NIS2 has moved from a directive text to a daily operational reality for thousands of organizations across the EU, and Wire's new State of Secure Collaboration 2026 report shows how far everyday collaboration habits have to travel to catch up with that reality.
We surveyed 208 IT, security, and compliance leaders across France, Germany, and the UK about how they collaborate, what they consider sensitive, and how prepared they feel for the regulation. The results give a concrete, data-backed picture of NIS2 readiness, and it is more nuanced than a simple pass or fail.
Our survey asked respondents how prepared their organization is to meet regulatory requirements such as NIS2 and DORA in terms of secure collaboration. 62% rated themselves prepared or very prepared. The same group also told us that 39% of their collaboration workflows are not covered by official tools, that access to shared files remains active longer than intended in at least some cases for 61% of organizations, and that 48% sometimes or often share sensitive information through tools not designed for secure communication.
Reading these numbers together clearly shows a preparedness gap: 62% of respondents call themselves prepared for NIS2. But in the same survey, most of them also describe the specific behaviors NIS2 is designed to catch: workflows outside official tools, access that never gets revoked, sensitive info going through the wrong channels. So "prepared" is mostly a self-assessment, not something borne out by how these teams actually operate day to day.
NIS2 (Directive (EU) 2022/2555) covers an estimated 160,000 entities across the EU, makes management bodies personally accountable for cybersecurity oversight under Article 20, and requires incident reporting within 24 hours for an early warning and 72 hours for a fuller notification.
Regulators are already auditing for precisely what our survey found: workflows nobody's tracking, access that never gets shut off, sensitive files moving through channels never built to hold them.
That gap is where secure, auditable collaboration stops being optional, particularly for the crisis and incident communication that has to keep working when a primary system is compromised. It maps directly onto the behaviors our survey flagged: workflows outside official tools, access that outlives its purpose, and sensitive content moving through channels never built for secure communication.
Wire addresses this at the collaboration layer itself: always-on end-to-end encryption across messages, calls, and files; a resilient, out-of-band crisis communication channel that keeps working independently of the primary platform; multi-tenancy for segregated, auditable environments; exportable audit logs; and flexible deployment models for organizations with residency or accreditation requirements.
For more on applying these controls to your own NIS2 program, see Wire's NIS2 risk management checklist, our guide to achieving NIS2 compliance, and our look at why crisis communication needs end-to-end encryption under NIS2. Our NIS2 compliance use case maps Wire's features directly to Article 21's requirements.