Current view on NIS2 enforcement landscape, compliance implications, and where the directive sits in EU cybersecurity regulation. Dated, revisable.
State of the view as of 2026-05-12
What NIS2 does well
- Broadened sector scope. 18 sectors vs NIS1's 7. Captures critical-infrastructure reality of 2020s digital economy.
- Harmonized size thresholds. Reduces Member-State-discretion fragmentation.
- Article 21 minimum measures. Explicit baseline cybersecurity expectations.
- Tight reporting timelines. 24h / 72h / 1-month structure forces incident-response maturity.
- Management body liability (Art 20). Cybersecurity at board level by mandate.
- Supply chain security (Art 21(d)). Recognition that supply-chain is critical attack vector.
- EU-CyCLONe + CSIRT network. Operational cooperation infrastructure for large incidents.
- Penalty teeth. Up to €10M / 2% turnover for essential entities.
What NIS2 does poorly
- Transposition variance. Member States transpose differently; harmonization is partial. DE NIS2UmsuCG, NL Cyberbeveiligingswet, FR transposition, others all have specifics.
- Identification ambiguity. Self-identification places burden on entities; medium-size entities at sector edges face classification uncertainty.
- Supervision capacity ramp-up. National competent authorities still resourcing through 2025-2026.
- Overlap with sector regulation. Financial services (DORA), digital products (CRA), AI systems (AI Act) all overlap with NIS2 obligations. Coordination guidance still developing.
- Definition of "significant incident" is qualitative. 24h early warning trigger uncertain in marginal cases.
- SME burden. Smaller entities in scope (50+ staff) face cost-disproportionate compliance.
Where the evidence currently sits
- Transposition completed in most Member States by mid-2025 (some lagging — Commission infringement procedures pending against several).
- Implementing acts published 2024-2025 detailing technical specifications.
- ENISA guidance rolling out continuously.
- First major enforcement actions plausibly visible 2026-2027 as authorities ramp.
- Industry compliance work mature in larger essential entities; mid-size + important entities lagging.
Personal calibration
- Working assumption for client engagements: scope-assessment per client — is the client an essential or important entity?
- Working assumption for AI work in NIS2-scope entities: AI systems are part of the entity's network and information systems; subject to Art 21 measures.
- Working assumption for vendor relationships: NIS2-scope clients require supply-chain due diligence; expect questions from clients to their vendors (including AI-tool consultants).
- Working assumption for incident response: 24h early warning capability is mandatory; pre-built notification workflows essential.
What would shift this view
- Major NIS2-related enforcement actions (2026-2027) will clarify supervisory authority priorities.
- Implementing acts further specifying Art 21 measures.
- Cross-regulator coordination guidance (NIS2 + DORA + AI Act + CRA + GDPR).
- CJEU jurisprudence on key terms ("significant incident", entity classification, supply-chain scope).