NIS2 creates a major compliance challenge primarily because it massively expands the number and types of organizations in scope, extends into more industries, and can apply to entities with more than 50 employees depending on revenue, balance sheet total, and sector. This expansion is paired with stringent operational obligations, especially around incident identification, response, and rapid reporting, including an initial notification within 24 hours and a more detailed report within 72 hours. NIS2 also elevates Business Continuity Management (BCM)—including backups, disaster recovery, and crisis handling—into a core requirement, reinforcing the need for well-defined cybersecurity policies as the basis for coordinated action under pressure.
The directive mandates cyber hygiene and cybersecurity training, implying practical alignment with recognized best practices and frameworks such as ISO/IEC 27001:2022. Supply chain security becomes a major gap area because organizations must address security aspects not only internally but also across direct suppliers and service providers, including third-party access, onboarding/offboarding, and supplier assurance mechanisms such as certifications. NIS2 and the draft Implementation Regulation further require a strong cybersecurity posture with concrete measures like strong authentication, encryption where needed, asset management, and physical/logical access controls.
A further complication is uncertainty: the Implementation Regulation remains in draft close to national transposition deadlines, leaving country-specific reporting pathways and detailed expectations insufficiently defined and increasing non-compliance risk. The proposed approach is a phased, framework-driven program: confirm scope, assess current organizational and technical maturity, perform a gap analysis, prioritize actions, implement governance, and execute a roadmap supported by models such as the Cybersecurity Fabric and a reference architecture, underpinned by policies, processes, a Target Operating Model, and operational capabilities such as XDR/SOAR supported by internal teams and/or managed service providers.
See All Locations
See All Locations