NIS2 Targeted Amendments
← All proposals
NIS2 targeted amendments — proposed
Status: PROPOSAL. Proposed 20 January 2026 as a directive amending NIS2, bundled with CSA2 in the Cybersecurity Package. Once adopted, Member States would have one year to transpose. In trilogue — verify before relying on detail.
Rather than reopen NIS2 wholesale, the Commission proposed targeted amendments to increase legal clarity and cut compliance cost, while aligning NIS2 with the new certification and single-reporting architecture.
What it would change
- Jurisdictional clarity — refine the Art. 26 rules on which Member State has jurisdiction over multi-country entities, reducing ambiguity and duplicate supervision.
- “Small mid-cap” (SMC) category — a new enterprise category between SME and large, to lower compliance costs for ~22,500 companies (the Commission cites ~28,700 companies benefiting from clarity overall, incl. ~6,200 micro/small).
- Streamlined ransomware data collection — simplify how ransomware-related data is gathered from entities.
- Stronger ENISA coordinating role — consistent with CSA2.
- Single-entry-point alignment — wire NIS2 Art. 23 reporting into the Digital Omnibus’s Single Entry Point (a new Art. 23a establishing the SEP and ENISA’s role).
- Certification presumption — connect to CSA2 “cyber posture certification” as proof of compliance.
Why it matters
NIS2 is still being transposed by several states; amending it mid-rollout risks a moving target. The proposal is deliberately narrow to avoid destabilising national laws already in force, while smoothing the sharpest edges (jurisdiction, SME burden, reporting duplication).
Relationship to other files
- Amends →
../10-eu-regulations/nis2-directive.md - Bundled with →
cybersecurity-act-2.md - Reporting change detailed in →
digital-omnibus-sep.md
Sources
- Commission cybersecurity policy hub: https://digital-strategy.ec.europa.eu/en/policies/cybersecurity
- NIS2 targeted-amendments proposal (Package documents): see the Commission library entry for the January-2026 Cybersecurity Package. ⚠️ VERIFY direct link.