Compliance & Risk

NIS2 Is Here, and Most Mid-Market Enterprises Aren't Ready

The NIS2 Directive requirements are now in force. A frank assessment of where most organisations stand, which gaps are most urgent to close, and what regulators are likely to scrutinise first.

JP
James Park
· May 3, 2026 · Compliance & Risk
Executive reviewing NIS2 compliance documentation in a modern office setting

Key Takeaways

  • 68% of mid-market enterprises in NIS2 scope have not completed a formal gap assessment, leaving them exposed to penalties that can reach 2% of global annual turnover or €10 million, whichever is greater.
  • NIS2 covers 18 sectors, a significant expansion from NIS1's original scope, capturing thousands of organisations that were not previously subject to European network and information security legislation.
  • Regulators have indicated they will prioritise three areas in early enforcement: risk management policy documentation, incident reporting capability with a 72-hour notification window, and supply chain security governance.
  • Organisations that demonstrate good-faith compliance effort, including a completed gap assessment and a remediation roadmap with executive sign-off, are significantly better positioned for regulatory engagement than those with no programme in place.

The NIS2 Directive became enforceable across EU member states in October 2024, and the compliance calendar has been running ever since. Yet the data on enterprise readiness remains deeply concerning. According to research from the European Union Agency for Cybersecurity, 68% of mid-market enterprises that fall within the Directive's expanded scope have not completed a formal gap assessment. That figure is not a measure of organisations with gaps in their controls. Every organisation has gaps. It is a measure of organisations that have not yet taken the basic first step of understanding where they stand. For those enterprises, the exposure is not theoretical: penalties under NIS2 can reach 2% of global annual turnover or €10 million, whichever figure is greater.

The scope expansion from NIS1 to NIS2 is the single most important administrative fact for compliance officers to internalise. The original NIS Directive covered seven sectors, applying primarily to operators of essential services in energy, transport, water, health, digital infrastructure, banking, and financial market infrastructure. NIS2 extends the framework to 18 sectors, adding postal services, waste management, manufacturing of critical products, food production, and a substantially broader definition of digital providers. Importantly, the size thresholds have changed as well: medium-sized enterprises with at least 50 employees or more than €10 million in annual turnover may now fall within scope in many of the new essential or important entity categories. The result is that thousands of organisations that never engaged with NIS1 are now regulated entities with formal obligations and a limited window in which to demonstrate they understand them.

The enforcement posture of national competent authorities across the EU is not yet uniform, but the direction of travel is clear. Germany's BSI, France's ANSSI, and the Netherlands' NCSC have all signalled proactive supervisory activity, including the issuance of questionnaires to newly in-scope organisations, requests for documentation of risk management frameworks, and the use of on-site inspection powers. Organisations operating across multiple EU jurisdictions face an additional layer of complexity: the lead authority principle under NIS2 means that cross-border operators must understand which member state's regulator holds primary supervisory responsibility for their activities. Getting that determination wrong at the outset can delay the entire compliance programme and, in adversarial enforcement scenarios, complicate the regulatory dialogue considerably.

The Compliance Gaps That Will Get Organisations Fined

The three enforcement priority areas that regulators have most consistently flagged are risk management policy documentation, incident reporting capability, and supply chain security governance. Of the three, the risk management documentation gap is the most prevalent and, paradoxically, the easiest to close with focused effort. NIS2 Section 21 specifies that essential and important entities must implement risk management measures covering ten defined areas: policies on risk analysis and information system security, incident handling, business continuity, supply chain security, acquisition and development of network systems, cybersecurity training, cryptography and encryption, personnel security, access control policies, and asset management. Most mid-market organisations have operational practices in the majority of these areas. The gap is overwhelmingly one of documentation and governance: the policies exist in practice but are not formally documented, have not been approved by senior management, and cannot be produced on demand during a supervisory inspection.

The incident reporting gap is more technically demanding to close. NIS2 requires a two-stage notification process: an early warning to the competent authority within 24 hours of becoming aware of a significant incident, followed by a more detailed incident notification within 72 hours. Many organisations do not currently have the detection and classification infrastructure to determine within 24 hours whether an incident meets the NIS2 significance threshold, which is defined by reference to the disruption caused to the provision of services, the number of users affected, and the duration of the disruption. Building that capability requires investment in SIEM tooling, on-call escalation procedures, pre-agreed classification criteria, and a clear chain of authority for making the reporting determination. For organisations without a mature security operations function, this is a six-to-twelve-week remediation programme at minimum, even under ideal conditions.

Supply chain security governance is the longest lead-time item in the NIS2 compliance programme and the area where most organisations are furthest behind. The Directive requires that essential and important entities assess the security practices of their key suppliers and service providers, covering both the suppliers' own security posture and the broader security of the products and services they deliver. The practical challenge is significant: a mid-market enterprise with 200 active suppliers cannot conduct meaningful individual security assessments of each of them within a compliance timeframe. The emerging practice is to tier suppliers by criticality, apply standardised security questionnaires to Tier 1 and Tier 2 suppliers, and document the methodology transparently enough that regulators can see a coherent and proportionate approach to the requirement.

"The organisations that are in the worst position right now are not the ones with gaps in their controls. Everyone has gaps. The ones in the worst position are the ones who have done nothing at all. Regulators have a track record of looking most unfavourably on organisations that cannot demonstrate any good-faith compliance effort."

Sophie Brennan, Partner, EU Cybersecurity Regulatory Practice, Linklaters

A Practical Prioritisation Framework

For organisations that have not yet begun their NIS2 programme, the prioritisation framework needs to be built around urgency and lead time simultaneously. Tier 1 actions should begin immediately and focus on the administrative foundations without which nothing else is possible. The first step is a scope determination: is your organisation actually covered by NIS2, and under which entity category? This is not always a simple question, and in some cases legal counsel familiar with the transposing national legislation should be involved. Once scope is confirmed, a gap assessment covering all ten Section 21 areas should begin. The gap assessment does not need to be exhaustive to be valuable. A structured assessment conducted over two to three weeks by a small internal team, validated against the relevant national authority's published guidance, will produce an actionable prioritisation of remediation work. Finally, at this stage, a named NIS2 compliance owner should be appointed with explicit executive sponsor authority. Without a single accountable owner, remediation programmes consistently stall at the first obstacle.

Tier 2 actions, to be completed within 30 to 60 days of programme launch, should focus on the two areas with the highest enforcement priority. The incident reporting capability gap requires dedicated project ownership, because it cuts across IT operations, security, legal, and executive communications. The deliverable at the 60-day mark should be a documented and tested incident classification and notification procedure, with named individuals responsible for each step of the 24-hour and 72-hour reporting workflow. The risk management policy framework should also be in draft form by this point, with at minimum the gap assessment findings translated into a structured policy document that can be reviewed by senior management. Even a partially completed policy framework that shows active progress is materially better than no documentation at all.

Tier 3 actions, to be completed within 60 to 120 days, cover the longer-lead-time elements of the compliance programme. The supply chain security assessment programme should be designed and initiated, starting with the Tier 1 supplier population. Board-level reporting should be formalised: NIS2 places explicit responsibility on management bodies for cybersecurity governance, and regulators will look for evidence that cybersecurity risk is reported to and considered by the board on a regular cadence. Staff awareness training covering the organisation's NIS2 obligations and basic security hygiene should be delivered to all staff and documented. Proactive engagement with the relevant national competent authority, through voluntary dialogue or industry working groups, is also worth considering at this stage. Regulators in most member states have indicated a preference for cooperative relationships with newly in-scope entities, and early engagement establishes goodwill before any enforcement interaction.

The enforcement calendar is accelerating. Germany and the Netherlands are among the most advanced in transposition and early supervisory activity, and their approaches will influence peer regulators across the bloc. The mutual recognition element of NIS2 means that a supervisory finding in one member state can have direct implications for an organisation's regulatory standing in others. The cost calculus is straightforward: starting a NIS2 compliance programme today, even an imperfect one, is substantially less expensive than starting one in response to a notification, an inspection, or an enforcement investigation. The gap assessment is the critical first step. Organisations that have not taken it have no credible way to assess their own exposure.

Share

More in Compliance & Risk

All Resources →