Abstract blue network nodes and light trails representing the NIS2 Directive review timeline

NIS2 Review 2026: Article 40 Isn’t Due Until October 2027 — but 13 Amendments Are Already on the Table

Two different things are being called “the NIS2 review” in 2026, and they run on different clocks. The Directive’s own review clause, Article 40, gives the Commission until 17 October 2027 to report to the European Parliament and the Council on how NIS2 is working. That review has not happened yet. What did happen, on 20 January 2026, is a separate proposal — COM(2026) 13 — that would amend the Directive in thirteen places before the statutory review is even written.

Conflating them produces a planning error: entities brace for one change event when there are three, and assume the January proposal settles questions Article 40 has not yet been asked. This guide separates the tracks and flags the amendment that does more than the Commission’s own summary suggests.

The three clocks running on NIS2 right now

In plain terms: one package has already been proposed and is being negotiated; a second, earlier package overlaps with it; and the Directive’s built-in review is a third, later event with a much narrower legal mandate than either. Nothing in the first two is law yet.

Track Date Legal status What it can do
Digital Omnibus Published 19 November 2025 Proposal, in negotiation A single entry point routing incident notifications across NIS2, GDPR, DORA, eIDAS and CER; applies 18 months after entry into force, extendable to 24 [13]
Cybersecurity Package — COM(2026) 13 Presented 20 January 2026 Proposal, in negotiation (2026/0012 COD) Thirteen targeted amendments to NIS2, plus alignment with a proposed Cybersecurity Act 2 [4][6]
Article 40 review Due by 17 October 2027, then every 36 months Binding obligation on the Commission, already in force A report to Parliament and Council, “accompanied, where necessary, by a legislative proposal” [1]

The Commission’s own explanatory memorandum keeps the tracks separate. Under “monitoring, evaluation and reporting arrangements”, COM(2026) 13 states that “according to Article 40 of the NIS 2 Directive, the Commission will review the functioning of the Directive and report to the European Parliament and to the Council every 36 months” [4]. The proposal is filed as regulatory-fitness work under REFIT and traces to the Cybersecurity Act revision’s impact assessment — not to Article 40 [4]. So the review is still ahead of you, and the amendment currently on the table is not it.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

What the Article 40 review can — and cannot — change

Article 40 is short, and its narrowness is the point. It obliges the Commission to “review the functioning of this Directive” by 17 October 2027 and to report. The report “shall in particular assess the relevance of the size of the entities concerned, and the sectors, subsectors and types of entity referred to in Annexes I and II” [1]. That is a scope mandate: who is caught, at what size, in which sector. It is not a mandate to rewrite Article 21’s security measures or Article 23’s reporting deadlines.

Two inputs are named. The Commission “shall take into account the reports of the Cooperation Group and the CSIRTs network on the experience gained at a strategic and operational level” [1]. The Cooperation Group’s side of that is a standing task: Article 14(4)(r) requires it to “prepare reports for the purpose of the review referred to in Article 40 on the experience gained at a strategic level and from peer reviews” [2]. If you have ever wondered why the Cooperation Group’s output matters despite binding nobody, this is the mechanism — it is the evidence channel into a scope decision.

And the review itself changes no obligation. The report “shall be accompanied, where necessary, by a legislative proposal” [1]. “Where necessary” is the Commission’s judgement, and any proposal then has to survive Parliament and Council like any other. Article 40 is a trigger, not a lever.

What COM(2026) 13 would actually change

Thirteen numbered amendment points sit in Article 1 of the proposal. Grouped by what they do to a compliance programme:

Change Provision touched Effect if adopted
New entities in scope regardless of size Art 2(2)(a), Art 3(1)(b), Annex I point 8 Providers of European Digital Identity Wallets and European Business Wallets become essential entities [4][5]
Submarine cable infrastructure Art 6 new definition (43), Annex I point 8 Operators of submarine data transmission infrastructure captured “where they are not covered as another type of entity” — including landing stations and terrestrial runs [4][5]
Dual-use infrastructure New Art 2(3a), Art 3(1)(h) Owners, managers and operators of strategic dual-use infrastructure in scope regardless of size, tied to the proposed military-mobility Regulation [4]
Essential-tier threshold raised Art 3(1)(a) Annex I entities would be essential only where they “exceed the ceilings for small mid-cap enterprises”. A small mid-cap employs fewer than 750 people and has turnover of no more than EUR 150 million or a balance sheet total of no more than EUR 129 million — so entities inside those limits would be designated important rather than essential [4][9]
Carve-outs Annex I 1(a), 1(e), 5; Annex II 3 Electricity producers at or below 1 MW total generation capacity out; hydrogen narrowed to production, storage and transmission operators; healthcare narrowed by reference to Directive 2011/24/EU; chemicals tied to REACH registration and notification duties [5]
DNS size-cap Recital (2) The general size-cap rule applied to DNS service providers, removing micro and small providers [4]
Ransomware data Art 23 new paras 12-13 Detection, attack vector and mitigation reported as standard; on request, whether a ransom was demanded and by whom, and if paid, “what amount in what means of payment and to which recipient”, including the crypto-asset service provider [4]
Certification as evidence Art 24 new paras 4-6 Where cyber posture is certified under a Cybersecurity Act 2 scheme, authorities “shall not subject the entity to additional measures” under Art 32(2)(b) or 33(2)(b) for what the certificate covers — though it “shall not affect the responsibility” to comply [4]
ENISA in supervision New Art 37a, Art 15(2), Art 27 ENISA supports mutual assistance, must produce an annually updated cross-border risk assessment report, and may join supervisory actions on request; registration data extends to service Member States and IP ranges, with changes notified within two weeks [4]
Post-quantum cryptography Art 7(2) new point (k) National strategies must include a PQC transition policy [4]

One correction worth making, because several published summaries get it backwards: the proposal sets no PQC deadline. Article 7(2)(k) only requires Member States to take account of “the transition timelines and relevant requirements set out in applicable Union legal acts and policies” [4]. The familiar 2030 and 2035 dates come from the Cooperation Group’s PQC roadmap of June 2025, which targets completion for high-risk use cases by 31.12.2030 and medium-risk by 31.12.2035 [10]. That roadmap uses the word “shall” while binding nobody. Treat it as planning guidance, not as a statutory deadline you can be fined against.

If adopted, Member States would have twelve months from entry into force to transpose [4]. On the Commission’s figures, the clarity changes touch roughly 28,700 companies and the small mid-cap category eases the burden for around 22,500 [7].

The change nobody is flagging: Article 5’s carve-out

Article 5 is currently unqualified. It says the Directive “shall not preclude Member States from adopting or maintaining provisions ensuring a higher level of cybersecurity, provided that such provisions are consistent with Member States’ obligations laid down in Union law” [3]. That single sentence is why a group operating in six countries has spent three years reconciling six different interpretations of the same Annex.

The proposal would replace it with the same sentence prefixed by five words: “Without prejudice to Article 21(5), fifth subparagraph” [4]. That new fifth subparagraph reads: “Where the Commission adopts implementing acts referred to in the first and second subparagraphs of this paragraph, Member States shall not impose any further technical, methodological or sectoral requirements of the measures referred to in Article 21(2) … on the entities in scope of those implementing acts” [4].

Read together, they would create the first ceiling on national gold-plating written into NIS2 itself — but only where a Commission implementing act already covers the entity. Today that reaches only the entity types listed in Article 21(5)’s first subparagraph, which CIR 2024/2690 covers. The proposal also widens the second subparagraph so the Commission “may” extend implementing acts to other sectors after an “open, transparent and inclusive consultation process” [4]. The practical consequence for multi-country groups is that harmonisation now arrives sector by sector, in step with implementing acts, rather than all at once. Two caveats keep this honest: it is a proposal, not law, and it bites only inside the scope of an implementing act. Outside that scope, national variation survives untouched.

ENISA’s own evidence points the other way

Article 40 asks whether the sectors and sizes in Annexes I and II are the right ones. ENISA’s NIS360 report is the closest thing to a public answer already in circulation, and the May 2026 edition — its third, not its first — reaches a conclusion in tension with a simplification agenda [8].

NIS360 plots each sector’s criticality against its maturity and defines a “risk zone” of sectors that are “more critical for the society and economy than they are currently prepared to manage cyber risks” [8]. In the 2026 edition that zone contains health, railway, maritime, ICT service management, space, public administrations, and drinking and waste water. Rail, drinking water and waste water moved in this year; gas started moving out [8].

Set that against what COM(2026) 13 does to the Annexes. Health gets a definitional narrowing. Road gets a redefinition of ITS providers. Electricity, hydrogen, DNS and chemicals get carve-outs or tighter tests. None of the seven risk-zone sectors gets an expansion [5][8].

That is not evidence of bad faith. ENISA is explicit that the risk zone is relative: “the composition of the risk zone can change as overall maturity improves across sectors” [8]. Rail and water did not get worse — the average moved. The zone also measures sector ecosystems, not whether individual entities belong in legal scope, and ENISA’s legal notice states the report “represents the views and interpretations of ENISA” rather than any regulatory obligation [8]. Still, when the Article 40 report lands this is the dataset the Cooperation Group’s reports will be read alongside — and it argues for attention to seven sectors the January proposal largely leaves alone. Plan for scope pressure in 2027, not relief.

What to do before October 2027 — by role

Nothing in either proposal is law, so the correct posture is preparation, not implementation. What differs is what each role should prepare.

Role Do this now Why
Compliance officer / legal Re-run your scope determination against both the current Annexes and the proposed ones, and record which result each produces The essential-tier threshold and four Annex entries would move; a dated dual assessment is the cheapest way to show you tracked it
CISO / IT security manager Check whether a Commission implementing act covers your entity type, and separate controls you hold because of the Directive from controls you hold because of one national regulator The Article 5 carve-out would freeze national add-ons only inside implementing-act scope — you need to know which of your controls sit where
SME owner / small mid-cap Check headcount and financials against the 750-staff and EUR 150 million / EUR 129 million ceilings Crossing or staying under them would decide essential versus important status, which drives supervision intensity
Board / C-suite Budget for a scope re-test in 2027, not a programme rebuild Article 40 can only recommend; the realistic 2027 outcome is a scope adjustment, not a new control set

One thing not to do: pause current work. Most Member States have transposed, national enforcement has begun, and neither proposal suspends an obligation that already applies. If you are still building, the existing roadmap remains the right one.

Frequently asked questions

Has the NIS2 review happened? No. Article 40 sets the deadline at 17 October 2027, and every 36 months after that [1]. The January 2026 proposal is a separate legislative track.

Does COM(2026) 13 change my obligations today? No. It is a proposal under the ordinary legislative procedure. If adopted, Member States would get twelve months from entry into force to transpose it [4].

Can the Article 40 review remove my sector from scope? The review itself cannot change anything. It can recommend, and its report “shall be accompanied, where necessary, by a legislative proposal” [1] — which would then need to pass Parliament and Council.

Is ENISA’s NIS360 legally binding? No. ENISA states the report “represents the views and interpretations of ENISA” and does not create a regulatory obligation [8]. It is evidence that informs policy, not law.

Will the amendments end national gold-plating? Only partly, and only if adopted. The proposed limit applies where a Commission implementing act covers the entity; elsewhere Article 5 minimum harmonisation continues to apply [3][4].

The practical read

The Directive is being edited faster than it is being reviewed. Its statutory evidence base — Cooperation Group reports, CSIRTs network experience, ENISA’s sector data — is still being assembled while a separate simplification package moves through Parliament and Council. For most entities that means two scope conversations roughly eighteen months apart, and one question worth settling early: is your compliance evidence built around the Directive itself, or around one national regulator’s reading of it? The first survives both tracks. The second may not need to.

Sources

  1. NIS 2 Directive, Article 40 — Review
  2. NIS 2 Directive, Article 14 — Cooperation Group
  3. NIS 2 Directive, Article 5 — Minimum harmonisation
  4. European Commission, COM(2026) 13 final — Proposal for a Directive amending Directive (EU) 2022/2555, 20 January 2026
  5. European Commission, Annex to COM(2026) 13 final — Amendments to Annexes I and II
  6. European Commission, proposal record: simplification measures and alignment with the Cybersecurity Act
  7. European Commission, Cybersecurity Package — Questions & Answers
  8. ENISA, NIS360: maturity and criticality of NIS sectors of high criticality, May 2026 (PDF)
  9. European Commission, Annex to Recommendation (EU) 2025/1099 on the definition of small mid-cap enterprises (PDF)
  10. NIS Cooperation Group, Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography, June 2025 (PDF)
  11. EUR-Lex, Directive (EU) 2022/2555 (NIS2 Directive)
  12. European Commission, NIS2 Directive policy page
  13. Bird & Bird, Digital Omnibus package: single EU harmonised incident reporting regime

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: