sedicii nis2 guidance

The NIS2 Directive: Overcoming the Implementation Challenge  

The European Union’s NIS2 Directive marks a significant step forward in strengthening cybersecurity across member states. Building on the original NIS Directive, NIS2 addresses emerging challenges by broadening its scope, enhancing security requirements and promoting greater harmonisation of the approach to cybersecurity among EU countries. 

What is NIS2? 

NIS2, or the Network and Information Security 2 Directive, is a European Union regulation designed to enhance the cybersecurity of essential and important entities across a wide range of sectors. It builds on the original NIS Directive introduced in 2016, introducing stricter requirements, expanding its scope to include additional sectors and entities, and fostering a more unified approach to cybersecurity across member states. The directive aims to improve incident reporting, ensure stronger security measures and promote greater resilience against cyber threats in a rapidly evolving digital landscape. 

Current State of NIS2 Implementation 

As of December 2024, the transposition of NIS2 into national law varies significantly across the EU. Only Croatia, Italy, Belgium and Lithuania have fully implemented the directive, while many others anticipate completion by early 2025, according to ESCO. This staggered adoption has led to operational challenges, particularly for organisations operating in multiple countries. Variations exist in entity classification, sector inclusion, incident reporting protocols and compliance deadlines, creating a fragmented cybersecurity landscape. 

In its recent white paper NIS2 Implementation: Challenges & Priorities, the ECSO highlights the, “… critical need for harmonisation across Europe to address the current fragmentation in scopes, tiering, and implementation approaches.” 

Organisational Preparedness for NIS2 and Challenges 

An ESCO survey of 155 respondents from 23 countries reveals notable gaps in organisational readiness for NIS2 compliance: 

  • Budget Constraints: Approximately 75% of organisations lack dedicated budgets for NIS2 implementation. 
  • Management Engagement: One-third report no involvement from management, despite legal obligations being clearly identified. 

Key Challenges Identified: 

  • Ambiguity in implementation requirements 
  • Concerns regarding supply chain security 
  • Complexities in incident reporting 
  • Difficulties aligning with various security frameworks 

While interactions with supervisory authorities are ongoing, organisations highlight the need for improved communication and practical guidance to navigate these challenges effectively. 

Sector-Specific Insights Related to NIS2

The white paper provides detailed case studies across various sectors, highlighting: 

  • Mature Implementation: Sectors with prior regulatory experience, such as those under NIS1, exhibit more advanced implementation strategies. 
  • Adaptation Challenges: Newly regulated sectors face steeper learning curves in adapting to NIS2 requirements. 

Common Themes among companies: 

  • Leveraging existing security frameworks 
  • Integrating multiple compliance requirements 
  • Variations in cybersecurity maturity influencing implementation approaches 
What Impact will NIS2 Have on SMEs 

While small and medium-sized enterprises (SMEs) may not be directly within the scope of NIS2, they are significantly affected through supply chain provisions. Medium-sized enterprises, in particular, face challenges in resource allocation to meet compliance demands, underscoring the need for tailored support and guidance. 

Recommendations for Harmonised Implementation of NIS2

To address the challenges identified and promote a cohesive cybersecurity framework across the EU, ECSO offers several recommendations: 

  1. Enhanced Communication: Foster open dialogue between regulatory authorities and organisations to clarify requirements and expectations. 
  2. Resource Allocation: Encourage organisations to allocate dedicated budgets and involve management in the implementation process. 
  3. Support for SMEs: Provide tailored guidance and resources to assist SMEs in meeting compliance obligations. 
  4. Leveraging Existing Frameworks: Advocate for the integration of current security frameworks to streamline compliance efforts. 
  5. Cross-Border Collaboration: Promote cooperation among member states to harmonise implementation approaches and reduce fragmentation. 
Opportunities with NIS2

The NIS2 Directive presents an opportunity to enhance cybersecurity resilience across the European Union. However, its success depends on coordinated implementation, clear communication and support for all affected entities, including SMEs. By addressing the challenges outlined and embracing the recommendations provided, member states and organisations can work together to create a more secure digital environment. 

For a comprehensive analysis and detailed insights, see the full white paper from ESCO.

 

This article is part of Sedicii’s ongoing thought leadership in support of Project PHACKS, an initiative focused on building collaborative communities to address complex cybersecurity and data privacy challenges. PHACKS is funded by the European Union and brings together organisations to explore new approaches to secure data collaboration utilising privacy enhancing technologies. Through this work, Sedicii contributes its expertise in advanced cryptography, secure data collaboration and digital identity to promote safer, more transparent digital ecosystems across Europe. The views expressed herein reflect the author’s perspective and do not necessarily represent those of the European Union. Learn more about Project PHACKS.

Scroll to Top