Compliance

How to Be Prepared for NIS2 Compliance Update?

How to Be Prepared for NIS2 Compliance Update

The EU’s NIS2 compliance deadline — October 17, 2024 — has come and gone, but the compliance work it triggered hasn’t. Most member states have now transposed the directive into national law, registration windows have opened and closed, and 2026 is widely described as the year supervisory authorities move from guidance to active enforcement. Yet only 16% of businesses in scope say they’re confident they’re fully compliant. If your organization is still treating NIS2 as a deadline you either hit or missed, this guide walks through where enforcement actually stands in 2026, what’s changed since the original rollout, and how to close the gap — including where a compliance audit fits into getting there.

The short version: NIS2’s transposition deadline passed in October 2024, but national implementation has rolled out unevenly since — Germany’s registration window closed July 31, 2026, the Netherlands enters full enforcement mid-2026, and Spain and France are still finalizing their national rules. The European Commission proposed further amendments to the directive in January 2026, and the adjacent Cyber Resilience Act adds its own reporting obligations starting September 11, 2026. NIS2 isn’t a deadline you missed or made — it’s an ongoing compliance posture regulators are now actively checking.

Where NIS2 Stands in 2026: From Deadline to Enforcement

NIS2 (the updated Network and Information Security Directive) was due to be transposed into the national law of all 27 EU member states by October 17, 2024. That date marked a legal deadline for governments to pass implementing legislation — not a single EU-wide date on which every covered business suddenly became compliant. In practice, transposition and enforcement have rolled out unevenly ever since:

Member state / groupStatus as of 2026
Most of the EU (~22–24 of 27 states)Transposed into national law, with implementing legislation and competent authorities in place
GermanyAmended BSI Act in force since December 6, 2025; registration deadline extended once to July 31, 2026 — now closed. Late registration still carries its own fine of up to €500,000, separate from substantive-violation fines
NetherlandsLaw enacted, with a staggered entry into full enforcement around mid-2026
SpainStill in active legislative process; remains under the older NIS1-based Royal Decree 43/2021 regime pending completion, expected late 2026
FranceTransposition act adopted; implementing decrees still being finalized

Adding to the moving target: the European Commission proposed targeted amendments to NIS2 in January 2026 as part of a broader EU cybersecurity package. The proposal would adjust the directive’s scope — bringing submarine data-cable infrastructure operators in, taking chemical distributors out (manufacturers stay in scope), adding a requirement to disclose whether a ransom was demanded and paid after a significant ransomware incident, and expanding which companies must appoint an EU representative. None of this is finalized, but it underlines the point: NIS2 compliance in 2026 means tracking a directive that’s still being tuned, not checking a box against a document that hasn’t changed since 2024. Germany’s BSI, for instance, publishes its own running guidance on which organizations must register under the national implementation — worth checking directly if you operate there, since the detail changes as the rules get finalized.

Whatever stage your country is at, the underlying obligation hasn’t changed — businesses in scope need their digital infrastructure and data management practices to be secure, resilient, and adaptable to evolving threats, backed by evidence a regulator can actually review. For the official legal text, see Directive (EU) 2022/2555 on EUR-Lex.

Why NIS2 Still Matters for European Businesses

The case for NIS2 was never really about the October 2024 date — it’s about the threat environment the directive was built to address, which has kept getting worse, not better. According to ENISA’s Threat Landscape 2025 report, which analyzed 4,875 incidents across the EU between July 2024 and June 2025, public administration was the single most targeted sector at 38% of incidents, ransomware activity fragmented across 82 distinct variants rather than concentrating on a few dominant groups, and AI-enabled phishing made up more than 80% of observed social-engineering activity by early 2025.

Why NIS2 Still Matters for European Businesses

That 16% figure comes from a survey of 670 business leaders across the UK, Poland, the Netherlands, Ireland, France, Germany, Denmark, and Belgium — and 11% of respondents said they were still unsure whether NIS2 even applied to their organization. That’s the real 2026 story: not a deadline that already happened, but a compliance gap most businesses in scope still haven’t closed, right as supervisory authorities shift from advisory guidance to active audits.

Which Industries Fall Under NIS2

NIS2 significantly broadened the sectoral scope of the original 2016 directive. Businesses now fall into one of two categories — “essential” or “important” entities — spanning sectors including energy, transport, banking, financial market infrastructure, health, drinking water and wastewater, digital infrastructure, ICT service management, public administration, and space, alongside a second tier covering postal and courier services, waste management, chemicals, food, manufacturing, and digital providers. Size thresholds generally apply (roughly 50+ employees or €10M+ turnover for important entities, 250+ employees or €50M+ turnover for essential entities), though certain critical providers are in scope regardless of size.

The practical effect for many businesses is indirect: NIS2 doesn’t always name your industry outright, but if you provide hosting, cloud, data-center, or CDN services to a company that is named — or if you’re a supplier deep in an essential entity’s chain — NIS2 obligations can reach you through that relationship even when you’re not separately listed.

NIS2 Fines and Penalties in 2026

The headline fine ceilings set by the directive haven’t changed:

Entity typeMaximum fineOther consequences
Essential entitiesUp to €10 million or 2% of global annual turnover, whichever is higherPersonal liability can extend to management for serious non-compliance
Important entitiesUp to €7 million or 1.4% of global annual turnover, whichever is higherSame personal-liability exposure for management
Late registration (example: Germany)Up to €500,000A separate, standalone penalty — distinct from substantive control failures

What’s changed is the enforcement posture around those numbers. Member states can set fine ceilings above the directive’s floor — Germany does — so multi-country operators should check local caps rather than assuming the EU minimums are the actual worst case. And 2026 is the year several national authorities, including Germany’s BSI, have moved from publishing guidance to actively auditing in-scope organizations. No wave of major published fines has landed as of this writing, but the shift from a grace period to active oversight is itself the headline: the deadline for having a compliance program was 2024; the deadline for having a defensible one is now.

NIS2, DORA, and the Cyber Resilience Act: Which Regime Applies

NIS2 no longer sits alone. Two adjacent EU regulations now overlap with it for a growing number of businesses, and 2026 is the year all three become operationally real at once:

RegulationWho it coversKey 2026 development
NIS2Essential and important entities across critical sectors (energy, health, digital infrastructure, and more)National registration deadlines closing through 2026; supervisory authorities shifting to active enforcement
DORAFinancial entities and their critical ICT third partiesFirst real supervisory enforcement cycle underway; Register of Information filings were due March 31, 2026, with incomplete third-party registers flagged as an enforcement priority
Cyber Resilience Act (CRA)Manufacturers of products with digital elements sold in the EUVulnerability and incident reporting obligations take effect September 11, 2026 — over a year ahead of the CRA’s full application in December 2027

The CRA’s new reporting clock is tight: manufacturers must submit an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe incident, a detailed notification within 72 hours, and a final report once corrective measures are available. For businesses already carrying NIS2 and, in some cases, DORA third-party risk obligations, the practical challenge is that these regimes currently run on parallel reporting tracks with no single consolidated channel — which makes incident-response process design, not just underlying security controls, a genuine 2026 compliance problem in its own right.

NIS2's 2024 deadline was the start of a multi-year rollout, not its end — 2026 is when it converges with the Cyber Resilience Act and DORA's own enforcement cycles.

How to Prepare for NIS2 Compliance

Whether your organization missed the original 2024 window entirely or has been working toward compliance since, the practical steps in 2026 look like this — or start with a structured self-assessment using our free NIS2 Compliance Checklist:

  • Confirm your registration status. If your country’s national registration deadline has passed and you haven’t registered with the competent authority, register now — late registration is typically treated more leniently than continued non-registration, but it isn’t free (see Germany’s €500,000 late-registration fine above).
  • Run a current risk assessment against NIS2’s actual control requirements — not the 2024 version of your infrastructure, but what’s running today.
  • Build or update your incident-reporting process to handle NIS2’s notification timelines alongside any DORA or CRA obligations that apply to the same business, rather than maintaining separate, uncoordinated processes for each.
  • Review third-party and sub-processor relationships, particularly hosting, cloud, and data-center providers, since NIS2 obligations can reach your organization through those relationships even when you’re not separately named in scope.
  • Get an independent technical read on where you actually stand — a compliance audit verifies the infrastructure behind your evidence, not just whether a policy document exists.

A few mistakes show up repeatedly in NIS2 readiness work:

  • Assuming the October 2024 deadline means the work is done. Transposition is a legal starting gun, not a finish line — enforcement is still ramping up in 2026.
  • Treating NIS2, DORA, and the CRA as separate projects when a business is in scope of more than one — the underlying security-control evidence overlaps significantly, and building one coordinated program is far more efficient than three parallel ones.
  • Skipping the registration step because the underlying security work feels more urgent — registration is a distinct, time-bound legal obligation with its own penalty, separate from your actual control maturity.
  • Not accounting for the moving target. With the Commission’s January 2026 amendment proposal still working through the legislative process, scope and reporting requirements may shift again before the current cycle settles.

Organizations without an in-house compliance function often route this work through a managed partner rather than building it internally — see our guide to Compliance as a Service for MSPs for how that model works. Teams that want a more ISO 27001-aligned path into NIS2 readiness can also see our NIS2 compliance solution overview.

Choosing an EU Cloud Provider for NIS2 Compliance

Many businesses are consolidating data operations within the EU specifically to simplify NIS2 compliance and reduce their reliance on sub-processors outside Europe — fewer cross-border data flows to document, fewer third-party relationships to monitor, and a shorter chain between your infrastructure and the regulator’s actual jurisdiction. When evaluating a provider against NIS2 requirements, prioritize transparent data-processing locations, minimal reliance on further sub-processors, a demonstrable compliance track record, and clear contractual commitments to EU-based data handling. For a deeper look at what that evaluation actually involves, see our guide to choosing an EU cloud provider.

Also, Gart Solutions, together with our partner — vBoxx, a renowned EU cloud solutions provider, offers a range of managed hosting and cloud server services that can significantly support businesses in their digital transformation journey.

1. Understanding the NIS2 Directive 

The NIS2 Directive represents a significant evolution in EU cybersecurity regulation, broadening the scope of compliance requirements to include a wider array of sectors. This directive underscores the necessity of not only securing data but also understanding its entire journey. 

Organizations must be vigilant about tracking their data flow to mitigate risks and meet the stringent new standards imposed by NIS2.

2. Comprehensive Data Tracking

Compliance with NIS2 requires an in-depth understanding of where and how data is processed, stored, and transferred. This involves documentation of every stage of the data lifecycle — from creation and processing to storage and eventual deletion. By mapping out the data journey, organizations can better identify vulnerabilities and ensure that all parties involved in data handling adhere to high security standards.

3. The Challenge of Sub-processors

One of the most complex challenges introduced by NIS2 is the need for organizations to maintain visibility over all sub-processors involved in data processing. Each sub-processor, regardless of their role, must meet the same rigorous cybersecurity standards. This requires thorough vetting and ongoing monitoring to ensure compliance, making it critical for businesses to establish strong relationships and clear communication channels with their sub-processors.

4. Strategic Shifts in the Market

In response to NIS2, many businesses are re-evaluating their reliance on third-party sub-processors, especially those located outside the EU. By consolidating data operations within the EU, organizations can better manage compliance and reduce the risk of data breaches. 

This trend towards localized data handling is reshaping the market, as companies seek to simplify their data ecosystems and enhance security.

5. Practical Steps for Compliance

To align with NIS2, businesses must take proactive measures, such as engaging closely with their service providers, conducting comprehensive risk assessments, and considering a shift to EU-based data centers and services. These steps not only facilitate compliance but also strengthen the overall cybersecurity posture, ensuring that the organization is well-prepared to meet current and future regulatory demands.

Measures, to align with NIS2

How Not to Repeat Mistakes: Case of Microsoft

If you say, we are using public data providers, there’s still are pitfalls we have to consider. 

Let’s take, for example, Microsoft. Microsoft’s products continue to be widely used, but they present significant challenges in transparency and data security. 

At the time of writing, Microsoft lists 47 subprocessors and 36 data centers, but details on their operations and data handling are unclear. This is concerning given Microsoft’s ongoing GDPR violations and multiple security breaches last year. 

Moreover, the global spread of subprocessors, often linked to parent companies in various countries, adds complexity and potential security risks, making it difficult for companies to verify compliance and data safety.

Final words

Prepare your business for the NIS2 compliance update with the expert guidance of Gart Solutions. Download our Free Checklist — a comprehensive guide to the NIS2 audit, and ensure your organization is ready for the upcoming changes. 

Wanna know how? Contact us.

Schedule a Free Consultation

See how we can help to overcome the challenges of NIS2 compliance.

You might also like

FAQ

What is the NIS2 Directive and why is it important?

The NIS2 Directive is a significant update to the original Network and Information Security (NIS) Directive that was implemented in 2016. This update strengthens cybersecurity measures across the European Union (EU) by expanding the scope of the industries it covers and introducing stricter regulations. It's crucial for European businesses as it aims to enhance resilience against rising cyberattacks, enforce proactive risk management, and improve collaboration in threat response.

What are the penalties for non-compliance with NIS2?

Essential entities face fines of up to €10 million or 2% of global annual turnover, whichever is higher; important entities face up to €7 million or 1.4% of global annual turnover. Management can face personal liability for serious violations, and some member states set fine ceilings above these EU minimums.

How can my organization prepare for the NIS2 compliance update?

To prepare for NIS2 compliance, organizations should start by identifying their compliance status. Conducting a thorough security risk assessment, developing a robust cybersecurity strategy, and investing in employee training are essential steps. Partnering with a cybersecurity solutions provider like Gart Solutions can also help ensure that your organization is fully compliant by the deadline.

What should I consider when choosing a cloud solutions provider for NIS2 compliance?

When selecting a cloud solutions provider, it's important to ensure that they have a strong track record of data security and compliance with EU regulations. The provider should offer comprehensive data tracking and management services, maintain transparency with their operations, and minimize reliance on third-party subprocessors. By choosing a provider like vBoxx, which specializes in data management within the EU, your organization can better manage compliance and reduce the risk of data breaches.

How does NIS2 relate to the Cyber Resilience Act and DORA?

All three are separate EU regulations that can apply to the same business at once. NIS2 covers essential and important entities across critical sectors; DORA covers financial entities and their critical ICT third parties; the Cyber Resilience Act covers manufacturers of products with digital elements and introduces its own vulnerability and incident reporting obligations starting September 11, 2026. They currently run on separate reporting tracks, so businesses in scope of more than one need a coordinated process rather than three siloed ones.

Why are only 16% of businesses NIS2-compliant in 2026?

According to a CyberSmart/OnePoll survey of 670 business leaders published in April 2026, only 16% of organizations in scope of NIS2 are confident they're fully compliant, and 11% weren't even sure the directive applied to them. The gap reflects how unevenly national transposition and enforcement have rolled out since the October 2024 deadline, plus the ongoing complexity of coordinating NIS2 with adjacent regulations like DORA and the CRA.

What is changing in the EU's proposed 2026 NIS2 amendments?

In January 2026, the European Commission proposed targeted amendments to NIS2: adding submarine data-cable infrastructure operators to scope, removing chemical distributors (manufacturers remain covered), requiring disclosure of whether a ransom was demanded and paid after a significant ransomware incident, and expanding which companies must appoint an EU representative. These are proposals working through the legislative process, not yet final law.

How can Gart Solutions help with NIS2 compliance?

Gart Solutions offers a range of services to help businesses navigate the complexities of NIS2 compliance. These include conducting security risk assessments, developing tailored cybersecurity strategies, providing employee training, and offering expert guidance throughout the compliance process. Gart Solutions, in partnership with vBoxx, also provides cloud solutions that align with the stringent requirements of NIS2, ensuring your business is well-prepared for the update.
arrow arrow

Thank you
for contacting us!

Please, check your email

arrow arrow

Thank you

You've been subscribed

We use cookies to enhance your browsing experience. By clicking "Accept," you consent to the use of cookies. To learn more, read our Privacy Policy