Compliance

The CISO’s NIS2 Burden: Ten Obligations, One Team, No Room for Failure

G
Jonathan Garzon
Founder & CEO, Garzon Cyber Solutions
April 2026 · 5 min read
The CISO’s NIS2 Burden, Part 2 of the NIS2 Compliance Series by Garzon Cyber Solutions

Part 2 of the NIS2 Compliance Series by Garzon Cyber Solutions. Part 1 examined the board’s exposure. This instalment turns to the person expected to deliver: the CISO.

We covered the readiness gap in Part 1. 84% of in-scope organisations admit they are not prepared. Personal liability at the board level is already operational, and penalties landed in Q1 2026.

So what happens next? Boards turn to the Chief Information Security Officer. One question: where do we stand?

Most CISOs I speak with already know the answer. Obligations have expanded. Headcount and budget have not kept pace.

Article 21: The Ten Measures No One Can Ignore

Article 21 of the directive sets out 10 cybersecurity risk management measures that every essential entity must implement. All ten. Not a subset. Regulators in Germany, France, and the Netherlands are already auditing against them.

What falls under those ten? Everything from risk analysis and incident handling through to business continuity, supply chain security, and cryptography policies. Throw in acquisition controls, effectiveness assessments, cyber hygiene training, access management, and multi-factor authentication, and you start to see why no single project plan can cover it. You are looking at a permanent operating model, not something with a go-live date and a handover.

Documentation alone won’t satisfy auditors. Each measure has to function in practice, with evidence you can produce when asked. CISOs who have been working towards ISO 27001 or SOC 2 will recognise plenty of overlap. Where NIS2 goes further is supply chain oversight, the speed required for incident reporting, and one provision that catches people off guard: board members themselves must sign off on risk management measures and undergo cybersecurity training. Personally. Not through a delegate.

The 24 Hour Clock

Article 23 introduces an incident-reporting obligation that most organisations have not stress-tested.

You get twenty-four hours. From the moment anyone in the organisation becomes aware of a significant incident, a clock starts running. Within that window, an early warning must be sent to your national CSIRT or competent authority. And the early warning cannot be vague. Regulators want an initial assessment: was this malicious? Could it cross borders?

Then comes the 72-hour follow-up with a more detailed notification. One month after the incident, a final report is due covering the root cause, what you did about it, and any cross-border consequences.

In practice? I have yet to meet a CISO whose current playbook would hold up under that kind of pressure. Escalation paths wind through too many people. At 2 am on a Saturday, nobody is entirely certain who can authorise external notification. The data you need to assess cross-border implications is stored in systems that most teams cannot query quickly enough. And the coordination required between technical, legal, and communications teams has almost never been rehearsed at anything close to Article 23 speed.

When the process falls apart during a real incident, the CISO is the one standing before the regulator, explaining why.

Supply Chain: The Obligation Most Are Avoiding

NIS2 explicitly requires organisations to manage cybersecurity risk across their supply chains. Not with a vendor questionnaire completed during onboarding and buried in a folder nobody revisits. The directive expects continuous, documented assessment of every supplier relationship. Contractual provisions that specifically address cybersecurity. Proof that you actually monitor how your suppliers handle their own security posture.

Most in-scope organisations are nowhere near that standard.

For CISOs in manufacturing, digital infrastructure, or healthcare, supplier dependencies run deep and wide. This single obligation could swallow an entire team’s capacity. And the professionals who can actually deliver it, people who blend GRC knowledge with supply chain risk expertise and genuine regulatory fluency, are among the scarcest profiles in the European market right now.

The Capacity Equation

Every obligation above runs into the same wall.

ENISA’s 2025 analysis put the EU cybersecurity workforce deficit at 299,000 professionals. 89% of CISOs report their teams are understaffed. Attracting qualified candidates is a struggle for three out of four organisations, and 71% struggle to retain the people they manage to bring on board.

NIS2 expanded the CISO’s mandate considerably. The talent pool did not expand with it. And regulators will not accept “we know we have a gap, but we cannot find the people” as a reason for non-compliance.

Consider what Article 21 demands in purely human terms. Somebody has to run risk analysis. Somebody else has to execute incident response under live pressure at speed. Supply chain oversight requires GRC specialists with niche expertise. Cryptography and access control rely on engineers. Training programmes require someone to design and deliver them. Continuous monitoring means a team operating around the clock, every day.

Budget, authority, and a capable team. Get all three, and compliance becomes achievable. In most organisations I work with, at least one is missing. Usually two.

What Evidence Actually Looks Like

NIS moved the conversation from “do you have a cybersecurity programme” to “prove it works.” NIS2 pushed that bar considerably higher.

What do regulators actually want to see? Structured risk assessments built on methodologies that they can follow and challenge. Incident response plans are tested against realistic scenarios, not written up once and left on a shelf. Supply chain risk registers that reflect where suppliers stand today, not where they stood eighteen months ago. Training records showing genuine comprehension, not just a tick in the completion column. Monitoring logs that are centralised, tamper-resistant, and reviewed on a schedule you can demonstrate.

Awareness and compliance are very different things. A CISO who acknowledges the gaps is in a fundamentally different position from one who can show, with hard evidence, that those gaps are actively closing. NIS2 only recognises the latter.

NIS2 CISO compliance infographic: 10 mandatory risk management measures under Article 21, 24 hour incident reporting window under Article 23, 89% of CISOs understaffed, 299,000 cybersecurity professional deficit across the EU. Garzon Cyber Solutions.

Closing the Gap

Garzon Cyber Solutions works alongside CISOs and security leadership teams to build the operational capabilities required by NIS2 compliance.

Cybersecurity Advisory. From incident readiness and response architecture to board-level risk translation, we provide the strategic support that enables CISOs to operate at the governance level while maintaining operational grip. We help build the reporting structures, evidence frameworks, and escalation processes that stand up to regulatory scrutiny.

Compliance and Regulatory Readiness. We operationalise NIS2’s Article 21 requirements alongside DORA, ISO 27001, and SOC 2 through integrated governance structures. Not shelf ware. Auditable, working frameworks that close the gap between obligation and evidence.

Security and Technology Talent. We source, assess, and place the GRC, incident response, and security engineering professionals that CISOs cannot find through generalist channels. We understand what integrated security functions are needed because we advise them.

Any CISO who waits for the next budget cycle to address the capacity gap will find themselves explaining that decision to a regulator who is not interested in hearing about hiring timelines.

Garzon Cyber Solutions: Cybersecurity · Compliance · Talent · garzoncybersolutions.com

Sources & references: NIS2 Directive (EU) 2022/2555, Articles 21 and 23. ENISA, NIS Investments Report, 2025. ENISA Threat Landscape, 2025. CyberSmart, NIS2 Compliance Survey, April 2026.

Where does this sit on your own risk register?

A short, practical conversation about where the exposure actually is, and what a proportionate response looks like. No obligation and no product pitch.

Start the Conversation →
#NIS2#Compliance#CyberSecurity#Governance#Regulation#GarzonCyberSolutions