The EU’s Cyber-Compliance Deadline Passed — and Most Enterprises Aren’t Ready

Spread the love

NIS2 reached full effect in 2026, Germany’s BSI registration deadline was 6 March 2026, and 24-hour incident reporting is now live — yet many enterprises remain unprepared. Legacy stacks make compliance harder: no fast incident detection, un-auditable code, and data sitting on infrastructure they don’t govern under the CLOUD Act. The readiness gap is a strategic risk, not a paperwork one.

A compliance deadline is only as real as its enforcement, and NIS2’s has arrived. The obligations are live across the EU — and a surprising share of enterprises are discovering their stack was never built to meet them.

The deadline has passed, and the grace period was never coming. The EU’s NIS2 Directive reached full effect in 2026, bringing mandatory audits and a 24-hour incident-reporting obligation into live operation. In Germany, the implementing law took effect in December 2025 with no transition period, and in-scope entities had until 6 March 2026 to register with the Federal Office for Information Security (BSI). Those dates are now behind us. Yet by the accounts of legal and industry observers, a large share of European enterprises are still not ready.

What the milestone actually obliges

NIS2 substantially widens both the population of covered organisations and the weight of what they must do. As analysis on Lexology and from the law firm Freshfields has set out, the core obligations are now concrete: register with the national authority, submit to security audits, maintain risk-management measures, and — the operationally hardest part — file an initial incident report within 24 hours of becoming aware of a significant incident.

The penalties give those obligations teeth. Fines run up to EUR 10 million or 2% of annual turnover, and — a detail boards keep underestimating — management-body members can be held personally liable for culpable conduct. This is no longer a matter the security function absorbs on the organisation’s behalf. It reaches the individuals who sign off on cyber-risk posture.

The readiness gap

The gap between obligation and readiness is not primarily about intent; most organisations know the rules exist. It is about capability. The European DIGITAL SME Alliance has repeatedly flagged that smaller and mid-sized enterprises — a large slice of the newly in-scope population — lack the tooling and the in-house expertise to meet obligations of this shape. A 24-hour reporting clock assumes you can see an incident within hours. Many stacks simply cannot.

That is where the technical and the regulatory collide.

Why legacy stacks make compliance harder

Three properties of aging systems turn NIS2 from a governance task into a genuine engineering problem.

  • No fast incident detection. The 24-hour rule is unforgiving of slow, fragmented telemetry. Legacy platforms customised over a decade tend to scatter logs, bolt on monitoring after the fact, and surface anomalies late. If you cannot detect quickly, you cannot report on time — and late reporting is precisely the failure regulators are already penalising.
  • Un-auditable code. Audits assume you can show what your systems do. A heavily patched, opaque codebase that even its own maintainers no longer fully understand is hard to attest to with a straight face. Auditability is not a document you produce at the end; it is a property the architecture either has or lacks.
  • Data on infrastructure you don’t govern. Three US-based firms hold roughly 65% of the European cloud market. Under the US CLOUD Act, US authorities can compel a US-owned provider to disclose data even when the servers sit in an EU data centre. Data residency, in other words, is not data sovereignty. Governments have noticed: the Netherlands public sector runs a “prefer open” policy, and Copenhagen has drawn up plans to exit US cloud dependence. For an organisation trying to prove control of its own systems, running on infrastructure it does not ultimately govern is an awkward starting position.

An honest caveat

None of this means the deadline having passed triggers immediate penalties for everyone unprepared. Enforcement across 27 member states will be uneven and will take years to find its shape, and reasonable organisations remediate on realistic timelines. Anyone claiming the sky fell on 7 March is selling something. The sober reading is simply that the obligations are now live, the tolerances are tighter than the old regime, and the organisations most exposed are those whose architecture — not their intentions — makes fast detection and clean audit difficult.

The strategic turn: build for the audit, not around it

If detection speed, auditability and genuine sovereignty are the three pressures NIS2 applies, the durable answer is to run on infrastructure that has all three by design. That points toward modern, self-hosted platforms where telemetry is native, the code is inspectable, and the organisation governs its own data outright.

Disclosure: VBWD, which supports this article, builds precisely such a system — a full-stack, self-hosted SDK on an intentionally agnostic Python core, source-available so the code can be read and audited directly, and hosted on infrastructure the organisation controls rather than rents. The honest trade is real and worth stating: VBWD is younger than the incumbents and carries less accumulated edge-case maturity, trading that for architecture, speed and sovereignty. For many organisations now personally accountable under NIS2 that is the better trade; for some it will not be, and that is a decision to make with clear eyes. The fuller argument is set out in VBWD’s own piece, sovereign by default: commerce for the NIS2 era.

If this maps to a conversation happening inside your own organisation, the useful next step is specific rather than generic: see your own workload on modern, self-hosted infrastructure. Request an enterprise installation and bring the numbers you’re trying to improve.

Sources: Lexology, Freshfields and the European DIGITAL SME Alliance (NIS2 readiness analysis, 2026).

Happy
Happy
0%
Sad
Sad
0%
Excited
Excited
0%
Angry
Angry
0%
Surprise
Surprise
0%
Sleepy
Sleepy
0%

Germany’s First Big NIS2 Fine Lands: EUR 850,000 for Slow Incident Detection

Five Enterprise-Grade Products a Small Studio Could Ship This Quarter

Leave a Reply

Your email address will not be published. Required fields are marked *

1 × 1 =