NIS2 Targeted Amendments

← All proposals

PROPOSAL

PROPOSAL
Proposed
2026-01-20
Key date
proposed 2026-01-20
Last verified
2026-07-16

NIS2 targeted amendments — proposed

Status: PROPOSAL. Proposed 20 January 2026 as a directive amending NIS2, bundled with CSA2 in the Cybersecurity Package. Once adopted, Member States would have one year to transpose. In trilogue — verify before relying on detail.

Rather than reopen NIS2 wholesale, the Commission proposed targeted amendments to increase legal clarity and cut compliance cost, while aligning NIS2 with the new certification and single-reporting architecture.

What it would change

  • Jurisdictional clarity — refine the Art. 26 rules on which Member State has jurisdiction over multi-country entities, reducing ambiguity and duplicate supervision.
  • “Small mid-cap” (SMC) category — a new enterprise category between SME and large, to lower compliance costs for ~22,500 companies (the Commission cites ~28,700 companies benefiting from clarity overall, incl. ~6,200 micro/small).
  • Streamlined ransomware data collection — simplify how ransomware-related data is gathered from entities.
  • Stronger ENISA coordinating role — consistent with CSA2.
  • Single-entry-point alignment — wire NIS2 Art. 23 reporting into the Digital Omnibus’s Single Entry Point (a new Art. 23a establishing the SEP and ENISA’s role).
  • Certification presumption — connect to CSA2 “cyber posture certification” as proof of compliance.

Why it matters

NIS2 is still being transposed by several states; amending it mid-rollout risks a moving target. The proposal is deliberately narrow to avoid destabilising national laws already in force, while smoothing the sharpest edges (jurisdiction, SME burden, reporting duplication).

Relationship to other files

  • Amends → ../10-eu-regulations/nis2-directive.md
  • Bundled with → cybersecurity-act-2.md
  • Reporting change detailed in → digital-omnibus-sep.md

Sources