Compliance

NIS2 Compliance: The Gap Between Directive and Delivery

G
Jonathan Garzon
Founder & CEO, Garzon Cyber Solutions
February 2026 · 3 min read

NIS2 was meant to raise the baseline. In practice, it has exposed a chasm between what the directive requires and what most in-scope organisations can actually evidence.

Scope has quietly exploded

The shift from NIS to NIS2 pulled an estimated 160,000+ entities into scope across sectors including manufacturing, food, waste, postal services, and digital infrastructure. Many of these organisations have never operated under a formal cybersecurity regulatory regime before. They are now managing obligations originally written for critical national infrastructure.

Where delivery is breaking down

  • Governance. NIS2 makes management bodies personally accountable and requires documented cyber risk training. Most boards have neither.
  • Supply chain. The directive demands active assessment of supplier risk, yet most in-scope firms still rely on a one-off vendor questionnaire as their primary control.
  • Incident reporting. The 24-hour early warning is tighter than most internal incident playbooks accommodate. Firms without a rehearsed decision framework will miss it.
  • Transposition drift. Member states have implemented NIS2 at different speeds and with local variations. Multi-jurisdictional firms are effectively managing several slightly different regimes under one directive.

The commercial lens

NIS2 penalties are material, €10M or 2% of global turnover, but the larger commercial risk is downstream. Regulated customers will increasingly require NIS2 alignment from their suppliers, whether the supplier is directly in scope or not. That makes this a procurement issue long before it is a penalty issue.

The organisations getting this right are treating NIS2 as a structural upgrade to their operating model, not a paperwork exercise. The ones treating it as paperwork will be the ones making headlines when the first enforcement actions land.

Where does this sit on your own risk register?

A short, practical conversation about where the exposure actually is, and what a proportionate response looks like. No obligation and no product pitch.

Start the Conversation →
#NIS2#Compliance#CyberSecurity#Governance#Regulation#GarzonCyberSolutions