In brief: A 34% compliance rate for NIS2 creates substantial pressure for most organizations in the remaining months before the deadline.
A study shows that by the NIS2 deadline in July, only 34% of companies are meeting regulatory requirements. This leaves little time for necessary cybersecurity measures.
Current data reveals a significant compliance gap in the implementation of the NIS2 Directive. With a compliance rate of 34% among affected organizations, two-thirds of companies remain behind regulatory requirements, despite the deadline approaching steadily.
For CISOs, this situation means high operational priority. NIS2 establishes binding requirements for cybersecurity governance, incident management, penetration testing, and supply chain management. A delayed start on compliance risks not only certifications but also fines and reputational damage. The remaining time allows only for prioritized, targeted measures — an ad-hoc approach becomes critical.
Organizations should immediately conduct a gap analysis, compare existing control mechanisms against NIS2 requirements, and roadmap missing controls with timelines. In parallel, quick wins such as policy updates, training, and initial incident response processes can be implemented promptly. The focus is on prioritization: which controls are mandatory, which are organization-specific and optional — and in what order do we close the gaps?
Source: news.google.com · Published 12 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.