Article 40
Review
Common Questions
Frequently Asked Questions
When and how often will the NIS2 directive be reviewed?
The European Commission will first review the NIS2 directive by 17 October 2027, then continue reviewing it regularly every three years, ensuring it remains effective, relevant and appropriate in improving cybersecurity, and meeting changing cybersecurity needs and conditions across the economy and society within the European Union.
Who conducts the reviews of the NIS2 Directive?
The European Commission handles the reviews of the NIS2 directive, compiling information from detailed reports submitted by cooperation groups and cybersecurity incident response teams (known as CSIRTs) within the EU, in order to effectively assess how well the directive operates and whether changes or updates may be needed going forward.
Which factors are considered during the review of the NIS2 Directive?
During the review, the Commission examines if the sizes of entities involved, the specific economic sectors, subsectors, or particular industries listed within the directive are still relevant and appropriate; it considers their importance for maintaining strong cybersecurity protections in daily business activities and services that citizens and society depend upon.
What happens if changes are deemed necessary after reviewing the NIS2 directive?
If the Commission finds significant need for changes after a review, it can propose new legislation or amendments, improving and updating the directive to better protect the economy and essential services from cybersecurity risks, ensuring European cybersecurity measures remain strong, practical, and effective for years to come.
