The Bottom Line: Less than 35 percent of affected companies have fully implemented NIS2; CISOs must drive accelerated implementation under compliance pressure.
A current survey shows that only 34 percent of companies have fully met the requirements of the NIS2 Directive so far. For CISOs, this means a significant implementation gap in the coming months.
Implementation of the European Network and Information Security Directive (NIS2) is falling behind schedule. Only about one third of surveyed companies have fully implemented the required security standards to date. The directive aims to increase protection of critical infrastructure as well as companies in systemically relevant sectors.
For Chief Information Security Officers, this presents a dual challenge: On the one hand, technical and organizational measures must be prioritized and implemented promptly. On the other hand, NIS2 requires continuous risk assessment and documented governance processes that are not yet fully established in many organizations. Regulatory deadlines are approaching, and non-compliance carries significant fines.
The delay can be traced to various factors: ambiguities in the interpretation of individual requirements, resource shortages in security teams, and the complexity of required organizational changes. CISOs should now establish a structured roadmap for the remaining implementation period and negotiate necessary investments with senior management.
Source: news.google.com · Published July 29, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.