NIS2 position

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Current view on NIS2 enforcement landscape, compliance implications, and where the directive sits in EU cybersecurity regulation. Dated, revisable.

State of the view as of 2026-05-12

What NIS2 does well

  • Broadened sector scope. 18 sectors vs NIS1's 7. Captures critical-infrastructure reality of 2020s digital economy.
  • Harmonized size thresholds. Reduces Member-State-discretion fragmentation.
  • Article 21 minimum measures. Explicit baseline cybersecurity expectations.
  • Tight reporting timelines. 24h / 72h / 1-month structure forces incident-response maturity.
  • Management body liability (Art 20). Cybersecurity at board level by mandate.
  • Supply chain security (Art 21(d)). Recognition that supply-chain is critical attack vector.
  • EU-CyCLONe + CSIRT network. Operational cooperation infrastructure for large incidents.
  • Penalty teeth. Up to €10M / 2% turnover for essential entities.

What NIS2 does poorly

  • Transposition variance. Member States transpose differently; harmonization is partial. DE NIS2UmsuCG, NL Cyberbeveiligingswet, FR transposition, others all have specifics.
  • Identification ambiguity. Self-identification places burden on entities; medium-size entities at sector edges face classification uncertainty.
  • Supervision capacity ramp-up. National competent authorities still resourcing through 2025-2026.
  • Overlap with sector regulation. Financial services (DORA), digital products (CRA), AI systems (AI Act) all overlap with NIS2 obligations. Coordination guidance still developing.
  • Definition of "significant incident" is qualitative. 24h early warning trigger uncertain in marginal cases.
  • SME burden. Smaller entities in scope (50+ staff) face cost-disproportionate compliance.

Where the evidence currently sits

  • Transposition completed in most Member States by mid-2025 (some lagging — Commission infringement procedures pending against several).
  • Implementing acts published 2024-2025 detailing technical specifications.
  • ENISA guidance rolling out continuously.
  • First major enforcement actions plausibly visible 2026-2027 as authorities ramp.
  • Industry compliance work mature in larger essential entities; mid-size + important entities lagging.

Personal calibration

  • Working assumption for client engagements: scope-assessment per client — is the client an essential or important entity?
  • Working assumption for AI work in NIS2-scope entities: AI systems are part of the entity's network and information systems; subject to Art 21 measures.
  • Working assumption for vendor relationships: NIS2-scope clients require supply-chain due diligence; expect questions from clients to their vendors (including AI-tool consultants).
  • Working assumption for incident response: 24h early warning capability is mandatory; pre-built notification workflows essential.

What would shift this view

  • Major NIS2-related enforcement actions (2026-2027) will clarify supervisory authority priorities.
  • Implementing acts further specifying Art 21 measures.
  • Cross-regulator coordination guidance (NIS2 + DORA + AI Act + CRA + GDPR).
  • CJEU jurisprudence on key terms ("significant incident", entity classification, supply-chain scope).

See also