Text · Report parliamentary committee draft
On the proposal for a directive of the European Parliament and of the Council amending Directive (EU) 2022/2555 as regards simplification measures and alignment with the [Proposal for the Cybersecurity Act 2]
Full title
On the proposal for a directive of the European Parliament and of the Council amending Directive (EU) 2022/2555 as regards simplification measures and alignment with the [Proposal for the Cybersecurity Act 2]
Document ITRE-PR-792221 · COM(2026)0013 – C100016/2026 – 2026/0012(COD)
- Kind
- Report parliamentary committee draft ITRE-PR-792221
- Date
- 17 September 2026
- Committee
- Committee on Industry, Research and Energy
- Rapporteur
- Markéta Gregorová
- Dossier
- 2026-0012
More facts (2)
- Formats
- Official page PDF Word
- Reference
- COM(2026)0013 – C100016/2026 – 2026/0012(COD)
In short
A summary of the text written by AI; ¶ opens the paragraph it rests on.
AI: In short Written by AI from the official text — check the source · deepseek-flash · 25 Sept 2026
This is the rapporteur's draft report on a Commission proposal to amend Directive (EU) 2022/2555 with simplification measures and alignment with the proposed Cybersecurity Act 2. It sets fixed dates for the migration to post-quantum cryptography: critical use cases by 31 December 2030 and all other use cases by 31 December 2035. It requires the Commission to issue guidance on the harmonised application of the Directive and guidelines on supplier information requests in a common, machine readable format. It adds confidentiality, deletion and liability rules for ransomware information, and data minimisation and resource rules for ENISA's registry and tasks. It routes incident notifications through a single entry point and amends Regulation (EU) No 910/2014, Regulation (EU) 2022/2554 and Directive (EU) 2022/2557 accordingly.
Position. The rapporteur proposes that Parliament adopt its first-reading position with 33 amendments to the Commission proposal, covering post-quantum migration dates, harmonised guidance, supplier guidelines, ransomware confidentiality, ENISA resources and data minimisation, single entry point notifications, and changes to three other Union acts.
Key points
- Sets fixed migration dates to post-quantum cryptography: critical use cases by 31 December 2030 and all other use cases by 31 December 2035, in line with the NIS Cooperation Group roadmap.
- Requires the Commission to adopt guidelines in a common, machine readable format for supplier information requests, so obligations are not unduly passed to micro and small enterprises and free and open-source software developers, maintainers and foundations.
- Requires ransomware information to be collected exclusively for prevention, situational awareness and support, treated confidentially, not used in supervisory or enforcement proceedings, transmitted onward only where Union or national law expressly provides, and deleted when no longer necessary.
- Requires the ENISA registry to comply with data minimisation, keeps information on entities' IP ranges with national competent authorities, and requires state-of-the-art protection designed with the European Data Protection Supervisor.
- Requires ENISA's new tasks to be matched by adequate resources, the cross-border risk assessment report and annual updates to go simultaneously to Parliament, the Council and the Commission, and unactionable requests to appear in its annual activity report.
- Requires the Commission, with the NIS Cooperation Group and ENISA, to issue guidance on harmonised interpretation of key obligations, including classification of entities, audit conditions, cross-border registration and reporting, and proportionality in supervision.
- Defines 'main establishment' and requires ENISA to keep an up-to-date, machine readable record of registered entities' main establishments.
- Replaces implementing acts with delegated acts for technical, methodological and sectoral requirements, requires assessments every two years, and ends national requirements going beyond those acts 12 months after their application.
- Requires significant incidents to be notified via a single entry point, states that notification does not increase liability, and requires ransomware communication channels to use end-to-end encryption by default with statistics published annually.
- Allows a manufacturer's notification of a severe incident under Regulation (EU) 2024/2847 to count as reporting under the Directive where it contains the required information.
- Requires cyber posture certificates to be recognised in all Member States and prevents additional supervisory measures where a certificate demonstrates compliance.
- Amends Regulation (EU) No 910/2014, Regulation (EU) 2022/2554 and Directive (EU) 2022/2557 to route notifications through the single entry point, and allows implementing acts on the type and format of critical entity notifications.
Who is affected
- Essential and important entities: must meet post-quantum migration dates, notify incidents via a single entry point, and follow supplier guidelines.
- Micro and small enterprises and free and open-source software developers, maintainers and foundations: protected from unduly passed-on obligations.
- ENISA: gains registry, guidance and reporting tasks, with resource and data protection conditions.
- Manufacturers of products with digital elements: their severe incident notifications can count as reporting under the Directive.
- Financial entities and critical entities: must report incidents through the single entry point.
Figures and deadlines
- 31 December 2030: deadline for migrating critical use cases to post-quantum cryptography.
- 31 December 2035: deadline for migrating all other use cases to post-quantum cryptography.
- 12 months after entry into force: deadline for Commission guidance on harmonised application and for supplier guidelines.
- 24 months after receipt: latest deletion of ransomware information collected.
- 15 months after entry into force: deadline for ENISA's cross-border cybersecurity risk analysis.
- 24 hours: deadline for critical entities' initial notification of incidents.
- One month: deadline for critical entities' detailed report after an incident.
- 12 months after application of delegated acts: national requirements going beyond them cease to apply.
Legal basis. Article 294(2) and Article 114 of the Treaty on the Functioning of the European Union.
Text
The text as parsed from the official Word file. Every paragraph has a link (¶) and can be saved to a project as a passage.
Jump to an amendment (33)
- Amendment 1
- Amendment 2
- Amendment 3
- Amendment 4
- Amendment 5
- Amendment 6
- Amendment 7
- Amendment 8
- Amendment 9
- Amendment 10
- Amendment 11
- Amendment 12
- Amendment 13
- Amendment 14
- Amendment 15
- Amendment 16
- Amendment 17
- Amendment 18
- Amendment 19
- Amendment 20
- Amendment 21
- Amendment 22
- Amendment 23
- Amendment 24
- Amendment 25
- Amendment 26
- Amendment 27
- Amendment 28
- Amendment 29
- Amendment 30
- Amendment 31
- Amendment 32
- Amendment 33
Draft european parliament legislative resolution
on the proposal for a regulation of the European Parliament and of the Council amending Directive (EU) 2022/2555 as regards simplification measures and alignment with the [Proposal for the Cybersecurity Act 2]
–having regard to Article 294(2) and Article 114 of the Treaty on the Functioning of the European Union, pursuant to which the Commission submitted the proposal to Parliament (C100016/2026),
–having regard to the reasoned opinion submitted, within the framework of Protocol No 2 on the application of the principles of subsidiarity and proportionality, by the French Senate, asserting that the draft legislative act does not comply with the principle of subsidiarity,
1.Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;
2.Instructs its President to forward its position to the Council, the Commission and the national parliaments.
| Text proposed by the Commission | Amendment |
|---|---|
| (8a) The migration to PQC should take place within fixed dates. Critical use cases should be transitioned to PQC by 31 December 2030 and all other use cases by 31 December 2035 at the latest, in line with the Coordinated Implementation Roadmap for the transition to PQC, adopted by the NIS Cooperation Group. |
| Text proposed by the Commission | Amendment |
|---|---|
| (9a) Essential and important entities pass cybersecurity-related requirements on to their suppliers and service providers in divergent formats and beyond what Directive (EU) 2022/2555 requires. The Commission should therefore be required to adopt guidelines in a common, machine readable format for supplier information requests, ensuring that obligations are not unduly passed on to entities outside the scope of that Directive, in particular to micro and small enterprises and to developers, maintainers and foundations of free and open-source software. |
| Text proposed by the Commission | Amendment |
|---|---|
| (10a) Information on demands and payments in the context of ransomware attacks encompasses data that allows the identification of victims and their negotiation position. Such information should be collected exclusively for the purposes of prevention, situational awareness and support, should be treated confidentially, should not be used in supervisory or enforcement proceedings against the reporting entity, should be transmitted onward only where Union or national law expressly so provides, and should be deleted when no longer necessary. The mere provision of such information should not subject the reporting entity to increased liability. Aggregated and anonymised statistics should be published so that entities and researchers benefit from the reported data. |
| Text proposed by the Commission | Amendment |
|---|---|
| (12a) The registry maintained by ENISA should comply with the principle of data minimisation. The information on the entities’ IP ranges is not necessary at Union level for the purposes of the registry and should remain with the national competent authorities. The registry should be protected by state-of-the-art technical and organisational measures designed in consultation with the European Data Protection Supervisor. |
| Text proposed by the Commission | Amendment |
|---|---|
| (12b) The new tasks conferred on ENISA by this Directive should be matched by adequate resources. The cross-border cybersecurity risk assessment report and its annual updates should be transmitted to the European Parliament, to the Council and to the Commission simultaneously, and requests that ENISA cannot act upon for reasons of inadequate resources should be visible in its annual activity report. |
| Text proposed by the Commission | Amendment |
|---|---|
| (14a) To ensure that Directive (EU) 2022/2555 is applied consistently and proportionately across the Union and in line with the report once principle, duplicative or unclear obligations, diverging national interpretations and additional national requirements should be avoided. The Commission should, in cooperation with the NIS Cooperation Group and ENISA, issue guidance on the harmonised interpretation and application of key obligations under that Directive. |
| Text proposed by the Commission | Amendment |
|---|---|
| (44) ‘main establishment’ means the establishment of an entity in the Union where the decisions related to the cybersecurity risk-management measures of an entity are predominantly taken, determined according to objective criteria implying the effective and real exercise of management activities; where no such establishment can be determined, the main establishment is the establishment in the Union where cybersecurity operations are carried out; ENISA shall keep, as part of the registry referred to in Article 27, an up to date, machine readable record of the main establishments of the registered entities. |
| Text proposed by the Commission | Amendment |
|---|---|
| (k) for the transition to post-quantum cryptography, taking into account the transition timelines and relevant requirements set out in applicable Union legal acts and policies.; | (k) for the transition to post-quantum cryptography, ensuring the migration of critical use cases by 31 December 2030 and of all other use cases by 31 December 2035, in line with the Coordinated Implementation Roadmap of the NIS Cooperation Group and taking into account the transition timelines and relevant requirements set out in applicable Union legal acts and policies.; |
| Text proposed by the Commission | Amendment |
|---|---|
| (5a) the following Article is inserted: | |
| ‘Article 14a | |
| Harmonised application | |
| 1. To ensure a consistent and proportionate application of this Directive across the Union, the Commission shall, by … [12 months after the date of entry into force of this amending Directive], in cooperation with the NIS Cooperation Group and ENISA, issue guidance on the harmonised interpretation and application of key obligations under this Directive. Such guidance shall address in particular: | |
| (a) the classification of entities as essential or important entities, including the avoidance of additional or diverging national categorisations beyond those provided for in this Directive; | |
| (b) the conditions under which cybersecurity audits, assessments or equivalent supervisory measures may be required, including their frequency and scope; | |
| (c) registration, notification and reporting obligations applicable to entities operating in more than one Member State; | |
| (d) the application of proportionality in supervisory and enforcement practices. | |
| 2. Member States shall take utmost account of that guidance when implementing and applying this Directive and shall refrain from introducing additional obligations that would undermine the uniform application of Union law.’ |
| Text proposed by the Commission | Amendment |
|---|---|
| The Commission may adopt implementing acts laying down the technical and the methodological requirements, as well as sectoral requirements, as necessary, of the measures referred to in paragraph 2 with regard to essential and important entities other than those referred to in the first subparagraph of this paragraph. The Commission shall regularly assess whether implementing acts referred to in this subparagraph shall be adopted for specific sectors or types of entities to improve the functioning of the internal market. When preparing such assessments, the Commission shall focus in particular on the cross-border nature of sectors or types of entities and shall carry out an open, transparent and inclusive consultation process with relevant stakeholders and Member States. | The Commission may adopt delegated acts in accordance with Article 38 laying down the technical and the methodological requirements, as well as sectoral requirements, as necessary, of the measures referred to in paragraph 2 with regard to essential and important entities other than those referred to in the first subparagraph of this paragraph. The Commission shall assess every two years whether acts referred to in this subparagraph shall be adopted for specific sectors or types of entities to improve the functioning of the internal market. When preparing such assessments, the Commission shall focus in particular on the cross-border nature of sectors or types of entities and shall carry out an open, transparent and inclusive consultation process with relevant stakeholders and Member States. The Commission shall transmit each assessment to the European Parliament and to the Council without delay. |
| Text proposed by the Commission | Amendment |
|---|---|
| Where the Commission adopts implementing acts referred to in the first and second subparagraphs of this paragraph, Member States shall not impose any further technical, methodological or sectoral requirements of the measures referred to in Article 21(2) of Directive (EU) 2022/2555 on the entities in scope of those implementing acts. | Where the Commission adopts delegated acts referred to in the first and second subparagraphs of this paragraph, Member States shall not impose any further technical, methodological or sectoral requirements of the measures referred to in paragraph 2 on the entities in scope of those acts. Requirements laid down in national law that go beyond those acts shall cease to apply 12 months after the date of application of the acts concerned. |
| Text proposed by the Commission | Amendment |
|---|---|
| (7a) in Article 21, the following paragraph is added: | |
| ‘5a. By … [12 months after the date of entry into force of this amending Directive], the Commission shall, after consulting ENISA, the NIS Cooperation Group and the relevant stakeholders, including representatives of free and open source software developers, adopt guidelines on the cybersecurity-related requirements that essential and important entities pass on to their suppliers and service providers as referred to in paragraph 2, point (d). The guidelines shall: | |
| (a) establish a common, machine readable format for supplier information requests; | |
| (b) ensure that obligations under this Directive are not unduly passed on to entities outside its scope, in particular to micro and small enterprises and to developers, maintainers and foundations of free and open-source software; | |
| (c) address the proliferation of divergent supplier questionnaires. | |
| The Commission shall review the guidelines every two years.’ |
| Present text | Amendment |
|---|---|
| (7b) in Article 23(1), the first subparagraph is replaced by the following: | |
| Each Member State shall ensure that essential and important entities notify, without undue delay, its CSIRT or, where applicable, its competent authority in accordance with paragraph 4 of any incident that has a significant impact on the provision of their services as referred to in paragraph 3 (significant incident). Where appropriate, entities concerned shall notify, without undue delay, the recipients of their services of significant incidents that are likely to adversely affect the provision of those services. Each Member State shall ensure that those entities report, inter alia, any information enabling the CSIRT or, where applicable, the competent authority to determine any cross-border impact of the incident. The mere act of notification shall not subject the notifying entity to increased liability. | ‘Each Member State shall ensure that essential and important entities notify, without undue delay, its CSIRT or, where applicable, its competent authority in accordance with paragraph 4, via the single entry point established pursuant to Article 23a, of any incident that has a significant impact on the provision of their services as referred to in paragraph 3 (significant incident). Where appropriate, entities concerned shall notify, without undue delay, the recipients of their services of significant incidents that are likely to adversely affect the provision of those services. Each Member State shall ensure that those entities report, inter alia, any information enabling the CSIRT or, where applicable, the competent authority to determine any cross-border impact of the incident. The mere act of notification shall not subject the notifying entity to increased liability.’ |
| Text proposed by the Commission | Amendment |
|---|---|
| 13. Member States shall ensure that in case of a significant incident caused by a ransomware attack, the entities concerned inform, upon request of the CSIRT or, where applicable, the competent authority via a communication channel provided by the CSIRT or, where applicable, the competent authority: | 13. Member States shall ensure that in case of a significant incident caused by a ransomware attack, the entities concerned inform, upon request of the CSIRT or, where applicable, the competent authority, exclusively for the purposes of prevention, situational awareness and support, via a communication channel provided by the CSIRT or, where applicable, the competent authority: |
| Text proposed by the Commission | Amendment |
|---|---|
| The provision of information pursuant to this paragraph shall not of itself subject the entity concerned to increased liability. That information shall be treated confidentially, shall not be used in supervisory or enforcement proceedings against the reporting entity and shall be transmitted to other authorities only where Union or national law expressly so provides. The communication channel referred to in the first subparagraph shall ensure end to end encryption by default. Information collected pursuant to this paragraph shall be deleted when no longer necessary for the purposes set out in the first subparagraph and at the latest 24 months after receipt. CSIRTs shall make available annually, in an anonymised, aggregated and machine readable format, statistics on ransomware attacks reported pursuant to paragraph 12 of this Article and pursuant to this paragraph, including as input to the report referred to in Article 18. |
| Text proposed by the Commission | Amendment |
|---|---|
| 13a. Where a manufacturer notifies a severe incident pursuant to Article 14(3) of Regulation (EU) 2024/2847 of the European Parliament and of the Council1a and that notification contains the information required under paragraph 4 of this Article, that notification shall constitute reporting under paragraph 4 of this Article. | |
| 1a Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements and amending Regulations (EU) No 168/2013 and (EU) 2019/1020 and Directive (EU) 2020/1828 (Cyber Resilience Act) (OJ L 2847 20.11.2024, p. 1, ELI: http://data.europa.eu/eli/reg/2024/2847/oj ). |
| Text proposed by the Commission | Amendment |
|---|---|
| 4. In order to demonstrate compliance with Article 21, Member States may require essential and important entities to obtain a certificate on the cyber posture under a European cybersecurity certification scheme adopted pursuant to Article 75 of Regulation (EU) XXX/XXX **** [Proposal for CSA2]. | 4. In order to demonstrate compliance with Article 21, Member States may require essential and important entities to obtain a certificate on the cyber posture under a European cybersecurity certification scheme adopted pursuant to Article 74 of Regulation (EU) XXX/XXX **** [Proposal for CSA2]. |
| **** Regulation (EU) XXX/XXX [Proposal for CSA2]’; | **** Regulation (EU) XXX/XXX [Proposal for CSA2]’; |
| Text proposed by the Commission | Amendment |
|---|---|
| 5. Where the cyber posture of an essential or important entity is certified under a European cybersecurity certification scheme adopted pursuant to Article 74 of Regulation (EU) XXX/XXX**** [Proposal for CSA2] and where the certificate demonstrates compliance with the requirements laid down in an implementing act adopted pursuant to Article 21(5) of this Directive or national law transposing Article 21(1) and (2) of this Directive, competent authorities shall not subject the entity to additional measures pursuant to Article 32(2), point (b), or Article 33(2), point (b), as applicable with regard to the requirements covered by the certificate. | 5. Where the cyber posture of an essential or important entity is certified under a European cybersecurity certification scheme adopted pursuant to Article 75 of Regulation (EU) XXX/XXX**** [Proposal for CSA2] and where the certificate demonstrates compliance with the requirements laid down in a delegated act adopted pursuant to this Directive or national law transposing Article 21(1) and (2) of this Directive, competent authorities in all Member States where the entity provides its services shall not subject the entity to additional measures pursuant to Article 32(2), point (b), or Article 33(2), point (b), as applicable with regard to the requirements covered by the certificate. A certificate referred to in paragraph 4 of this Article shall be recognised in all Member States. |
| **** Regulation (EU) XXX/XXX [Proposal for CSA2]’; | **** Regulation (EU) XXX/XXX [Proposal for CSA2]’; |
| Text proposed by the Commission | Amendment |
|---|---|
| (da) manufacturers of a type referred to in Annex II, shall be considered to fall under the jurisdiction of the Member State in which they have their main establishment in the Union under paragraph 2 of this Article. |
| Text proposed by the Commission | Amendment |
|---|---|
| 4. Upon receipt of the information referred to in Article 3(4), the single point of contact of the Member State concerned shall, without undue delay, forward it to ENISA. | 4. Upon receipt of the information referred to in Article 3(4), except for the information referred to in Article 3(4), first subparagraph, point (f), the single point of contact of the Member State concerned shall, without undue delay, forward it to ENISA. |
| Present text | Amendment |
|---|---|
| (11a) in Article 30(1), the introductory part is replaced by the following: | |
| 1. Member States shall ensure that, in addition to the notification obligation provided for in Article 23, notifications can be submitted to the CSIRTs or, where applicable, the competent authorities, on a voluntary basis, by: | ‘1. Member States shall ensure that, in addition to the notification obligation provided for in Article 23, notifications can be submitted to the CSIRTs or, where applicable, the competent authorities, on a voluntary basis, via the single entry point established pursuant to Article 23a, by:’ |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. For the purposes set out in paragraph 1, by … [15 months after the entry into force of this Regulation], ENISA shall conduct a comprehensive analysis of cross-border cybersecurity risks relating to essential and important entities that provide services in more than one Member State or that provide services in one or more Member States and have their network and information systems located in one or more other Member States. The analysis shall evaluate the extent of possible cross-border and internal market consequences of incidents affecting such essential and important entities. For the purpose of this analysis, ENISA shall, in cooperation with the Commission and the Cooperation Group, develop a methodology. Based on the analysis, ENISA shall draw up a comprehensive cross-border cybersecurity risk assessment report, which shall be updated annually. | 2. For the purposes set out in paragraph 1, by … [15 months after the entry into force of this amending Directive], ENISA shall conduct a comprehensive analysis of cross-border cybersecurity risks relating to essential and important entities that provide services in more than one Member State or that provide services in one or more Member States and have their network and information systems located in one or more other Member States. The analysis shall evaluate the extent of possible cross-border and internal market consequences of incidents affecting such essential and important entities. For the purpose of this analysis, ENISA shall, in cooperation with the Commission and the Cooperation Group, develop and publish a methodology. Based on the analysis, ENISA shall draw up a comprehensive cross-border cybersecurity risk assessment report, which shall be updated annually. ENISA shall transmit the report and its annual update to the European Parliament, to the Council and to the Commission simultaneously. |
| Text proposed by the Commission | Amendment |
|---|---|
| 5a. ENISA shall state in its annual activity report the number of requests received under paragraph 3, the number of requests it could not act upon for reasons of inadequate resources and the resources allocated to the tasks under this Article.’ |
| Text proposed by the Commission | Amendment |
|---|---|
| (12a) in Article 38, paragraphs 2, 3 and 6, the words ‘Article 24(2)’ are replaced by ‘Article 21(5), second subparagraph, and Article 24(2)’. |
| Text proposed by the Commission | Amendment |
|---|---|
| Article 1a | |
| Amendments to Regulation (EU) No 910/2014 | |
| Regulation (EU) No 910/2014 is amended as follows: | |
| (1) in Article 19a, the following paragraph is inserted | |
| ‘1a. Notifications pursuant to paragraph 1, point (b), of this Article to the supervisory body and, where applicable, to other relevant competent authorities, shall be made through the single entry point established pursuant to Article 23a of Directive (EU) 2022/2555.’; |
| Text proposed by the Commission | Amendment |
|---|---|
| (2) in Article 24, the following paragraph is inserted: | |
| ‘2a. Notifications pursuant to paragraph 2, point (fb), of this Article to the supervisory body and, where applicable, to other relevant competent bodies, shall be made through the single entry point established pursuant to Article 23a of Directive (EU) 2022/2555.’; |
| Text proposed by the Commission | Amendment |
|---|---|
| (3) in Article 45a, the following paragraph is inserted: | |
| ‘3a. Notifications pursuant to paragraph 3 to the Commission and to the competent supervisory body shall be made through the single entry point established pursuant to Article 23a of Directive (EU) 2022/2555.’. |
| Present text | Amendment |
|---|---|
| Article 1b | |
| Amendments to Regulation (EU) 2022/2554 | |
| Article 19 of Regulation (EU) 2022/2554 is amended as follows: | |
| (1) in paragraph 1, the first subparagraph is replaced by the following: | |
| Financial entities shall report major ICT-related incidents to the relevant competent authority as referred to in Article 46 in accordance with paragraph 4 of this Article. | ‘Financial entities shall report major ICT-related incidents to the relevant competent authority as referred to in Article 46 via the single entry point established pursuant to Article 23a of Directive (EU) 2022/2555 in accordance with paragraph 4 of this Article.’; |
| Present text | Amendment |
|---|---|
| (2) in paragraph 2, the first subparagraph is replaced by the following: | |
| Financial entities may, on a voluntary basis, notify significant cyber threats to the relevant competent authority when they deem the threat to be of relevance to the financial system, service users or clients. The relevant competent authority may provide such information to other relevant authorities referred to in paragraph 6. | ‘Financial entities may, on a voluntary basis, notify via the single entry point established pursuant to Article 23a of Directive (EU) 2022/2555 significant cyber threats to the relevant competent authority when they deem the threat to be of relevance to the financial system, service users or clients. The relevant competent authority may provide such information to other relevant authorities referred to in paragraph 6.’. |
| Present text | Amendment |
|---|---|
| Article 1c | |
| Amendments to Directive (EU) 2022/2557 | |
| Article 15 of Directive (EU) 2022/2557 is amended as follows: | |
| (1) in paragraph 1, first subparagraph, the introductory wording is replaced by the following: | |
| Member States shall ensure that critical entities notify the competent authority, without undue delay, of incidents that significantly disrupt or have the potential to significantly disrupt the provision of essential services. Member States shall ensure that, unless operationally unable to do so, critical entities submit an initial notification no later than 24 hours after becoming aware of an incident, followed, where relevant, by a detailed report no later than one month thereafter. In order to determine the significance of a disruption, the following parameters shall, in particular, be taken into account: | ‘Member States shall ensure that critical entities notify via the single entry point established pursuant to Article 23a of Directive (EU) 2022/2555 the competent authority, without undue delay, of incidents that significantly disrupt or have the potential to significantly disrupt the provision of essential services. Member States shall ensure that, unless operationally unable to do so, critical entities submit an initial notification no later than 24 hours after becoming aware of an incident, followed, where relevant, by a detailed report no later than one month thereafter. In order to determine the significance of a disruption, the following parameters shall, in particular, be taken into account:’; |
| Text proposed by the Commission | Amendment |
|---|---|
| (2) in paragraph 2, the following subparagraph is added: | |
| ‘The Commission may adopt implementing acts further specifying the type and format of information notified pursuant to Article 15(1). Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 24(2).’ |
| Text proposed by the Commission | Amendment |
|---|---|
| (d) in point 5, the first indent in the third column is replaced by the following: | deleted |
| ‘— Healthcare providers as defined in Article 3, point (g), of Directive 2011/24/EU of the European Parliament and of the Council****, excluding providers of services to which Directive 2011/24/EU does not apply pursuant to its Article 1(3), point (a)’ | |
| ****Directive 2011/24/EU of the European Parliament and of the Council of 9 March 2011 on the application of patients’ rights in cross-border healthcare (OJ L 88, 4.4.2011, p. 45, ELI: http://data.europa.eu/eli/dir/2011/24/oj). ’; |
| Text proposed by the Commission | Amendment |
|---|---|
| 2. in Annex II, point 3 is amended as follows: | deleted |
| (a) the text in the first column is replaced by the following: | |
| ‘3. Manufacture and production of chemicals; ’ | |
| (b) the text in the third column is replaced by the following: | |
| ‘— Undertakings carrying out the manufacture of substances, as referred to in Article 3, point (9), of Regulation (EC) No 1907/2006 of the European Parliament and of the Council*****, where the undertaking is subject to the general obligation to register substances on their own or in mixtures pursuant to Article 6 of Regulation (EC) No 1907/2006 | |
| — Undertakings carrying out the production of articles, as defined in Article 3, point (3) of Regulation (EC) No 1907/2006, from substances or mixtures, where the undertaking is subject to the obligation to notify substances in articles pursuant to Article 7(2) of Regulation (EC) No 1907/2006’ | |
| ***** Regulation (EC) No 1907/2006 of the European Parliament and of the Council of 18 December 2006 concerning Registration, Evaluation, Authorisation and Restriction of Chemicals (REACH), establishing a European Chemicals Agency, amending Directive 1999/45/EC and repealing Council Regulation (EEC) No 793/93 and Commission Regulation (EC) No 1488/94 as well as Council Directive 76/769/EEC and Commission Directives 91/155/EEC, 93/67/EEC, 93/105/EC and 2000/21/EC (OJ L 396, 30.12.2006, p. 1, ELI: http://data.europa.eu/eli/reg/2006/1907/oj). ’ |
Connections
The dossier, the decisions on this text and its other versions.
No connections found for this item.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 25 September 2026
Cite as
European Parliament (2026). “DRAFT REPORT on the proposal for a directive of the European Parliament and of the Council amending Directive (EU) 2022/2555 as regards simplification measures and alignment with the [Proposal for the Cybersecurity Act 2]”. Text, 17 September 2026. docId ITRE-PR-792221. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-792221 (retrieved 25 September 2026). Data: EP Open Data API: document record, https://data.europarl.europa.eu/api/v2/documents/ITRE-PR-792221 (CC BY 4.0).
BibTeX
@misc{epw-text-itre-pr-792221,
author = {{European Parliament}},
title = {{DRAFT REPORT on the proposal for a directive of the European Parliament and of the Council amending Directive (EU) 2022/2555 as regards simplification measures and alignment with the [Proposal for the Cybersecurity Act 2]}},
year = {2026},
date = {2026-09-17},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-792221}},
url = {https://news.eu-parl.st-solutions.dev/texts/ITRE-PR-792221},
urldate = {2026-09-25},
publisher = {EU Parl Watch Research},
note = {Text. docId ITRE-PR-792221. Data: EP Open Data API: document record (CC BY 4.0)}
}