Skip to content
NIS2 Art. 40 EN
LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this article. Contains: the article text, related recitals, cases citing it, enforcement stats and top fines, guidance, and related topics. Everything links back to its source on overview.legal — legal information, not advice.

Review

In force — consolidated2022-12-27 · CELEX 02022L2555-20221227 · ELI ↗
Version history 1
  • 2022-12-27in force CELEX 02022L2555-20221227

By 17 October 2027 and every 36 months thereafter, the Commission shall review the functioning of this Directive, and report to the European Parliament and to the Council. The report shall in particular assess the relevance of the size of the entities concerned, and the sectors, subsectors and types of entity referred to in Annexes I and II for the functioning of the economy and society in relation to cybersecurity. To that end and with a view to further advancing the strategic and operational cooperation, the Commission shall take into account the reports of the Cooperation Group and the CSIRTs network on the experience gained at a strategic and operational level. The report shall be accompanied, where necessary, by a legislative proposal.