In a nutshell: Only approximately 33 percent of regulated companies have completed their NIS2 registration.
Implementation of the NIS2 Directive is progressing more slowly than hoped: only about one-third of affected companies have registered so far. This reveals significant compliance gaps with the EU cybersecurity regulation.
Registration rates in the implementation of the Network and Information Security Directive 2 (NIS2) point to substantial compliance delays. Current data shows that so far only about one-third of affected organisations have completed their registration.
For CISOs, this status represents a critical area for action: failure to register not only exposes an individual company to regulatory sanctions, but also signals sector-wide implementation shortfalls. NIS2 requires operators of critical infrastructure and digital service providers to register with competent authorities and to implement security measures in accordance with the state of the art.
The low registration rate reflects typical implementation obstacles: uncertainty in determining which organisations are in scope, resource constraints in security teams, and lack of prioritization at executive level. Particularly critical is the time factor – with approaching deadlines and increasing enforcement by national regulatory authorities, the sanction risk for non-compliant companies grows exponentially.
CISOs should immediately conduct an inventory to clarify registration obligations and involve management and compliance teams in accelerating implementation. Registration itself is often only the first step – it is followed by comprehensive organisational and technical measures to reduce risk.
Source: news.google.com · Published 10 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.