The European Data Protection Board and European Data Protection Supervisor have issued a joint opinion on two legislative proposals: the Cybersecurity Act 2 and amendments to the NIS 2 Directive.…
EDPB and EDPS support strengthening EU’s cybersecurity and easing compliance while protecting individuals’ personal data
Network and Information Security Directive (NIS2). Sourced from EDPB, summarised by Matproof.
AI Analysis
What changed and what to do.
The EDPB and EDPS have issued a joint opinion endorsing the European Commission's draft implementing acts for the NIS2 Directive. This opinion supports measures designed to standardize and clarify cybersecurity risk management and reporting obligations across the EU. The primary goal is to strengthen the Union's collective cybersecurity while simplifying compliance burdens and ensuring a high level of personal data protection.
The changes directly affect entities within the broad scope of the NIS2 Directive. This includes medium and large organizations in essential sectors like energy, transport, and healthcare, as well as important digital providers such as cloud computing services and data centers.
Compliance teams in-scope organizations should first review the detailed implementing acts once formally adopted. The next step is to conduct a gap analysis against the newly clarified technical and procedural requirements. Teams should then prepare to integrate these standardized measures into existing cybersecurity and incident response frameworks, ensuring alignment with both NIS2 and GDPR obligations.
This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.
More NIS2 updates
Latest in Network and Information Security Directive (NIS2).
The French National Agency for the Security of Information Systems (ANSSI) has published new guidance and support initiatives to aid in the implementation of the transposed NIS2 Directive. This…
The French National Cybersecurity Agency (ANSSI) has announced the opening of a pre-registration portal for entities in scope of the NIS 2 Directive. This is a key procedural step ahead of the formal…
The European Data Protection Board (EDPB) has published its agenda for the IAPP Global Summit 2026, highlighting key regulatory priorities. This agenda signals the EDPB's focus on the operational…
Map this to your controls
Connect regulatory changes to your compliance work.
Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.