NIS2 · CELEX 02022L2555-20221227
Article 19
Verbatim text of the current consolidated version (consolidated 2022-12-27) · status: in force. Check it on EUR-Lex ↗
NIS2, Article 19(1) — Peer reviews
The Cooperation Group shall, by 17 January 2025 , establish, with the assistance of the Commission and ENISA, and, where relevant, the CSIRTs network, the methodology and organisational aspects of peer reviews with a view to learning from shared experiences, strengthening mutual trust, achieving a high common level of cybersecurity, as well as enhancing Member States’ cybersecurity capabilities and policies necessary to implement this Directive. Participation in peer reviews is voluntary. The peer reviews shall be carried out by cybersecurity experts. The cybersecurity experts shall be designated by at least two Member States, different from the Member State being reviewed. The peer reviews shall cover at least one of the following: (a) the level of implementation of the cybersecurity risk-management measures and reporting obligations laid down in Articles 21 and 23; (b) the level of capabilities, including the available financial, technical and human resources, and the effectiveness of the exercise of the tasks of the competent authorities; (c) the operational capabilities of the CSIRTs; (d) the level of implementation of mutual assistance referred to in Article 37; (e) the level of implementation of the cybersecurity information-sharing arrangements referred to in Article 29; (f) specific issues of cross-border or cross-sector nature.
NIS2, Article 19(2) — Peer reviews
The methodology referred to in paragraph 1 shall include objective, non-discriminatory, fair and transparent criteria on the basis of which the Member States designate cybersecurity experts eligible to carry out the peer reviews. The Commission and ENISA shall participate as observers in the peer reviews.
NIS2, Article 19(3) — Peer reviews
Member States may identify specific issues as referred to in paragraph 1, point (f), for the purposes of a peer review.
NIS2, Article 19(4) — Peer reviews
Before commencing a peer review as referred to in paragraph 1, Member States shall notify the participating Member States of its scope, including the specific issues identified pursuant to paragraph 3.
NIS2, Article 19(5) — Peer reviews
Prior to the commencement of the peer review, Member States may carry out a self-assessment of the reviewed aspects and provide that self-assessment to the designated cybersecurity experts. The Cooperation Group shall, with the assistance of the Commission and ENISA, lay down the methodology for the Member States’ self-assessment.
NIS2, Article 19(6) — Peer reviews
Peer reviews shall entail physical or virtual on-site visits and off-site exchanges of information. In line with the principle of good cooperation, the Member State subject to the peer review shall provide the designated cybersecurity experts with the information necessary for the assessment, without prejudice to Union or national law concerning the protection of confidential or classified information and to the safeguarding of essential State functions, such as national security. The Cooperation Group, in cooperation with the Commission and ENISA, shall develop appropriate codes of conduct underpinning the working methods of designated cybersecurity experts. Any information obtained through the peer review shall be used solely for that purpose. The cybersecurity experts participating in the peer review shall not disclose any sensitive or confidential information obtained in the course of that peer review to any third parties.
NIS2, Article 19(7) — Peer reviews
Once subject to a peer review, the same aspects reviewed in a Member State shall not be subject to a further peer review in that Member State for two years following the conclusion of the peer review, unless otherwise requested by the Member State or agreed upon after a proposal of the Cooperation Group.
NIS2, Article 19(8) — Peer reviews
Member States shall ensure that any risk of conflict of interest concerning the designated cybersecurity experts is revealed to the other Member States, the Cooperation Group, the Commission and ENISA, before the commencement of the peer review. The Member State subject to the peer review may object to the designation of particular cybersecurity experts on duly substantiated grounds communicated to the designating Member State.
NIS2, Article 19(9) — Peer reviews
Cybersecurity experts participating in peer reviews shall draft reports on the findings and conclusions of the peer reviews. Member States subject to a peer review may provide comments on the draft reports concerning them and such comments shall be attached to the reports. The reports shall include recommendations to enable improvement on the aspects covered by the peer review. The reports shall be submitted to the Cooperation Group and the CSIRTs network where relevant. A Member State subject to the peer review may decide to make its report, or a redacted version of it, publicly available.
This text is not written by an AI. It is rendered from a corpus built from the official EUR-Lex source, where every fragment is content-hashed and signed at ingestion — which is what lets you cite it and defend the citation. Ask a question about this article →
Other articles of the NIS2
Art. 1Art. 2Art. 3Art. 4Art. 5Art. 6Art. 7Art. 8Art. 9Art. 10Art. 11Art. 12Art. 13Art. 14Art. 15Art. 16Art. 17Art. 18Art. 19Art. 20Art. 21Art. 22Art. 23Art. 24Art. 25Art. 26Art. 27Art. 28Art. 29Art. 30Art. 31Art. 32Art. 33Art. 34Art. 35Art. 36Art. 37Art. 38Art. 39Art. 40Art. 41Art. 42Art. 43Art. 44Art. 45Art. 46
Acquis returns official sources verbatim with citations; it is not legal advice. Texts © European Union, reuse permitted (Decision 2011/833/EU) — only the EUR-Lex original is authentic. Why legal AI fails · Coverage