The French National Agency for the Security of Information Systems (ANSSI) has published new guidance and support initiatives to aid in the implementation of the transposed NIS2 Directive. This…
EDPB-EDPS Joint Opinion on the Proposal for a Cybersecurity Act 2 and the Proposal on amendments to the NIS 2 Directive
Network and Information Security Directive (NIS2). Sourced from EDPS, summarised by Matproof.
AI Analysis
What changed and what to do.
The European Data Protection Board and European Data Protection Supervisor have issued a joint opinion on two legislative proposals: the Cybersecurity Act 2 and amendments to the NIS 2 Directive. This opinion highlights the need for stronger alignment between cybersecurity and data protection frameworks, specifically advocating for the integration of data protection by design and by default principles into the new cybersecurity certification schemes.
The opinion is primarily relevant to entities already in scope of the NIS 2 Directive, including essential and important entities across sectors like energy, transport, banking, and digital infrastructure. It will also directly impact future manufacturers and providers of ICT products, services, and processes seeking EU cybersecurity certification.
Compliance teams in affected sectors should monitor the legislative progress of these proposals closely. They should begin proactive gap analyses to assess how enhanced certification requirements and potential new obligations for incident reporting and vulnerability handling could impact their operations. Engaging with internal cybersecurity and product development teams now will be crucial for future readiness.
This summary is AI-generated for orientation purposes. For regulatory action, always consult the original source linked above.
More NIS2 updates
Latest in Network and Information Security Directive (NIS2).
The French National Cybersecurity Agency (ANSSI) has announced the opening of a pre-registration portal for entities in scope of the NIS 2 Directive. This is a key procedural step ahead of the formal…
The European Data Protection Board (EDPB) has published its agenda for the IAPP Global Summit 2026, highlighting key regulatory priorities. This agenda signals the EDPB's focus on the operational…
The European Data Protection Board and European Data Protection Supervisor have issued a joint opinion on the proposed Cybersecurity Act 2 and amendments to the NIS 2 Directive. This opinion provides…
Map this to your controls
Connect regulatory changes to your compliance work.
Matproof maps every regulator update directly to your controls and surfaces the ones that affect your organisation — across 21 frameworks.