Skip to main content
Compliance

What Our Report Says on NIS2 Readiness

New survey data reveals a gap between NIS2 readiness confidence and actual compliance behavior. See where organizations fall short and how to close it.

NIS2 has moved from a directive text to a daily operational reality for thousands of organizations across the EU, and Wire's new State of Secure Collaboration 2026 report shows how far everyday collaboration habits have to travel to catch up with that reality.

We surveyed 208 IT, security, and compliance leaders across France, Germany, and the UK about how they collaborate, what they consider sensitive, and how prepared they feel for the regulation. The results give a concrete, data-backed picture of NIS2 readiness, and it is more nuanced than a simple pass or fail.

IT Leaders Feel Prepared

Our survey asked respondents how prepared their organization is to meet regulatory requirements such as NIS2 and DORA in terms of secure collaboration. 62% rated themselves prepared or very prepared. The same group also told us that 39% of their collaboration workflows are not covered by official tools, that access to shared files remains active longer than intended in at least some cases for 61% of organizations, and that 48% sometimes or often share sensitive information through tools not designed for secure communication.

Bypassing official tools

Reading these numbers together clearly shows a preparedness gap: 62% of respondents call themselves prepared for NIS2. But in the same survey, most of them also describe the specific behaviors NIS2 is designed to catch: workflows outside official tools, access that never gets revoked, sensitive info going through the wrong channels. So "prepared" is mostly a self-assessment, not something borne out by how these teams actually operate day to day.

Why the Gap Matters Now

NIS2 (Directive (EU) 2022/2555) covers an estimated 160,000 entities across the EU, makes management bodies personally accountable for cybersecurity oversight under Article 20, and requires incident reporting within 24 hours for an early warning and 72 hours for a fuller notification.

Did you know?
As of mid-2026, 23 of the EU's 27 member states have fully transposed NIS2 into national law, national CSIRTs (Computer Security Incident Response Team) have launched systematic audit programs across essential sectors, the first fines have landed in Belgium, Italy and Hungary, and Germany's BSI has issued formal compliance notices since late 2025.

Regulators are already auditing for precisely what our survey found: workflows nobody's tracking, access that never gets shut off, sensitive files moving through channels never built to hold them.

How to Achieve NIS2 Readiness

That gap is where secure, auditable collaboration stops being optional, particularly for the crisis and incident communication that has to keep working when a primary system is compromised. It maps directly onto the behaviors our survey flagged: workflows outside official tools, access that outlives its purpose, and sensitive content moving through channels never built for secure communication.

Wire addresses this at the collaboration layer itself: always-on end-to-end encryption across messages, calls, and files; a resilient, out-of-band crisis communication channel that keeps working independently of the primary platform; multi-tenancy for segregated, auditable environments; exportable audit logs; and flexible deployment models for organizations with residency or accreditation requirements.

For more on applying these controls to your own NIS2 program, see Wire's NIS2 risk management checklist, our guide to achieving NIS2 compliance, and our look at why crisis communication needs end-to-end encryption under NIS2. Our NIS2 compliance use case maps Wire's features directly to Article 21's requirements.

Wire

As a leader in secure communication, we empower businesses and government agencies with expert-driven content that helps protect what matters. Stay ahead with industry trends, compliance updates, and best practices for secure digital exchanges.

Similar posts

See Wire in action 

product_shot_mobile_and_desktop_calling_1200px-min

Discover in a quick call how Wire enables secure, compliant, and seamless collaboration for your organization, without compromising on usability or control.

  • Messaging, calling, conferencing, and file sharing — all in one app.
  • The only full implementation of Messaging Layer Security (MLS).
  • Invisible security that’s easy to use and built for enterprise scale.
  • Government-approved for VS-NfD, GDPR, and NIS2, trusted by 1,800+ customers.