Logo Teldat

• Cybersecurity Glossary

NIS2 Reform 2026: What Changes with the Commission’s Amendment Proposal

The NIS2 reform of 2026 is a set of Targeted amendments to Directive (EU) 2022/2555, proposed by the European Commission on 20 January 2026 within a wider cybersecurity package that also revises the Cybersecurity Act. The reform clarifies and narrows NIS2 scope, adds Sector thresholds such as a 1 MW line for electricity producers, creates a new small midcap category, brings in strategically sensitive entities, and harmonizes rules across member states. The Commission estimates it will ease compliance for around 28,700 entities, including 6,200 micro and small enterprises, without removing the core duties to manage cyber risk and report incidents. This page explains what the reform changes, why it is happening, and what it means in practice.

What the NIS2 reform is?

The NIS2 reform of 2026 is a package of targeted amendments to the NIS2 Directive, Directive (EU) 2022/2555, that the European Commission proposed on 20 January 2026. It was published alongside a proposal to revise the Cybersecurity Act, as part of a broader effort to streamline and harmonize the EU’s cybersecurity rules.

Importantly, the reform does not tear up NIS2 or remove its core requirements. Entities in scope still have to manage cyber risk and report significant incidents. What the amendment changes is the edges: who exactly is covered, how consistently the rules apply across member states, and how heavy the administrative burden is for organizations that were struggling with unclear or duplicated obligations.

The headline the Commission itself emphasizes is relief: the reform is expected to ease compliance for around 28,700 entities, including 6,200 micro and small enterprises. In other words, it is a simplification and clarification exercise layered on top of the existing directive, not a replacement of it.

Why the Commission is amending NIS2?

Amending a directive so soon after adoption is unusual, and the reasons say a lot about how NIS2 has landed in practice. These are the main drivers behind the 2026 reform.

1
Uneven national transposition
NIS2 had an October 2024 transposition deadline, but many member states missed it and some are still transposing. The result was a patchwork of national rules and infringement proceedings, leaving businesses to comply with inconsistent laws across borders. Harmonization is the Commission’s answer.
2
Unclear scope and classification
Many organizations struggled to know whether they were in scope at all, or whether they counted as essential or important. That ambiguity drove cost and legal uncertainty. The reform introduces clearer thresholds and definitions so entity classification becomes more predictable.
3
Overlap with other EU rules
Entities often faced duplicated reporting under NIS2, GDPR, DORA and sectoral regimes. Building on the Digital Omnibus of November 2025, the reform continues aligning NIS2 with neighbouring laws, including a move toward single points for incident reporting.
4
A simplification agenda
The reform sits within a wider EU drive to cut regulatory friction and strengthen sovereignty, alongside the revised Cybersecurity Act. The goal is proportionate rules that focus supervision on systemically important operators while lifting unnecessary load off smaller ones.

The main changes at a glance

The proposal is detailed, but its substance can be grouped into a handful of themes. The table summarizes the main changes and what each one means for organizations.

Change What it means?
Clearer scope and thresholds Sector rules refined, for example a 1 MW threshold for electricity producers
New small midcap category Generally classified as important, not essential, so lighter supervision
New strategic entities added Digital identity and business wallets, submarine cables, dual use infrastructure
Greater harmonization More consistent technical measures and certification based pathways
Stronger ENISA role More cross border coordination and central support
Ransomware data collection Harmonized reporting on attack vectors, mitigations and ransom details

The core stays the same: across all these changes, the fundamental NIS2 duties, managing cyber risk with appropriate technical and organizational measures and reporting significant incidents, remain in place. The reform recalibrates who is covered and how consistently, but it does not lower the underlying security bar.

Scope in and scope out

One of the clearest effects of the reform is that it moves some entities out of scope while pulling others in. Understanding both directions is the key to knowing whether the reform changes your own position.

1
Out, small electricity producers
Only electricity producers with a total generation capacity above 1 MW would fall within scope, where previously all producers were covered regardless of scale. This lifts small scale and household producers out of NIS2 and lets supervisors focus on operators that matter for grid stability.
2
Out, pure chemical trading
In the chemical sector, coverage would be limited to manufacturers and producers of substances subject to REACH obligations, taking pure import and distribution trading out of scope. This aligns NIS2 more closely with genuine risk exposure within the EU.
3
In, digital wallets and identity
Providers of European Digital Identity Wallets and European Business Wallets would be brought into scope, classified as essential entities regardless of their size, reflecting how central digital identity is becoming to the EU’s economy and security.
4
In, strategic infrastructure
Operators of submarine data transmission infrastructure and owners or operators of strategic dual use infrastructure would be added, in some cases regardless of size, reflecting a focus on assets that are sensitive for European security and resilience.

Reassess if you are near a line: organizations sitting close to a threshold, such as the 1 MW electricity capacity or the new small midcap size criteria of over 750 employees with turnover up to €150 million, should re-examine how they might be classified once the reform advances, because a change in category also changes supervisory intensity.

Timeline and what happens next

The reform is a proposal, not yet law, so its timeline matters as much as its content. The table sets out the key dates and stages.

Stage Timing
Digital Omnibus, first adjustments November 2025
Amendment proposal published 20 January 2026
Parliament and Council negotiations Through 2026
Expected political agreement Late 2026 or early 2027
National transposition after adoption Around 12 months

Keep complying in the meantime: because the proposal is still moving through the legislative process and its text may change, existing NIS2 obligations continue to apply in full. The sensible approach is to keep working on current compliance while tracking the reform, rather than pausing in anticipation of changes that are not yet settled.

What it means, and Teldat’s role?

Whatever the final shape of the reform, the core NIS2 duties remain, so the technical foundation of resilience does not change. Teldat is a European manufacturer whose infrastructure supports that foundation, regardless of how entities are reclassified.

1
Resilient connectivity stays essential
No matter how scope is redrawn, keeping critical services available means resilient, redundant connectivity. Teldat SD-WAN delivers self healing connectivity that supports the operational resilience NIS2 expects, for essential and important entities alike.
2
Layered security and detection
The duty to manage risk and report incidents is untouched, so layered network and cloud security and fast detection remain central. Teldat be.Safe Pro provides cloud security with secure web gateway and NGFW features, and be.Safe XDR adds monitoring and extended detection and response.
3
European jurisdiction and harmonization
As the reform pushes toward harmonization and European sovereignty, sourcing infrastructure from a European manufacturer operating under European jurisdiction fits the direction of travel, and supports the supply chain considerations that run through EU cyber law.
4
Focus on resilience, not paperwork
By easing administrative load, the reform lets organizations concentrate on genuine security outcomes. That is where infrastructure choices matter most, and where Teldat’s portfolio is designed to help, though Teldat does not certify compliance and each organization remains responsible for its own.

A European foundation through the change: the reform recalibrates NIS2 but keeps its heart, the duty to be genuinely resilient. Teldat combines SD-WAN, be.Safe Pro and be.Safe XDR under European jurisdiction, giving organizations a European infrastructure foundation that stays relevant whichever way the final text lands. Teldat does not certify compliance, and each organization remains responsible for its own obligations.

FAQ’s about the NIS2 reform

❯ What is the NIS2 reform of 2026?

The NIS2 reform of 2026 is a set of targeted amendments to the NIS2 Directive, Directive (EU) 2022/2555, that the European Commission proposed on 20 January 2026. It forms part of a wider cybersecurity package that also revises the Cybersecurity Act. Rather than replacing NIS2, the reform aims to clarify and narrow its scope, harmonize how it is applied across member states, and reduce the compliance burden, while keeping the core obligations to manage cyber risk and report significant incidents intact. The Commission estimates it will ease compliance for around 28,700 entities, including 6,200 micro and small enterprises.

❯ Why is the Commission amending NIS2 so soon?

The timing reflects practical implementation problems. NIS2 had a transposition deadline of October 2024, but many member states missed it and some are still transposing, which led to infringement proceedings and uneven national rules. That fragmentation created uncertainty and cost for businesses, especially those operating across several countries. The 2026 reform responds by clarifying scope, adding sector thresholds and harmonizing requirements, so that organizations face more predictable and proportionate obligations. It builds on the Digital Omnibus of November 2025, which had already begun streamlining how NIS2 interacts with other EU rules.

❯ What are the main changes in the NIS2 2026 amendment?

The proposal makes several targeted changes. It narrows scope in some sectors, for example only covering electricity producers above a 1 MW generation capacity and limiting the chemical sector to manufacturers subject to REACH. It creates a new small midcap category, generally classifying those entities as important rather than essential to reduce supervisory intensity. It adds strategically sensitive entities such as providers of European Digital Identity Wallets and European Business Wallets, operators of submarine data transmission infrastructure and strategic dual use infrastructure. It also harmonizes technical measures, introduces certification based compliance pathways aligned with the revised Cybersecurity Act, strengthens ENISA’s coordinating role, and adds harmonized data collection on ransomware.

❯ When will the NIS2 reform take effect?

The reform is still a proposal. Published on 20 January 2026, it now goes through the ordinary EU legislative procedure, with negotiations in the European Parliament and Council. Commentators expect political agreement no earlier than late 2026 or early 2027. Once adopted, the amendments would need to be transposed into national law, with the current draft foreseeing a 12 month transposition period after entry into force. Until then, the existing NIS2 obligations continue to apply, so organizations should keep working on current compliance while tracking the proposal, because the core duties to manage risk and report incidents are not going away.

❯ How should organizations respond to the NIS2 reform?

Because the core obligations remain, the practical priority is unchanged: build genuine cyber resilience rather than treating NIS2 as a paperwork exercise. Organizations near a scope threshold, such as the 1 MW electricity line or the small midcap size criteria, should reassess how they may be classified once the reform advances. Regardless of classification, resilient connectivity, layered network and cloud security, and fast detection remain the technical foundation. For that foundation, sourcing infrastructure from a European manufacturer such as Teldat, operating under European jurisdiction, helps align with the direction of EU cyber law, though each organization remains responsible for its own compliance.

Stay resilient through the NIS2 reform with Teldat

Whichever way the reform lands, the duty to be genuinely resilient remains. Teldat combines SD-WAN, be.Safe Pro and be.Safe XDR under European jurisdiction, giving organizations a European infrastructure foundation for NIS2 resilience.