersecurity Act — Regulation (EU) 2019/881
Of 17 April 2019, on ENISA and on ICT cybersecurity certification, repealing Regulation (EU) No 526/2013, published in OJ L 151 of 7 June 2019.
It establishes a voluntary European cybersecurity certification framework for ICT products, ICT processes and ICT services. European schemes provide a common framework of trust for users.
Voluntary is the word to underline. A great deal of exam value sits in resisting the assumption that an EU certification framework must be compulsory. What the framework does is create presumptions and common criteria — not an obligation to certify.
National cybersecurity certification authorities are designated under Article 58. Candidate schemes are prepared by ENISA under Article 48(2) at the Commission's request.
The Cyber Resilience Act — Products With Digital Elements
The Cyber Resilience Act builds directly on the Cybersecurity Act, and the interlock is examinable.
Products with digital elements, and processes put in place by the manufacturer, for which an EU statement of conformity or certificate has been issued under a European cybersecurity certification scheme adopted pursuant to Regulation (EU) 2019/881, are presumed to conform to the essential cybersecurity requirements set out in Annex I — in so far as that statement or certificate, or parts of it, cover those requirements.
A presumption, and a partial one. Certification does not discharge the obligation wholesale; it discharges it to the extent of what was actually certified.
Market surveillance authorities cooperate with the national cybersecurity certification authorities designated under Article 58 of Regulation (EU) 2019/881 and exchange information regularly. For supervision of the reporting obligations, they cooperate and exchange information with the CSIRTs designated as coordinators and with ENISA, and may request a designated CSIRT to assist.
ENISA's role here is proactive: it may propose joint activities to be conducted by market surveillance authorities based on indications of potential non-compliance across several Member States, or identify categories of products for which sweeps should be organised. In exceptional circumstances, at the Commission's request, ENISA may conduct evaluations in respect of specific products.
When establishing the single reporting platform, ENISA should consult other Union institutions or agencies managing platforms or databases subject to stringent security requirements — eu-LISA, the agency for large-scale IT systems in the Area of Freedom, Security and Justice, is named — and analyse complementarities with the European vulnerability database.
CER — Directive (EU) 2022/2557
Of 14 December 2022, on the resilience of critical entities, repealing Council Directive 2008/114/EC.
The relationship with NIS2 is the examinable part. Where competent authorities under NIS2 exercise their supervisory and enforcement powers to ensure compliance of an entity identified as a critical entity under CER, they inform the relevant CER authorities within the same Member State. Where appropriate, CER authorities may request NIS2 authorities to exercise their supervisory and enforcement powers in relation to such an entity.
To streamline supervision and minimise administrative burden, the two sets of competent authorities should endeavour to harmonise incident notification templates and supervisory processes.
The division of labour: NIS2 governs cyber resilience, CER governs physical resilience, and an entity can be both. The Directives are built to hand work to each other rather than duplicate it.
DORA — Financial Entities
DORA addresses the digital operational resilience of financial entities, and its distinctive feature is the Oversight Framework for ICT third-party providers.
Scope. The Oversight Framework applies only to critical ICT third-party service providers. A designation mechanism accounts for the dimension and nature of the financial sector's reliance on such providers, using quantitative and qualitative criteria setting the criticality parameters — assessed regardless of the provider's corporate structure.
The Lead Overseer. The Framework depends on collaboration between the Lead Overseer and the critical provider, and on the Lead Overseer's ability to conduct monitoring missions and inspections assessing the rules, controls and processes used, and the potential cumulative impact of the provider's activities.
What it does not do. The Framework does not replace or substitute for financial entities' own obligation to manage the risks of using ICT third-party providers, including ongoing monitoring of contractual arrangements with critical providers. Nor does it affect their full responsibility for complying with their own legal obligations. And it is without prejudice to Member States' competence to conduct their own oversight of providers not designated as critical but regarded as important at national level.
Coordination. The Joint Committee of the ESAs continues to ensure overall cross-sectoral coordination on all matters pertaining to ICT risk.
Consolidation. DORA, together with Directive (EU) 2022/2556, consolidates ICT risk-management provisions across the financial services acquis, amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 to clarify the applicable rules.
Physical resilience. Because the physical resilience of financial entities is addressed comprehensively by DORA's ICT risk-management and reporting obligations, the obligations in Chapters III and IV of the CER Directive are handled coherently with it rather than layered on top.
Five Places Candidates Lose Marks
24 versus 72. Early warning in 24 hours, incident notification in 72. Both "without undue delay and in any event within". Different documents, different purposes.
Voluntary certification. The European cybersecurity certification framework is voluntary. Certification creates presumptions of conformity, and only to the extent of what it covers.
Full participant versus observer. The Commission sits in EU-CyCLONe as a full member only for large-scale incidents with significant impact; otherwise as an observer. ENISA is the secretariat, not a member state authority.
Which instrument applies. Network and information systems, physical critical-entity resilience, products with digital elements, financial entities. Four instruments, four scopes, deliberate overlaps, and cross-referral duties rather than duplication.
Oversight does not transfer responsibility. Designating a provider as critical and overseeing it does not relieve the financial entity of managing that risk itself. The Regulation says so explicitly, and a question can be built entirely on candidates assuming the opposite.
How to Study This Field
Read NIS2 first — the definitions, the scope provisions, the risk-management measures and the reporting article. It is the anchor instrument, and the other three cyber texts define themselves against it.
Then read the interlock provisions rather than the whole of CER, the Cyber Resilience Act and DORA. The examinable content is where they touch: presumption of conformity, cross-informing between competent authorities, the boundary of the Oversight Framework.
Then cover the institutional half separately — the founding regulations of Europol, Eurojust and the European Border and Coast Guard Agency, and the EEAS material on CSDP civilian missions and military operations. That half is not covered here, and it is examined.
Then practise under time. Eighty seconds per question is what turns five instruments into marks. You can drill the security block on EU-now in short sessions, and ask EUgenio when two instruments seem to say the same thing — it answers from the same official texts cited here, and says when it has no source rather than inventing one.
References and Sources
All quotations in this article come from official EU sources:
- Directive (EU) 2022/2555 — NIS2 (OJ L 333, 27.12.2022)
- Directive (EU) 2022/2557 — resilience of critical entities
- Regulation (EU) 2019/881 — Cybersecurity Act (OJ L 151, 7.6.2019)
- Regulation (EU) 2022/2554 — DORA
- ENISA — European Union Agency for Cybersecurity
- Europol
- EEAS — Security and Defence
Where this article describes what a question is likely to test, that is our editorial judgement based on the format of published field-related MCQs — not text from any Notice of Competition. The provisions, deadlines and definitions are quoted from the instruments listed above.
Get the free EPSO AD reasoning mock test
A realistic practice PDF — verbal, numerical and abstract reasoning. Enter your email and we send it right away.
Free. No spam. Unsubscribe anytime.



