On 3 August 2026, the European Commission issued a corrigendum to Implementing Regulation (EU) 2024/2690, correcting a technical requirement in the Annex that applies to a wide range of digital service providers. The correction, published as C(2026) 5716 final, replaces the phrase "making a backup or archiving keys" with "recovering lost or damaged keys" in point 9.2(c)(viii) of the Annex, on page 28 of the Regulation. This change clarifies the cybersecurity risk-management measure expected from entities covered by the act, including DNS providers, cloud computing services, data centre services, online marketplaces, search engines, social networking platforms, and trust service providers.

The original Implementing Regulation (EU) 2024/2690 was adopted on 17 October 2024 and published in the Official Journal on 18 October 2024, laying down technical and methodological requirements for cybersecurity risk-management measures under Directive (EU) 2022/2555, the NIS2 Directive. The Regulation specifies, among other things, the cases in which an incident is considered significant for these entities. The corrigendum does not alter the scope of the Regulation or its overall obligations; it only refines the wording of one specific measure, shifting the focus from maintaining backups or archives of keys to ensuring the ability to recover lost or damaged keys.

For affected organisations, the practical effect is limited but concrete: compliance documentation and internal procedures should now reflect that the required measure is key recovery, not merely backup or archiving. This distinction may affect how entities design their cryptographic key management practices, particularly in terms of disaster recovery and business continuity planning. The correction is technical in nature and does not introduce new obligations or change the timeline for compliance, which remains aligned with the original Regulation's application date.

The corrigendum is part of the Commission's ongoing implementation of the NIS2 framework, which has been progressively rolled out since the Directive entered into force. While this specific correction is minor, it underscores the importance of precise technical language in cybersecurity regulations, where small wording changes can have operational implications for the entities subject to the rules. The Commission's action also highlights the iterative nature of regulatory implementation, as it fine-tunes requirements based on practical feedback and legal clarity.

Stakeholders most directly affected are the digital service providers listed in the Regulation, which must update their compliance documentation to reflect the corrected wording. National supervisory authorities responsible for enforcing NIS2 may also need to align their guidance and inspection criteria with the revised measure. For these entities, the impact is moderate in terms of administrative adjustment but low in terms of new costs, as the change clarifies an existing requirement rather than adding a new one. The corrigendum does not affect consumers or end-users directly, as it concerns internal risk-management practices rather than service delivery.

The correction will be published in the Official Journal of the European Union, and it is expected that the European Parliament and the Council will take note of it as part of their ongoing oversight of NIS2 implementation. No further legislative action is required, as the corrigendum is a technical amendment to an existing implementing act.

← Atlas › News › Digital & Communication