To demonstrate compliance with certain obligations, the competent national authority, NIS, may impose organizations to use categories of ICT products, ICT services, and ICT processes developed by essential or important entities or purchased from third parties, provided they are certified under the European cybersecurity certification systems.
The competent national authority, NIS, also promotes the use of qualified trust services by organizations.