{
  "id": 4008421,
  "title": "NIS2 Isn't Compliance Theatre—It's a Liability Shift",
  "url": "https://urgent.news/2026/08/28/nis2-isnt-compliance-theatre-its-a-liability-shift",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-28T18:00:54.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/analogique/nis2-isnt-compliance-theatre-its-a-liability-shift-5625"
  },
  "original_language": "en",
  "account": "The European Union's NIS2 Directive brings about significant changes to cybersecurity regulations. Contrary to popular belief, NIS2 is not just an updated version of the earlier NIS Directive from 2016; it represents a fundamental shift in the responsibility for cybersecurity in Europe, extending beyond the original scope that covered only essential services such as energy, water, transport, healthcare, and finance.\n\nWhat sets NIS2 apart is its inclusion of roughly 150,000 additional organisations across the EU that were previously outside the regulatory net. These include digital service providers, cloud infrastructure operators, DNS providers, managed security service providers, and critical infrastructure manufacturers, indicating that supply chains now become a significant area of accountability.\n\nUnder NIS2, organisations are required to implement supply chain risk management, which involves auditing critical suppliers, documenting their security controls with the same rigor as internal controls, and continuously monitoring them. This creates a challenging intersection between procurement and security teams, as procurement teams may resist the idea of auditing every vendor, while security teams are obligated by the regulation to do so.\n\nAnother key change is the requirement for board-level accountability. The management body, typically the board, must now have cybersecurity expertise and actively oversee cyber risk. This change shifts the responsibility from solely relying on the CISO to ensuring that the board actively participates in cyber risk management, including having at least one board member with demonstrable cybersecurity knowledge and including cybersecurity as a regular item on board meetings.\n\nIncident reporting under NIS2 is more forensic than before. The directive defines incidents with surgical precision, requiring reporting within 24 hours of detection, not merely within a vague timeframe. This means that organisations must initiate reporting processes immediately upon detection of an incident, even if the full nature of the incident is not yet clear. This change necessitates a revised incident response process that can handle parallel tracks of immediate notification and ongoing investigation.\n\nIn addition to these changes, NIS2 mandates a more documented, auditable, and continuous risk management approach. This involves maintaining active risk assessments, tying security measures directly to identified risks, documenting why certain risks are accepted and how their exposure is monitored. Unlike the more theoretical approach under NIS, NIS2 demands tangible proof of how risk management decisions are made and documented, making the process far more rigid and defensible to regulators.",
  "summary": "The European Union's NIS2 Directive arrives with the force of a regulation but the clarity of a fog bank. I've spent the last months helping organisations navigate it, and I can tell you: the gap between what Brussels published and what your security team must actually do is enormous. This isn't a theoretical piece. This is what I'm seeing in real boardrooms, real infrastructure, real budgets…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}