NIS2 Enforcement Is Live. 84% of Organisations Are Not Ready.

Part 1 of the NIS2 Compliance Series by Garzon Cyber Solutions. This series examines what NIS2 enforcement means for every level of the organisation: boards and executives (Part 1), CISOs (Part 2), CTOs (Part 3), and the frontline workforce (Part 4).
First penalties issued. Personal liability is now active at leadership level. And the vast majority of in-scope organisations still have not done the work.
The Readiness Illusion
NIS2 spent two years as a future problem. Something to prepare for eventually. A regulatory horizon that felt comfortably distant.
That comfort evaporated in Q1 2026. Twenty-two of 27 EU member states have transposed the directive into national law. Germany, France, and the Netherlands are actively auditing and issuing fines. The enforcement phase is operational, not theoretical.
CyberSmart surveyed 670 in-scope business leaders across eight European countries this April. The findings should alarm every boardroom on the continent: 84% admit their organisations are not ready. Only 16% consider themselves fully prepared. And 11%, remarkably, were unsure what NIS2 actually is, despite sitting squarely within its scope.
Not a minor gap. A structural exposure at the leadership level, playing out in real time.
The Penalty Architecture
NIS2 was designed with penalties large enough to command attention at the executive table.
Essential entities, those in energy, transport, health, and digital infrastructure, face a ceiling of €10 million or 2% of global annual revenue, whichever bites harder. Important entities spanning manufacturing, food, waste, and postal services face €7 million in losses, or 1.4%. These figures are not hypothetical. Administrative fines landed in Q1 2026, and regulators across the most active jurisdictions have shifted their posture from guidance to enforcement.
Personal Liability: The Provision Most Boards Have Missed
Ask a board member about NIS2 penalties, and they will usually reference the organisational fines. Ask about personal liability, and the room goes quiet.
Article 20 places direct accountability on management bodies for approving cybersecurity risk management measures and completing regular training. Read that again: approving, not delegating. The directive requires directors to understand the substance of their organisation’s security posture. Signing a document prepared by the IT department does not satisfy it.
Germany has gone furthest. Individual managers there face fines of up to €500,000 for governance failures, entirely separate from any penalty on the company. Directors can be temporarily banned from holding management roles. Other member states are moving in the same direction.
If you sit on a board and have been treating NIS2 as a compliance workstream managed three levels below you, Article 20 is the reason that needs to change.
Why the Gap Persists
Indifference is not the problem. 75% of the leaders CyberSmart surveyed acknowledge that compliance confers a competitive advantage. They get it. The barriers sitting between acknowledgement and readiness are structural.
Budget came first among the obstacles cited. Then, there is unclear implementation guidance. Then a shortage of internal expertise. All three are compounded by the talent crisis ENISA documented in its 2025 analysis: a deficit of 299,000 cybersecurity professionals across the EU, three-quarters of organisations struggling to attract qualified candidates, and 71% unable to retain the staff they manage to hire.
Regulatory scope has expanded. The workforce has not expanded with it. And unlike previous regulatory cycles, there is no transitional grace period to fall back on. The clock started months ago.
What Compliance Actually Demands
Treating NIS2 as a project with a deadline and a finish line is a mistake that will surface at the worst possible moment: during an audit, an incident, or a regulatory inquiry.
Compliance under NIS2 is continuous. It spans risk management, incident response, supply chain oversight, and board-level accountability. The areas where most organisations are weakest are well known. Monitoring and response processes are incomplete. Evidence bases, logs, structured reports, and documented risk assessments are thin or absent. Supply chain obligations are addressed through a one-off vendor questionnaire. Cloud and identity environments that have not been hardened. Incident playbooks that cannot meet the 24-hour early warning window.
Closing these gaps takes sustained investment in governance capability, backed by leadership with the authority to direct it and technical professionals with the skill to deliver it. A single procurement decision will not get you there.
The Board’s Responsibility
There is a pattern I see repeatedly. The board says cybersecurity matters. A CISO or CTO gets the brief. Budget arrives, usually thin. Compliance becomes a workstream, reviewed quarterly at best, and assumed to be on track because nobody has raised a flag.
Then the regulator arrives and asks a different set of questions entirely. Not whether the organisation has a cybersecurity team. Whether the management body can demonstrate that it has approved specific risk management measures. Whether it understands the residual risk profile. Whether its members have completed the training NIS2 requires.
Personal liability exists to close exactly this gap. Delegation is not a defence under the directive. Informed engagement at the highest level is the standard.
The Commercial Dimension
Penalties and personal exposure are the stick. The commercial upside is worth understanding, too.
Regulated customers are already building NIS2 alignment into their procurement requirements, regardless of whether the supplier falls directly in scope. Insurance underwriters are recalibrating premiums based on governance maturity. Institutional investors are weighing regulatory readiness in their risk models. Procurement teams are writing compliance into contracts.
Organisations that reach genuine NIS2 compliance will carry a measurable edge in procurement cycles, insurance terms, and stakeholder confidence. Those who do not will find themselves gradually excluded from the commercial relationships where compliance has become a prerequisite.

Closing the Gap
Garzon Cyber Solutions works with boards, CISOs, and senior technology leaders to close the distance between where their security and compliance posture sits today and where NIS2 enforcement now requires it to be. That work spans three integrated capabilities.
Cybersecurity Advisory. Board-level risk translation, CISO advisory, security architecture governance, and incident readiness. We provide the strategic capability that enables leadership teams to govern cyber risk with the rigour regulators now expect.
Compliance and Regulatory Readiness. Operationalising NIS2 alongside DORA, the EU AI Act, ISO 27001, and SOC 2 through a single integrated governance structure. Not shelf ware. Working frameworks that hold up under audit.
Security and Technology Talent. Sourcing, assessing, and placing the cybersecurity and compliance professionals that the market cannot produce at scale. We understand what integrated security functions are needed because we advise them.
NIS2 enforcement is here. The organisations that close the readiness gap now will operate with confidence through the enforcement cycle ahead. The rest will make headlines.
Sources: CyberSmart NIS2 Compliance Survey, April 2026. ENISA NIS Investments Report, 2025. NIS2 Directive (EU) 2022/2555. German NIS2 implementation, management liability provisions. ECSO transposition tracker, March 2026.
Where does this sit on your own risk register?
A short, practical conversation about where the exposure actually is, and what a proportionate response looks like. No obligation and no product pitch.
Start the Conversation →