Source: OJ L 333, 27.12.2022, p. 80–152

Current language: FR

Article 40 Réexamen


Summary What does Article 40 of the NIS 2 directive say?

This is a review clause that places an obligation on the Commission to periodically assess how the Directive is functioning in practice.

The focus of the review is notably specific: rather than a general health-check, it targets whether the scoping criteria — entity size, sectors, subsectors, and types of entity — remain appropriate for the economy and society from a cybersecurity perspective.

To inform this assessment, the Commission must draw on the outputs of the Cooperation Group and the CSIRTs network, connecting this article directly to those cooperative bodies established elsewhere in the Directive.

Important points:

  • The Commission is required to conduct a review by 17 October 2027 and every 36 months after that, reporting to the European Parliament and the Council.
  • The review must specifically assess whether the size thresholds and sectoral scope set out in Annexes I and II remain fit for purpose in relation to cybersecurity.
  • The report may be accompanied by a legislative proposal, meaning the Directive's scope could be revised as a result of the review.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

Au plus tard le 17 octobre 2027 et tous les 36 mois par la suite, la Commission réexamine le fonctionnement de la présente directive et en fait rapport au Parlement européen et au Conseil. Le rapport évalue notamment la pertinence de la taille des entités concernées et des secteurs, sous-secteurs et types d’entité visés aux annexes I et II pour le fonctionnement de l’économie et de la société en ce qui concerne la cybersécurité. À cette fin et en vue de faire progresser la coopération stratégique et opérationnelle, la Commission tient compte des rapports du groupe de coopération et du réseau des CSIRT sur l’expérience acquise au niveau stratégique et opérationnel. Le rapport est accompagné, si nécessaire, d’une proposition législative.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod