NIS2 Peer Review: Member States Volunteer Themselves, Shape the Scope, and ENISA’s First Report Marked It ‘Not Covered’
Article 19 of the NIS2 Directive creates no obligation for any essential or important entity. No registration, no evidence pack, no deadline. It binds Member States — and only the ones that put their own hand up.
That distinction matters, because peer review is routinely described as the mechanism that will expose weak regulators and shame national authorities into raising their standards. The instrument the Cooperation Group actually built does close to the opposite. Its own text calls the goal “a collaborative and non-judgemental space for mutual learning”, and the country under review controls what leaves the room [2]. Most write-ups of Article 19 paraphrase the Directive’s nine paragraphs and stop; this one reads the document those paragraphs produced.
Does Article 19 apply to you?
In one line: not directly, and not at all as a duty. Here is who Article 19 actually reaches.
| Who | What Article 19 asks of them | Binding? |
|---|---|---|
| Essential and important entities | Nothing. No filing, no evidence, no deadline, no cost. Article 19 is not addressed to regulated entities at any point. | No obligation |
| Member State / competent authority | May ask to be reviewed or to supply experts. If reviewed, it must give the experts the information needed for the assessment, subject to national-security and classified-information limits (Art 19(6)), and must disclose any conflict of interest affecting designated experts (Art 19(8)) [1]. | Voluntary to enter; binding once inside |
| National CSIRT | Article 10(5), verbatim: “The CSIRTs shall participate in peer reviews organised in accordance with Article 19.” [7] | Binding, once a review is organised |
| Cooperation Group | Article 14(4)(q): establish the methodology, lay down the self-assessment methodology, and develop codes of conduct for the experts. Article 14(4)(h): discuss the resulting reports and draw up conclusions [5]. | Binding task |
| Commission and ENISA | Assist with the methodology (Art 19(1)); participate in the reviews as observers (Art 19(2)) [1]. | Binding task |
Two of those rows sit in tension. Article 19(1) says flatly that “Participation in peer reviews is voluntary”; Article 10(5) says the CSIRTs “shall” participate. The discretion belongs to the Member State at the moment it decides whether a review happens — once one is organised, the national CSIRT you report incidents to has no opt-out.
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
What the Cooperation Group actually delivered
Article 19(1) gave the Cooperation Group a hard date: 17 January 2025, to establish “the methodology and organisational aspects of peer reviews” [1]. It landed early. The Peer Review Methodology is dated December 2024, runs to 21 pages, and is listed among the Group’s publications on the Commission’s own NIS Cooperation Group page [2][3]. The file still carries a TLP:AMBER marking from its drafting, which explains its register: it reads as an internal working document, not public guidance.
The first thing it does is invent vocabulary the Directive never uses. Article 19 knows only “cybersecurity experts” and “the Member State being reviewed”. The methodology adds Learner Peers, Member States “that wish to improve a specific area”, and Reviewer Peers, those “that excel in a specific area and could bring expertise and good practices” [2]. That is a mentoring relationship, not an audit one, and the naming makes the design intent explicit.
The process runs in four phases:
| Phase | What happens | Who decides |
|---|---|---|
| 1. Initiation | Step 1.0 (optional): the Member State self-assesses. Step 1.1: it submits an expression of interest naming the area it wants to improve. | The Member State alone |
| 2. Preparation | ENISA matches Learner with Reviewer Peers; scope is agreed; experts are appointed; on-site or virtual format and timeline are settled. | Participating Member States |
| 3. Execution | Visits and off-site information exchange; experts validate what the Learner Peer has provided and write recommendations. | Experts, with Commission and ENISA observing |
| 4. Documentation | Step 4.1: an internal report whose “distribution will be limited to the peers of the peer review”. Step 4.2: a closure session, then a “sharable extract” goes to the Cooperation Group. | The reviewed Member State |
Note where phase 1 starts: nobody nominates anybody. A Member State writes to ENISA — named in the methodology as “secretariat of Workstream on Peer Reviews and National Cybersecurity Strategies” — naming which of the six Article 19(1) areas it wants help with [2]. No Member State, and neither the Commission nor the Cooperation Group, can put an unwilling country under review. The regulator with the weakest supervisory record is precisely the one that never files an expression of interest.
Why peer review will not create competitive pressure
The popular theory is that published findings will embarrass laggards into improving. Three separate discretionary gates stand between a peer review and anything a citizen, a journalist, or a compliance officer can read — and the reviewed Member State holds all three.
- Whether it happens at all. Article 19(1): participation is voluntary, and initiation is by expression of interest [1][2].
- What leaves the review. The full report’s distribution is limited to the peers involved. What reaches the wider Cooperation Group is a “sharable extract”, and the methodology is explicit that “Learner Peers will be able to decide on the information to be shared”, “excluding any confidential or specific information regarding the subjects of the peer review” [2].
- Whether the public ever sees it. Article 19(9): the reviewed Member State “may decide to make its report, or a redacted version of it, publicly available” [1]. May. Redacted. Its choice.
There is also an empirical check available, and it points the same way. The one place peer review output is supposed to surface publicly is ENISA’s biennial Report on the State of Cybersecurity in the Union. In the first edition, December 2024, the row for Article 18(1)(d) reads: “Not covered as the peer review mechanism had not been implemented as of the drafting of the report but will be included in future versions of the report” [4].
That same report carries the EU Cybersecurity Index, built under Article 18(3) as the Union’s maturity yardstick. Its 2024 value is 62.65 out of 100, with an average Member State deviation from that mean of 3.76 points, a maximum of +7.45 and a minimum of −13.18 [4]. Those are the only comparative figures published, and the report names no Member State against any of them: search all 71 pages for Germany, France, Poland, Spain, Italy or the Netherlands and no country is attached to a score. There is no league table for a laggard to fall down, which is why “competitive pressure” is the wrong model for Article 19.
The report is specific about which domains diverge most: vulnerability disclosure and “supervisory measures for essential and important entities”, alongside R&D and education, show average deviations of 25 index points or more [4]. Supervision of entities like yours is, on the Union’s own measure, among the least consistent things in the EU — worth bearing in mind when comparing how supervisory regimes are run from one Member State to the next.
The two routes by which a peer review can reach you
Peer review is not a dead end for regulated entities. It has exactly two statutory exits, both named in the Directive by article number, and neither is publication.
Route 1 — Article 18(1)(d). ENISA must include “an aggregated assessment of the outcome of the peer reviews referred to in Article 19” in its biennial state-of-cybersecurity report [6]. Aggregated, so no country is identified, but the findings feed the report’s policy recommendations. The 2024 edition left that line empty; on a two-year cycle, the 2026 edition — not yet published as of late August 2026 — is the first that could carry anything. That is the artefact to diarise.
Route 2 — Article 14(4)(r) into Article 40. The Cooperation Group must “prepare reports for the purpose of the review referred to in Article 40 on the experience gained at a strategic level and from peer reviews” [5]. Article 40 requires the Commission, by 17 October 2027 and every 36 months after, to review how the Directive is functioning, report to the Parliament and Council, and where necessary attach a legislative proposal [8]. This is the only channel that can change what your organisation must actually do — and a slow one: findings feed a review, which may propose an amendment, which would then need transposing.
One detail sharpens why this matters. Of the six reviewable areas, Article 19(1)(a) is “the level of implementation of the cybersecurity risk-management measures and reporting obligations laid down in Articles 21 and 23” [1]. A review under that heading examines how well entities in that country have implemented the Article 21 measures, and therefore how effectively the authority has supervised them. If a regulator comes out of that with a recommendation to tighten supervision, entities feel it as inspection intensity, not as a new rule.
What the methodology left unfinished
Article 19 asks the Cooperation Group for four things. The December 2024 document delivers one outright and defers the rest to a roadmap in its own Annex 1, which describes the text as “the first definition of the peer review methodology, which is initially formulated conceptually” [2].
| What the Directive requires | What the methodology does with it | Public status, 24 August 2026 |
|---|---|---|
| Art 19(1): methodology and organisational aspects, by 17 January 2025 | Delivered: four phases, three roles, division of labour between ENISA and the Group | Published, still at version 1.1 (December 2024) |
| Art 19(2): “objective, non-discriminatory, fair and transparent criteria” for designating experts | Annex 2 offers indicative guidance and points to ISO 19011:2018 and ISO/IEC 27007:2020; a purpose-built competence model is listed as future work | Criteria not settled; deferred in Annex 1 |
| Art 19(5): self-assessment methodology (also Art 14(4)(q)) | Treated as an optional Step 1.0; the document suggests the EU Cybersecurity Index and SIM3 as reference points rather than laying down a methodology | No self-assessment methodology on the Commission’s Cooperation Group publications page |
| Art 19(6): codes of conduct for designated experts | Explicitly out of scope — “Once the peer review code of conduct is established, it will be referenced in this document”. Annex 3 supplies source material: ENISA’s ISAC code-of-conduct template and the ISACA Code of Professional Ethics | No code of conduct listed on that page |
| Art 19(8): disclosure of expert conflicts of interest and the right to object | Restated from the Directive; Annex 1 lists “definition of official process to declare conflict of interest or object to experts’ designation” as an activity still to be done | No published procedure |
A calibration note, because it changes what you can conclude: “not on the publications page” is not “does not exist”. The methodology itself was drafted TLP:AMBER, so a code of conduct and a self-assessment methodology may well circulate among Member States without being posted publicly. What can be said confidently is that a compliance reader in August 2026 cannot obtain them, and that the Group’s own roadmap listed them as open when it published.
The closest public instrument arrived separately: ENISA’s National Capabilities Assessment Framework 2.0, published 22 April 2026 with an online tool, which “supports Member States in preparing for the voluntary peer review process foreseen under Article 19 of the NIS2 Directive” [10]. It is a preparation aid for governments, not the Article 19(5) methodology, and not something an entity is expected to use.
One practical warning while you are in this material: the methodology contains at least two internal citation slips. Page 8 attributes the voluntariness of participation to “Article 19(2)” when that sentence sits in Article 19(1), and a footnote on the same page attributes ENISA’s duty to assist the Cooperation Group to “Art 10”, which mentions peer review only at 10(5), and only to bind CSIRTs [1][2][7]. Official provenance is not a substitute for checking the article number yourself.
What to do with this, by role
| Role | What changes | The one thing to track |
|---|---|---|
| Compliance officer | Nothing. Record Article 19 in the regulatory register as monitored, not applicable: no control, no evidence, no deadline. | The 2026 edition of ENISA’s Article 18 report — the first that can carry peer review output — not a report you will probably never see. |
| CISO / IT security manager | No change to the control set. A regulator volunteering under Article 19(1)(b) is asking outsiders to assess its own resources and effectiveness. | Inspection intensity. Recommendations of that kind arrive downstream as more frequent or more detailed supervisory contact. |
| Board / C-suite | No budget line, no liability exposure, no reporting duty. | 17 October 2027 — the Article 40 review, whose required inputs include peer review experience. |
None of that requires new legislation to bite, which is why it is worth knowing what your national competent authority can already do today. The shape is familiar from the rest of NIS2’s institutional layer: the bodies that coordinate are kept apart from the bodies that enforce. Article 19 sits with the Cooperation Group, which is named in none of Articles 31 to 37 — the supervision, enforcement and penalty provisions.
Frequently asked questions
Can my company request a peer review of our national regulator?
No. Article 19(1) puts participation in the hands of Member States, and Step 1.1 of the methodology routes expressions of interest from Member States to ENISA as workstream secretariat [1][2]. There is no petition route for entities, associations or the public.
Can I read a peer review report?
Only if the reviewed Member State chooses to publish it, in full or redacted, under Article 19(9) [1]. None appears to have been published as of August 2026 — but because publication is optional, that silence is not evidence that no review has taken place.
If a country gets a poor peer review, do entities there face fines?
No. Neither “peer review” nor “Cooperation Group” appears anywhere in Articles 31 to 37, the Directive’s supervision, enforcement and penalties provisions [1]. Article 19(6) also limits the material: “Any information obtained through the peer review shall be used solely for that purpose”, which is a purpose limitation, not a route into an enforcement file. Findings reach you only indirectly, through supervisory behaviour or the Article 40 route. See how NIS2 penalties are actually triggered.
Is this the same as the CSIRTs Network peer review?
No, and the Directive anticipates the overlap. Recital 75 — interpretive, not binding — states that peer reviews “should take account of the results of similar mechanisms, such as the peer-review system of the CSIRTs network, and should add value and avoid duplication” [9]. Where a review covers CSIRT operational capabilities under Article 19(1)(c), the methodology directs experts to build on the CSIRTs Network maturity work rather than repeat it [2].
Has the two-year cooling-off period bitten yet?
Not observably. Article 19(7) blocks a repeat review of the same aspects in the same Member State for two years after conclusion, unless that state requests it or the Cooperation Group proposes otherwise [1]. With no publicly concluded review on record, the clock is not visibly running anywhere.
This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.
Sources
- Directive (EU) 2022/2555, Article 19 (Peer reviews) — full text: nis-2-directive.com/NIS_2_Directive_Article_19.html
- NIS Cooperation Group, Peer Review Methodology, Final v1.1, December 2024 (21 pp.) — linked inline above
- European Commission, NIS Cooperation Group publications — linked inline above
- ENISA, 2024 Report on the State of the Cybersecurity in the Union, December 2024 — linked inline above
- Directive (EU) 2022/2555, Article 14 (Cooperation Group), points 4(h), 4(q), 4(r): nis-2-directive.com/NIS_2_Directive_Article_14.html
- Directive (EU) 2022/2555, Article 18 (Report on the state of cybersecurity in the Union): nis-2-directive.com/NIS_2_Directive_Article_18.html
- Directive (EU) 2022/2555, Article 10 (CSIRTs), paragraph 5: nis-2-directive.com/NIS_2_Directive_Article_10.html
- Directive (EU) 2022/2555, Article 40 (Review): nis-2-directive.com/NIS_2_Directive_Article_40.html
- Directive (EU) 2022/2555, Recitals 75 and 76: nis-2-directive.com/NIS_2_Directive_Preamble_71_to_80.html
- ENISA, National Capabilities Assessment Framework 2.0, 22 April 2026 — linked inline above
- Directive (EU) 2022/2555, Article 19 — independent cross-check: nis2resources.eu/directive-2022-2555-nis2/article-19/
- Official consolidated text, Directive (EU) 2022/2555 (NIS 2), EUR-Lex: eur-lex.europa.eu/eli/dir/2022/2555/oj
Get the NIS2 Article 21 Compliance Checklist
90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.
