Ring of connected network nodes representing EU-level cybersecurity policy coordination under the NIS2 Cooperation Group

The NIS2 Cooperation Group Has No Power Over You — But 3 of Its 19 Tasks Under Article 14 Decide What Your Regulator Asks For

On 26 May 2026, at its 39th plenary meeting in Cyprus, a body that cannot inspect you, cannot fine you and cannot issue you a single binding instruction agreed the format of the incident report you will file after your next significant incident. That body is the NIS Cooperation Group, established by Article 14 of the NIS2 Directive, and the Commission now plans to adopt those templates “through an implementing act, making them mandatory for all Member States” [1].

Non-binding deliverable, then implementing act, then national obligation. That sequence is the only way the Cooperation Group ever reaches a regulated entity — and it is why three of its nineteen Article 14 tasks are worth tracking while the other sixteen are not.

What the Cooperation Group can and cannot do to your organisation

In plain terms: the Group has no supervisory or enforcement power over essential and important entities. Article 14 confers no power exercisable against a private organisation — what it confers is a seat in the room where the instruments that do bind you get drafted.

Common assumption What Article 14 actually provides
“It regulates entities like mine.” No. Article 14(4)(a) directs guidance “to the competent authorities” on transposition and implementation [2]. Only your national competent authority holds powers exercisable against you.
“Its guidance documents are mandatory.” No. Nothing in Article 14 makes any deliverable binding. The Commission describes the Group’s own ICT Supply Chain Security Toolbox as “a horizontal, common, and non-binding approach” [3].
“You can be penalised for ignoring its recommendations.” No. Supervision, enforcement and administrative fines run through Articles 32 to 34, against the entity, under national law. The Cooperation Group is named in fourteen of the Directive’s forty-six articles — none of them in the supervision, enforcement or penalty chapter.
“It decides which supply chains get investigated.” Partly. Article 22(1) says the Group “may carry out” coordinated assessments — but Article 22(2) leaves the choice of which ICT services, systems or products are assessed with the Commission, after consulting the Group and ENISA [4].
“So it has no effect on me at all.” Wrong in the other direction. Article 14(4)(e) puts the Group in the drafting loop for every delegated and implementing act adopted under the Directive [2].

Who sits in the room, and why your trade association is not a member

Article 14(3) is short and closed: the Group “shall be composed of representatives of Member States, the Commission and ENISA” [2]. The European External Action Service participates as an observer. The European Supervisory Authorities and the competent authorities under DORA may participate in accordance with Article 47(1) of Regulation (EU) 2022/2554 — the standing bridge between the two regimes. The Commission provides the secretariat, and the chairmanship rotates with the Presidency of the Council of the EU [5].

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Private-sector access sits in two places, both permissive. Article 14(3) allows the Group, “where appropriate”, to invite “representatives of relevant stakeholders”. Article 14(4)(o) tasks it “to organise regular joint meetings with relevant private stakeholders from across the Union” to discuss its activities and gather input [2]. Read the grammar: the Group organises, the Group invites. No company or sector body has a right to attend, to be heard, or to a response — Recital 66, an interpretive aid rather than an obligation, frames the same activity with “could” [6]. Lobbying Brussels on implementation detail is therefore not how you get heard: your Member State’s representative carries a national position into the Group, and your competent authority forms it.

The three tasks that actually reach you

Article 14(4)(e) — advice on draft delegated and implementing acts. The load-bearing one, and the Directive makes the loop explicit rather than leaving it to inference. Article 23(11) gives the Commission power to adopt implementing acts “further specifying the type of information, the format and the procedure of a notification”, then states that “the Commission shall exchange advice and cooperate with the Cooperation Group on the draft implementing acts… in accordance with Article 14(4), point (e)” [7]. That is the precise route the 26 May 2026 templates are travelling. Article 21(5) carries the identical sentence for the risk-management implementing acts [13] — which is how Implementing Regulation (EU) 2024/2690 came to set the binding technical requirements behind Article 21’s ten measures for DNS and TLD providers, cloud, data centre and CDN providers, MSPs and MSSPs, online marketplaces, search engines, social platforms and trust service providers.

Article 14(4)(a) — guidance to competent authorities. Recital 65 says the Group should “assess the impact of Cooperation Group deliverables on national approaches” and formulate recommendations “facilitating an alignment of the transposition of this Directive among Member States” [6]. That is intent, not obligation — but the operational reading is straightforward: when regulators in two Member States start asking for the same evidence in the same format, the shared position was usually agreed in the Group first.

Article 14(4)(i) with Article 22 — coordinated supply chain risk assessments. This task has precedent behind it. Recital 91 names “the EU Toolbox on 5G cybersecurity agreed by the Cooperation Group” as a source of the risk factors an assessment should weigh, technical and non-technical alike [6]. Whatever your view of how the 5G process ended, it shows the reach. In its June 2023 communication on implementation of the toolbox, the Commission recorded that “decisions to restrict or exclude certain suppliers from their 5G networks” had been taken by Member States, and stated that “decisions adopted by Member States to restrict or exclude Huawei and ZTE are justified and compliant with the 5G Toolbox” [14]. A non-binding Cooperation Group product became the yardstick against which national vendor restrictions were judged. If your sector is next, the effect lands on your supplier due-diligence file before it lands in any statute.

Three Cooperation Group outputs already sitting in your compliance file

Date Output Legal status What it changes for you
23 Jun 2025 Coordinated Implementation Roadmap for the transition to post-quantum cryptography — “the first deliverable of the NIS CG work stream on PQC” [8] Recommendation addressed to Member States Says that for high-risk use cases “quantum-vulnerable public-key mechanisms shall not be used stand-alone after the end of 2030” [8]. Your national roadmap is likely to inherit that date; Article 21(2)(h) is where it attaches.
Jun 2025 ENISA Technical Implementation Guidance on CIR 2024/2690, v1.0 (170 pp) — “developed by ENISA, in collaboration with the European Commission and the Network and Information Systems Cooperation Group” [9] Non-binding; ENISA’s own views and interpretations Its per-requirement “examples of evidence” lists are the closest thing to an EU-level audit evidence checklist for entities in the Implementing Regulation’s scope.
13 Feb 2026 EU ICT Supply Chain Security Toolbox [3] “Non-binding”; “a structured set of voluntary measures” Recommends “establishing a framework for assessment of critical suppliers, the promotion of multi-vendor strategies and overcoming the dependencies on high-risk suppliers”. The Group reviews its application after one year.

None of the three binds your organisation. All three are the material your national authority draws on when deciding what “appropriate and proportionate” looks like in a supervisory conversation — which is why reading them early is cheaper than hearing about them later.

Peer reviews are voluntary, and you may never see the report

Peer review is usually described as the mechanism that exposes weak regulators and forces them to raise their game. Article 19 is more modest than that reputation. “Participation in peer reviews is voluntary” [10] — no Member State can be compelled into one. Publication is equally discretionary: “a Member State subject to the peer review may decide to make its report, or a redacted version of it, publicly available” [10]. The reviewed state may object to particular experts on duly substantiated grounds, the same aspects cannot be re-reviewed there for two years, and the experts may not disclose sensitive or confidential information. As of August 2026 no peer review report appears to have been published — but since publication is optional, silence is not evidence that no review took place.

Where a review does land is inside the Group: reports go to it, and Article 14(4)(h) tasks it to discuss them “and draw up conclusions and recommendations” [2]. The subject matter is what makes this relevant to you — reviews may cover “the level of implementation of the cybersecurity risk-management measures and reporting obligations laid down in Articles 21 and 23”, and “the level of capabilities, including the available financial, technical and human resources” of the competent authorities [10]. A regulator told in a review that it under-resources supervision now has a budget argument, and will need a supervisory programme to spend it on. ENISA published version 2.0 of its National Cybersecurity Assessment Framework on 22 April 2026, which “supports Member States in preparing for the voluntary peer review process foreseen under Article 19 of the NIS2 Directive” [11].

What Article 19 says and what the Group built from it are two different documents. The Peer Review Methodology landed in December 2024, ahead of the 17 January 2025 deadline, and it reframes the exercise around “Learner Peers” and “Reviewer Peers” — countries that ask to be taught something, matched by ENISA against countries that already do it well. It also left the Article 19(6) code of conduct and the Article 19(8) objection procedure on a roadmap rather than delivering them, and ENISA’s first Article 18 report recorded “Not covered” against the peer-review line. For the four-phase workflow, the three discretionary gates that keep findings out of public view, and the two statutory routes by which they can still reach you, see how the NIS2 peer review mechanism actually works.

What to monitor, by role

Role What to watch Why it matters Effort
Compliance officer Plenary outputs on the Commission’s digital-strategy news feed, plus your national authority’s guidance page Outputs surface nationally well before they bind. Aligning your early-warning process to a published template early costs nothing. Low — quarterly
CISO / IT security manager ENISA evidence lists, the PQC timeline, any Article 22 assessment touching your stack These set the evidence bar and the crypto-migration clock before any national instrument does. Medium
SME owner (non-technical) Whether your sector appears in a coordinated supply-chain assessment; national guidance on the size-cap criteria Recital 20 has the Commission producing guidelines on the micro and small enterprise scope criteria “in cooperation with the Cooperation Group” [6] — the input that decides whether you are in scope at all. Low — annual
Board / C-suite The Article 40 review, and any Article 22 assessment naming a vendor you depend on Scope changes and vendor restrictions are strategic exposure, not operational detail. Low — annual

17 October 2027: the date to put in the calendar

Article 40 requires that “by 17 October 2027 and every 36 months thereafter, the Commission shall review the functioning of this Directive”. The report “shall in particular assess the relevance of the size of the entities concerned, and the sectors, subsectors and types of entity referred to in Annexes I and II”, and the Commission “shall take into account the reports of the Cooperation Group and the CSIRTs network” [12]. Article 14(4)(r) is the task that produces those reports, and the review may be accompanied by a legislative proposal.

That review is not, however, the change already in motion. On 20 January 2026 the Commission tabled COM(2026) 13, a separate proposal that would amend the Directive in thirteen places — re-tiering Annex I entities against the small mid-cap ceilings, carving electricity producers at or below 1 MW out of scope, and adding the first limit on national gold-plating written into NIS2 itself. Its own explanatory memorandum still treats the Article 40 review as a future, separate event. For how the two clocks differ, what each one can legally change and which sectors ENISA’s evidence base puts under scope pressure in 2027, see the NIS2 review and the 2026 amendments explained.

The Group’s strategic reporting is therefore an input to the one scheduled moment when the list of who is in scope — and the size thresholds that put them there — is formally reconsidered. If you are a borderline entity, or sit just under a threshold, follow it.

Key takeaways

  • The Cooperation Group has no power over entities. It advises, coordinates and publishes; your competent authority is the only body that can act on you.
  • Three of its nineteen Article 14 tasks reach you indirectly: advice on draft implementing acts (14(4)(e)), guidance to competent authorities (14(4)(a)), and coordinated supply-chain risk assessments (14(4)(i) with Article 22). Both Article 21(5) and Article 23(11) name 14(4)(e) explicitly — the route by which the 26 May 2026 templates can become a mandatory reporting format.
  • Peer reviews under Article 19 are voluntary, and the reviewed Member State decides whether the report is ever published. Do not plan around seeing one.
  • 17 October 2027 is when Cooperation Group reporting feeds a formal review of Annex I and II scope and the entity-size thresholds.

Frequently asked questions

Does the Cooperation Group publish anything an entity must comply with? No. Every deliverable is non-binding on its face. Obligations reach you through national transposition law, through Commission implementing acts such as Regulation (EU) 2024/2690, and through your competent authority’s supervisory decisions.

Can my company attend a Cooperation Group meeting? Only if invited. Article 14(3) permits the Group to invite “representatives of relevant stakeholders” where appropriate, and Article 14(4)(o) tasks it with organising joint meetings with private stakeholders — but neither creates a right of participation.

Is the Cooperation Group the same as the CSIRTs network? No. The Group is strategic and policy-facing; the CSIRTs network is operational, made up of national incident response teams. Article 14(4)(l) tasks the Group with giving strategic guidance to the CSIRTs network and EU-CyCLONe, and Article 14(6) lets it request a technical report from the network.

How often does it publish? Article 14(7) requires a work programme “by 1 February 2024 and every two years thereafter”, but deliverables land between plenaries, not on a fixed calendar. The Commission’s NIS Cooperation Group page indexes them [5].

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. NIS2 Cooperation Group adopts common templates for incident reporting — European Commission, Shaping Europe’s digital future, 26 May 2026.
  2. Directive (EU) 2022/2555, Article 14 — Cooperation Group.
  3. ICT supply chain security: EU adopts a toolbox to mitigate risks — European Commission, 13 February 2026.
  4. Directive (EU) 2022/2555, Article 22 — Union level coordinated security risk assessments of critical supply chains.
  5. NIS Cooperation Group — European Commission policy page and publications index.
  6. Directive (EU) 2022/2555, Recitals 61-70 (Recitals 64-66), together with Recitals 20, 90 and 91. Recitals are non-binding interpretive aids.
  7. Directive (EU) 2022/2555, Article 23 — Reporting obligations (see Article 23(11)).
  8. Coordinated Implementation Roadmap for the transition to Post-Quantum Cryptography — NIS Cooperation Group, 23 June 2025.
  9. Technical Implementation Guidance on Commission Implementing Regulation (EU) 2024/2690 — ENISA, June 2025, version 1.0 (PDF).
  10. Directive (EU) 2022/2555, Article 19 — Peer reviews.
  11. Assess your National Cybersecurity Capabilities and Maturity with the updated ENISA Framework — ENISA, 22 April 2026 (NCAF 2.0).
  12. Directive (EU) 2022/2555, Article 40 — Review.
  13. Directive (EU) 2022/2555, Article 21 — Cybersecurity risk-management measures (see Article 21(5) and Article 21(2)(h)).
  14. Communication from the Commission on the implementation of the 5G Cybersecurity Toolbox — European Commission, 15 June 2023.
  15. Directive (EU) 2022/2555 (NIS2) — official text, EUR-Lex.
  16. Directive (EU) 2022/2555, Article 14 — second independent text source used to verify the wording of Article 14.
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: