Skip to main content
PolicySpeak
← All files

2026/0012(COD) · Commission Proposal

Amending the NIS 2 Directive as regards simplification measures and alignment with the Cybersecurity Act 2

330 submissions from 266 organizations told the European Commission what they think about this file. Here is what each of them said, in their own words.

The Commission lists 594 submissions on this file. Shown here: the 330 from organizations. Not shown, by design: submissions from private individuals, which we never publish, and anything filed since our last weekly refresh.

Committee ITRERapporteur Markéta Gregorová (Greens/EFA)
  1. Deliberations in Council · 9 Jun 2026
  2. Deliberations in Coreper · 3 Jun 2026
  3. Deliberations in Council working party · 28 May 2026
  4. Feedback on adopted proposal closed: The EU Cybersecurity Act — 93 responses · 12 May 2026
  5. Referral of the legislative proposal to the EP committee responsible (announced in plenary) · 25 Mar 2026

Who showed up

249 submissions from industry — companies and their trade associations — against 42 from civil society: NGOs, consumer organizations, environmental groups and trade unions. That is 5.9 industry submissions for every one from civil society.

Industry 249Civil society 42Public authorities, academia, other 39

Groupings use the respondent type each organization selected when filing. Counting submissions, not organizations — a body that filed twice is counted twice.

What the room declares

153 of 266
in the EU Register
601
full-time lobbying staff
€99.3M+
declared costs a year
455
EP accreditations declared

Self-declared to the EU Transparency Register (snapshot 30 Aug 2026). The cost figure sums band floors, so the true total is higher.

The file, right now

The consultation closed on 12 May 2026 — it ran from 5 Feb 2026.

Policy area
Digital & tech (DG CNECT)
Where it stands
Awaiting adoption
Legislative stage
Commission Proposal
Lead committee
ITRE
Commission reference
COM(2026)13

How it got here

  1. Call for evidence · impact assessment20 Jun 2025
  2. Public consultation20 Jun 2025
  3. Prop dir12 May 2026
  4. Proposal for a regulation12 May 2026

Also on the Commission’s pipeline for this file, with no date recorded: Initiative planned.

330 positions · showing 25

DD

DVF Deutsches Verkehrsforum e.V.

· · filed 12 May 2026 · source

PDF

Stellungnahme des Deutschen Verkehrsforums e.V. zum Vorschlag für eine Richtlinie des Europäischen Parlaments und des Rates zur Änderung der Richtlinie (EU) 2022/2555 im Hinblick auf Vereinfachungsmaßnahmen und die Angleichung an den Vorschlag für die Cybersicherheitsverordnung 2 Berlin, 12.05.2026/dp 1.

Opening of the attached position paper · the full paper is on the Commission’s record (source link above)

LinkedInX
SP

Sungrow Power Supply Co. ltd

· · filed 12 May 2026 · source

PDF

Sungrow welcomes the opportunity to provide input on the European Commission's proposal for the revision of the Cybersecurity Act. We recognise the proposal's ambition to strengthen EU cyber resilience and reduce regulatory fragmentation.

LinkedInX
IA

ISP Alliance a.s.

· · filed 12 May 2026 · source

PDF

Dear Members of the Commission, ISP Alliance a.s. represents more than 80 regional providers of publicly available electronic communications networks and services in the Czech Republic, most of them micro and small enterprises operating fixed networks.

LinkedInX
EC

European Cloud User Coalition

· · filed 12 May 2026 · source

PDF

We welcome the European Commission's initiative to revise the Cybersecurity Act and appreciate the opportunity to contribute to this important consultation. As a several European Financial institutions who operate across multiple Member States, we have a direct and substantial interest in ensuring robust cybersecurity frameworks that protect our operations, our customers, and the financial system as a whole.

LinkedInX
IC

IBM Corporation

· · filed 12 May 2026 · source

PDF

IBM welcomes the opportunity to provide feedback on the revised draft EU Cybersecurity Act (CSA2) and the targeted amendments to the NIS2 Directive. As a global provider of enterprise technology and cybersecurity solutions, we welcome the steps taken to update ENISAs mandate and certification development framework in line with the new legislation such as NIS2, CRA, DORA, reflecting the changing needs, roles and…

LinkedInX
CI

Chair in Cyber Policy, University of Luxembourg

· · filed 12 May 2026 · source

PDF

The Chair in Cyber Policy at the University of Luxembourg would like to submit its feedback in order to contribute to the legislative debate on the Proposal for a Regulation CSA2 and the targeted amendments to the NIS2 Directive.

LinkedInX
CI

Chair in Cyber Policy, University of Luxembourg

· · filed 12 May 2026 · source

PDF

The Chair in Cyber Policy at the University of Luxembourg would like to submit its feedback in order to contribute to the legislative debate on the Proposal for a Regulation CSA2 and the targeted amendments to the NIS2 Directive.

LinkedInX
E

Eurosmart

· · filed 12 May 2026 · source

PDF

Eurosmart welcomes the European Commissions proposal to amend Directive (EU) 2022/2555 (NIS2) through the Digital Omnibus simplification package and supports the objective of reducing unnecessary administrative burden while preserving a high level of cybersecurity across the Union.

LinkedInX
DS

Decathlon SE

· · filed 12 May 2026 · source

PDF

Decathlon welcomes the European Commissions proposal for the Cybersecurity Act 2 and appreciates the opportunity to provide feedback on this proposal. The Cybersecurity Act has been an efficient instrument while letting room for improvement.

LinkedInX
EF

Eclipse Foundation AISBL

· · filed 12 May 2026 · source

PDF

FOR FULL FEEDBACK PLEASE SEE THE ATTACHED PDF Eclipse Foundation Feedback on Proposals for the EU Cybersecurity Act COM(2026) 11 About this submission Headquartered in Brussels, and with 66% of its staff in Europe, Eclipse Foundation AISBL is Europes largest open source code-hosting foundation hosting over 400 open source projects that European industry relies on spanning cloud, IoT, automotive, AI, and developer…

LinkedInX
E

Eurosmart

· · filed 12 May 2026 · source

PDF

Eurosmart welcomes the European Commissions proposal to revise the Cybersecurity Act (CSA2) and supports the objective of strengthening and scaling the European cybersecurity certification framework in response to evolving cybersecurity threats and increasing digital dependencies.

LinkedInX
AC

American Chamber of Commerce to the EU

· · filed 12 May 2026 · source

PDF

Our position Cybersecurity Act review AmCham EU speaks for American companies committed to Europe on trade, investment and competitiveness issues. It aims to ensure a growth-orientated business and investment climate in Europe. AmCham EU facilitates the resolution of transatlantic issues that impact business and plays a role in creating better understanding of EU and US positions on business matters.

Opening of the attached position paper · the full paper is on the Commission’s record (source link above)

LinkedInX
CC

China Chamber of Commerce to the EU (CCCEU)

· · filed 12 May 2026 · source

PDF

The China Chamber of Commerce to the EU (CCCEU) welcomes the opportunity to provide feedback to the European Commission on the proposed revision of the Cybersecurity Act (CSA2). CCCEU acknowledges the importance of strengthening cybersecurity and protecting critical infrastructure.

LinkedInX
W

WIndEurope

· · filed 12 May 2026 · source

PDF

WindEurope welcomes the opportunity to provide feedback on the proposed revision of the Cybersecurity Act (CSA) and the possible amendments to the NIS2 Directive. We broadly support the direction of the CSA revision, including the reinforcement of ENISA's mandate, the move towards EU-level cybersecurity certification schemes, the recognition of non-technical risks, and the establishment of an EU-level trusted ICT…

LinkedInX
I

ISACA

· · filed 12 May 2026 · source

PDF

ISACA warns that the CSA2 risks creating a disproportionately burdensome attestation architecture for cybersecurity skills certifications and professional development. In the attached position paper, we argue that the EU does not need a new attestation market to make cybersecurity skills understandable.

LinkedInX
F

FEPORT

· · filed 12 May 2026 · source

PDF

The Federation of European Private Port Companies and Terminals FEPORT reply to the public consultation on the Cybersecurity Act II proposal Introduction FEPORT represents the interests of 2290 private port companies and terminals performing cargo handling and logistics related activities in European seaports.

Opening of the attached position paper · the full paper is on the Commission’s record (source link above)

LinkedInX
CF

Center for Cybersecurity Policy and Law

· · filed 12 May 2026 · source

PDF

12 May 2026 VIA ELECTRONIC SUBMISSION Re: Proposal for the Cybersecurity Act 2 (CSA2) The Hacking Policy Council (“HPC”)1 submits the following comments in response to the European Commission’s open consultation on its Proposal for the Cybersecurity Act 2 (CSA2).2 We appreciate the opportunity to comment on the effort to modernise EU’s foundational cybersecurity legislation.

Opening of the attached position paper · the full paper is on the Commission’s record (source link above)

LinkedInX
MC

Microsoft Corporation

· · filed 12 May 2026 · source

PDF

Microsoft recommendations regarding the EU Cybersecurity Act 2.0 May 2026 Executive summary Microsoft welcomes the European Commission’s proposal to revise the EU Cybersecurity Act (CSA 2.0) and supports its overarching objective of strengthening Europe’s cybersecurity resilience, trust, and regulatory coherence in an increasingly complex threat landscape.

Opening of the attached position paper · the full paper is on the Commission’s record (source link above)

LinkedInX
EL

European Local Fibre Alliance

· · filed 12 May 2026 · source

PDF

The European Local Fibre Alliance (ELFA), representing more than 1,200 alternative electronic communications operators and service providers across more than 11 European countries, welcomes the objective of strengthening cybersecurity and resilience within Europes digital infrastructure.

LinkedInX
DS

Dassault Systèmes

· · filed 12 May 2026 · source

PDF

May 2026 Dassault Systèmes’ position on the Cybersecurity Act Revision As a European software company, Dassault Systèmes welcomes the CSA2 proposal’s objective of reinforcing ENISA’s role, simplifying compliance requirements and improving the overall effectiveness and coherence of the European Cybersecurity Certification Framework (ECCF).

Opening of the attached position paper · the full paper is on the Commission’s record (source link above)

LinkedInX
SN

Svenskt Näringsliv/ Confederation of Swedish Enterprise

· · filed 12 May 2026 · source

PDF

The Confederation of Swedish Enterprise (SN) welcomes the goal of strengthening the EU's cybersecurity and reducing fragmentation in the internal market. Unfortunately, the European Commission is not taking the opportunity to significantly facilitate compliance and streamline the complex set of cybersecurity rules adopted in recent years.

LinkedInX
F

FiberCop

· · filed 12 May 2026 · source

FiberCop supports the overarching objective of the Cybersecurity Act 2 (CSA2) to ensure cybersecurity and resilience across the European digital ecosystem, recognising that secure and trustworthy digital infrastructure is fundamental to Europes competitiveness and technological sovereignty.

LinkedInX
Z

Zscaler

· · filed 12 May 2026 · source

PDF

Zscaler feedback on the revised EU Cybersecurity Act Brussels, 12 May 2026 Zscaler welcomes the opportunity to provide feedback to the proposal for a revision of the EU Cybersecurity Act. We welcome the objectives of the draft regulation, namely to revise the mandate of EU Cybersecurity Agency ENISA, to modernize the European Cybersecurity Certification Framework, and to introduce a new mechanism for conducting…

Opening of the attached position paper · the full paper is on the Commission’s record (source link above)

LinkedInX
VE

Vodafone España S.A.U.

· · filed 12 May 2026 · source

PDF

Vodafone Spain welcomes the opportunity to contribute to the European Commissions public consultation on the proposed revision of the cybersecurity framework. Vodafone Spain fully supports the European Unions objective of achieving a high and common level of cybersecurity across the Union.

LinkedInX
A

Aotec

· · filed 12 May 2026 · source

Spain is one of the few EU countries where the deployment of fiber optic (FTTH) is close to completion. An important reason for this success is the constant cooperation with major from China. We are concerned that European legislation.

LinkedInX
Take the dataCSV — all 330 submissionsJSONFull text, not the excerpt. Free to cite.Search every submission →

Follow this file

Get an email when a new organization files a position here: one email on Tuesdays, only when there is something new. Free.

We use your email for updates on this file, and PolicySpeak may contact you about the product. Unsubscribe in one click. Privacy policy.

Method. Every quote is verbatim from the organization’s own submission to the European Commission, trimmed to its opening passage and never summarized by a model. Where a submission was filed in another EU language we show the English text the European Commission publishes alongside it, labeled on the quote; the original is one click away at the source. Groupings use the respondent type the organization itself selected when filing. We deliberately do not label anyone “supportive” or “opposed” — you read what they wrote and draw your own conclusion. Organizations only, never individuals. Reused under Commission Decision 2011/833/EU; the European Commission is not liable for this reuse.