White Paper: NIS2 Implementation: Challenges and Priorities

This comprehensive publication examines the current state of NIS2 implementation across member states and affected organisations, providing insights into adoption progress and readiness levels. 

This White Paper arrives at a critical juncture, as the majority of EU member states have yet to transpose the NIS2 Directive, despite the October 17, 2024 deadline. Our research provides a comprehensive analysis of:

  • The varying approaches to implementation across EU countries in key cybersecurity areas
  • Results from our Europe-wide survey of cybersecurity practitioners on organizational preparedness
  • Detailed case studies of sectoral implementation

The findings emphasise the critical need for countries to harmonise their approaches across Europe to address the current fragmentation. The document includes key takeaways from our analysis of national and companies implementation approaches, along with actionable recommendations for institutional stakeholders to enhance the implementation process.

Key takeaways: 

  1. Disproportionate Impact on Medium Sized Enterprises, Multinational Companies, Sectors with Lower Cybersecurity Maturity Level and Newly Introduced Entities in the Scope: the financial impact of implementation is particularly acute when considering both the technology investments and the needed changes in the processes combined with the lack of experience from being part of NIS1 and the need to follow varying requirements from multiple national authorities.
  2.  NIS2 Scope & Classification Disharmony: while NIS2 provides a foundational two-tier classification system, Member States are adopting varying approaches in entity classification ranging from single tier to three-tier systems.
  3. International Security Framework Diversity: Countries are taking distinctly different approaches to incorporating recognised frameworks – from direct references to specific frameworks in guidance documents to creating hybrid national standards that blend multiple frameworks.
  4. NIS2 incident reporting – timeline and classification variances. Member States are adopting significantly different notification timeframes, with some requiring initial incident reports within 6 hours compared to NIS2’s baseline 24-hour requirement.
  5. Budget Readiness –investment gap in organisational preparedness: survey data indicates that approximately 75% of organisations have not allocated dedicated financial resources for NIS2 implementation.
  6.  Management engagement –  critical Gap Between regulatory requirements and current practice: survey data shows that 34% of organisations indicate no upper management involvement in the NIS2 Implementation.

Online session

An online presentation of the White Paper took place on 22 January at 13:00 CET. The webinar included a Q&A session and an open discussion following the presentation.

ECSO NIS2 Directive Transposition Tracker

The NIS2 Directive Transposition Tracker is a collaborative project providing a streamlined and comprehensive overview of the Directive’s transposition across EU member states.

 

Organised into dedicated sections for each country, the tracker covers key aspects such as the sectoral scope, applicable standards, registration processes, sanctions, lists of competent authorities, and deadlines.

 

This initiative aims to identify similarities and differences in implementation while ensuring clarity for stakeholders navigating the evolving regulatory landscape.

About the ECSO Cyber Threat Management Working Group

The author of this paper is the ECSO Cyber Threat Management Working Group. The mission of this group is to provide support to organisations in tackling cyber threats, creating an environment for practitioners and end-users in cybersecurity where they can share information, lessons learned and best practices to increase cyber resilience of European companies and organisations.

Sebastijan Čutura

Senior Manager, Industry Cybersecurity

sebastijan.cutura[at]ecs-org.eu

Tomasz Michałowski

Junior Manager for European Cyber Security Community

tomasz.michalowski[at]ecs-org.eu

Share this publication on social media

Search

Recent Publications