Skip to content

NIS2 Implementation: Two-Thirds of SMEs Report Security Gaps

The Point: Around two-thirds of SMEs report they are not yet sufficiently equipped to meet NIS2 Directive requirements.

A survey shows that 65 percent of small and medium-sized enterprises have not yet adequately built up their cybersecurity for the NIS2 Directive. For CISOs, compliance implementation thus becomes a strategic priority.

A recent survey documents a significant security gap in the implementation of the NIS2 Directive across the SME landscape: 65 percent of surveyed small and medium-sized enterprises report inadequate security measures to meet regulatory requirements.

The NIS2 Directive requires enterprises in critical infrastructure and other strategic sectors to meet elevated cybersecurity standards. For CISOs, this figure represents massive need for action: not only must their own organizations adapt their security architecture, but compliance evidence must also be provided – for many SMEs, the technical and organizational foundations for this have not yet been established.

The reasons for this delay often lie in resource scarcity, lack of technical expertise, and budget constraints. For CISOs in the DACH region, this creates a dual scenario: either they must act quickly as leaders of their own organizations, or they advise SMEs as external partners in addressing this compliance challenge. The implementation timelines for the NIS2 Directive leave no room for further delays.


Source: news.google.com · Published 21 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: