NIS2 Enforcement Has Started: A CISO Compliance Roadmap
NIS2 Enforcement Has Started: A CISO Compliance Roadmap
NIS2 Enforcement Has Started: A CISO Compliance Roadmap
Short answer: NIS2 has moved out of the transposition-and-guidance phase and into active supervision, and 2026 is the year regulators started asking for evidence instead of intentions. If you are in scope, the work is a sequence, not a scramble: confirm scope, run a gap assessment against the ten risk-management measures, build an evidence file that proves governance actually happened, and rehearse the incident reporting timeline before you need it. Management personal liability is the part that changes the board conversation, so start there.
I have watched a lot of compliance regimes arrive. Most of them land softly: a directive, a grace period, a round of conference talks, then a slow drift into checkbox territory. NIS2 is tracking differently. With the directive now in active supervision and enforcement across member states in 2026, supervisory authorities are conducting audits, requesting documentation, and in some cases interviewing management directly. The question they ask is not whether you have a firewall. It is whether your leadership approved the risk-management measures, whether they were trained to oversee them, and whether you can prove both on paper.
First, establish whether you are actually in scope
Scope is where most organizations waste their first quarter, arguing about it instead of confirming it. The directive covers essential and important entities across eighteen sectors energy, transport, health, digital infrastructure, manufacturing of critical products, digital providers, and more generally at the medium-size threshold and above, with some entities in scope regardless of size. Two traps deserve attention. First, the supply chain pull: even if you fall outside the sectors, your in-scope customers will push requirements into your contracts, so you may end up meeting the standard anyway. Second, group structures: a subsidiary in one member state can drag reporting obligations across the group. Get a written legal opinion on scope, per entity, per country. It costs a fraction of what guessing wrong costs.
What regulators are actually asking for
Strip away the recitals and NIS2 asks for documented evidence of risk governance. Article 21 lists the measures: risk analysis and information system security policies, incident handling, business continuity, supply chain security, secure development and vulnerability handling, effectiveness measurement, cyber hygiene and training, cryptography, HR security and access control, and multi-factor authentication where appropriate. Nothing on that list should surprise a functioning security program. What surprises people is the evidentiary standard. A policy that exists but was never approved by management, never versioned, and never read is treated as absent. An incident process that has never been exercised is treated as untested, because it is.
This is why I tell peers to treat the policy layer as a governance artifact, not paperwork. A policy needs an owner, an approval record, a review date, and a link to the controls that implement it. If yours are stale, rebuilding from a clean information security policy template is faster than renovating a decade of accumulated drafts, and it gives you the approval trail the auditor will ask for on day one.
Personal liability changes the board conversation
The provision that gets attention in the boardroom is management accountability. Under NIS2, management bodies must approve the risk-management measures, oversee their implementation, and undergo training and they can be held personally liable for infringements, up to and including temporary bans from management functions for essential entities. I have briefed boards for two decades, and no slide about threat actors ever produced the quality of attention that this clause produces.
Use that attention well. The wrong move is fear theater. The right move is to give directors a clean mechanism for doing their job: a risk register they can actually read, decisions framed as accept, mitigate, transfer, or avoid, and minutes that record who decided what. My cyber risk register template exists for exactly this purpose every material risk gets an owner, a decision, and a date, so when a supervisor asks how management oversaw cyber risk, the answer is a document trail rather than a recollection.
The reporting timeline is tighter than your muscle memory
NIS2 reporting runs on a clock most incident teams have not internalized: an early warning to your CSIRT or competent authority within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within a month. Twenty-four hours is short. It is shorter at 2 a.m. on a Saturday when the person who knows which portal to file through is on leave. The fix is rehearsal: run a tabletop where the output is an actual draft early-warning notification, written against the clock, with the legal reviewer in the room. You will find the gaps who declares significance, who drafts, who approves in ninety minutes of exercise instead of during a live incident.
One practical note: the early warning is deliberately allowed to be thin. Report what you know, flag what you do not, and update. The regulators I have spoken with are far more concerned about silence than about an early report that later gets revised.
A sequence that works
Quarter one: scope confirmation with legal sign-off, entity by entity, and a management briefing that lands the liability point. Quarter two: gap assessment against Article 21, honest and internally led if you have the skill, external if you need the independence. Rate each measure on two axes is it implemented, and can you prove it because those are different questions and the second one is where most programs fail. Quarter three: close the evidence gaps. Approvals, training records, exercise reports, review dates. Quarter four: rehearse reporting, brief the board on residual risk, and record their acceptance of whatever you are consciously not fixing yet.
None of this is exotic. That is rather the point. NIS2 rewards organizations that run security as a governed program and exposes the ones that ran it as a collection of tools. If your program is sound, the work is mostly assembling proof. If assembling proof feels impossible, that is a finding in itself.
Supply chain security: the measure most programs underestimate
Of the ten Article 21 measures, supply chain security is the one I see most consistently underbuilt. The directive expects you to assess the security of your direct suppliers and service providers, weigh the quality of their development practices, and reflect all of it in your contracts. A supervisor reviewing this measure wants three things: a register of your critical suppliers, security requirements written into the agreements that govern them, and evidence that assessment results actually changed something a remediation demand, a contract clause, a decision to exit. An annual questionnaire that nobody reads fails on the third point, and the third point is the one that gets tested.

Be realistic about depth. Nobody can meaningfully audit three thousand vendors, and pretending otherwise produces shallow coverage everywhere. Tier the population: the handful of suppliers whose failure would stop your operation get real scrutiny architecture conversations, incident notification clauses with hard deadlines, tested exit plans. The long tail gets baseline contractual requirements and monitoring. Documenting that tiering decision is itself evidence of risk governance, which is the currency this whole regime trades in.
One more overlap worth planning for: if you are also in scope for DORA, GDPR breach notification, or sector rules, a single incident can trigger three reporting clocks with different definitions of severity. Map those triggers side by side now, on one page, and decide in advance who files what. Doing that mapping during a live incident is how deadlines get missed and regulators get irritated.
Frequently Asked Questions
When does NIS2 enforcement actually start?
Enforcement is live now. Member states transposed the directive into national law, and 2026 has seen supervisory authorities move from issuing guidance to conducting audits, requesting evidence, and opening proceedings. Waiting for a further signal is no longer a defensible plan.
Who is personally liable under NIS2?
Management bodies of in-scope entities. They must approve cybersecurity risk-management measures and oversee implementation, and they can be held personally liable for infringements, with essential-entity managers facing possible temporary bans from management functions in serious cases.
What evidence do NIS2 auditors ask for?
Approved and versioned policies, a maintained risk register with management decisions recorded, incident response documentation and exercise reports, supplier security requirements in contracts, training records including management training, and proof that reporting timelines have been rehearsed.
What are the NIS2 incident reporting deadlines?
An early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month. The early warning may be brief; regulators prefer a thin, timely report over a polished late one.