On 20 January 2026 the European Commission published a cybersecurity package proposing updates to two existing instruments: a revision of the 2019 Cybersecurity Act (referred to as CSA2) and a NIS2 Simplification amendment. The stated intent is to simplify compliance with EU cybersecurity rules and risk-management requirements for companies operating in the Union.
"Simplification" is doing specific work in that sentence, and it is worth being clear about what it does and does not mean.
What NIS2 requires, before any amendment
NIS2 expands security and incident-reporting duties across "essential" and "important" entities in sectors including energy, transport, finance, health and digital infrastructure. It raises the bar on governance, risk management and supply chain oversight.
Three features distinguish it from its predecessor:
- Management accountability. Senior management can be held personally liable for compliance failures. This is the provision that moved cybersecurity onto board agendas across Europe.
- Supply chain obligations. Entities must address risks arising from their suppliers and service providers, which pushes requirements down to organisations not directly in scope.
- Tight reporting timelines. An early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month.
What the simplification amendment addresses
The pressure for amendment came from the practical experience of transposition. NIS2 is a directive, implemented separately in each member state, which produced meaningful divergence in scope definitions, reporting formats and supervisory approaches. A company operating in eight member states could face eight variations of the same obligation.
The simplification effort targets that administrative friction. Critically, it targets the friction rather than the substance — the security obligations themselves are not being relaxed.
If your NIS2 readiness programme is behind schedule, the simplification package is not a reprieve. It is a change to how you report, not to what you must protect.
Common reporting templates, adopted May 2026
The most immediately useful development for practitioners: the NIS2 Cooperation Group adopted common templates for incident reporting in May 2026, providing a uniform format across member states and reducing administrative burden.
The practical implication is that your incident response process can now be built around a single reporting structure rather than a matrix of national variants. Concretely:
- Map the template fields into your IR runbook so that responders capture required information while the incident is live, not retroactively.
- Pre-populate everything static — entity identifiers, sector classification, contact points, competent authority details.
- Assign a named owner for the 24-hour early warning. That clock is short, and it starts when you become aware, not when you finish investigating.
- Rehearse the notification in a tabletop exercise. Teams routinely discover during a real incident that nobody knows who signs off.
The AI dimension
The EU Action Plan on Cybersecurity and AI, published on 7 July 2026, is the first EU-level document to formally link NIS2 compliance with AI-assisted threat detection as an expected operational practice.
This is worth watching carefully. It sits somewhere between guidance and expectation — not a hard requirement to deploy specific technology, but a signal about what supervisory authorities may come to regard as reasonable practice. Organisations should be able to articulate how their detection capability keeps pace with attack automation, whether or not that answer involves buying an AI product.
How this compares with the US position
For organisations subject to both regimes, the differences shape process design:
| NIS2 (EU) | SEC rules (US) | |
|---|---|---|
| Who is covered | Essential and important entities by sector | SEC-registered public companies |
| Trigger | Significant incident | Material incident |
| First deadline | 24-hour early warning | 4 business days from materiality determination |
| Recipient | National competent authority / CSIRT | Public filing (Form 8-K) |
| Governance | Management liability | Annual disclosure of risk management and governance |
The most consequential difference is audience. NIS2 reporting goes to a regulator; SEC disclosure goes to the public market. An organisation subject to both needs a process that can produce a regulator notification within 24 hours and a materiality assessment for public filing, without the two contradicting each other.
Practical next steps
- Confirm your classification in every member state where you operate — essential, important or out of scope. This still varies.
- Adopt the common reporting templates into your IR documentation now.
- Test the 24-hour path end to end, including out-of-hours and weekend scenarios.
- Review supply chain provisions in supplier contracts; flow-down obligations take months to renegotiate.
- Document management-level oversight. Under a liability regime, evidence that the board was informed is part of the control.



