Executive Summary
The European Union is facing a paradox in cybersecurity regulation.
On one side, the European Commission has referred France, Spain, Ireland, and the Netherlands to the Court of Justice of the European Union for failing to fully transpose the NIS2 Directive into national law.
On the other side, many companies already argue that NIS2 may not go far enough. A Cohesity study reported in France found that 62% of French companies surveyed believe cybersecurity rules should be strengthened further.
At first glance, the situation looks contradictory.
Companies usually ask for fewer rules, not more. They often criticize compliance costs, regulatory inflation, audits, reporting obligations, sanctions, and administrative complexity.
Yet in cybersecurity, regulation is increasingly perceived not only as a burden, but also as a protection mechanism.
This article explains why the NIS2 debate reveals a deeper shift in European digital regulation. The key issue is not whether Europe regulates too much or too little. The real question is whether Europe can regulate fast enough, clearly enough, and practically enough to protect its economy against cyber threats, cloud dependency, AI-driven attacks, and strategic dependence on foreign digital infrastructure.
NIS2 is not the end of European cybersecurity regulation.
It is the beginning of a broader legal architecture linking cybersecurity, resilience, cloud sovereignty, artificial intelligence, supply-chain security, incident reporting, and executive accountability.
Key Takeaways
NIS2 is the European Union’s second major cybersecurity directive on network and information systems. It expands cybersecurity obligations across 18 critical sectors.
France, Spain, Ireland, and the Netherlands were referred to the Court of Justice of the European Union in July 2026 for failing to fully transpose NIS2 into national law.
The transposition deadline for NIS2 was October 17, 2024.
In France, NIS2 is expected to dramatically expand the number of regulated entities, moving from a narrow perimeter of critical operators to thousands of essential and important entities.
A Cohesity study reported in France found that 62% of French companies surveyed support stricter cybersecurity regulation, even though NIS2 is not yet fully implemented.
This apparent paradox can be explained by the nature of cyber risk. Cybersecurity regulation is not only a compliance burden. It can also create collective resilience across suppliers, partners, cloud providers, and critical digital chains.
The key legal challenge is to avoid two opposite failures: regulating too slowly, which leaves companies exposed, or regulating too heavily, which makes compliance expensive and difficult to operationalize.
Europe’s future cybersecurity strategy will likely connect NIS2 with cloud sovereignty, AI governance, supply-chain resilience, and critical infrastructure protection.
Quick Answer: Why Are Companies Asking for Stricter Cybersecurity Rules While NIS2 Is Still Not Fully Implemented?
Companies may be asking for stricter cybersecurity rules because cybersecurity is no longer only an internal IT issue.
Cyber risk now spreads across supply chains, cloud providers, software vendors, AI systems, managed service providers, critical infrastructure operators, and public services.
When one weak actor in the chain is compromised, the consequences can affect many others.
For this reason, some companies may see stronger cybersecurity regulation as a way to raise the security baseline of the entire ecosystem.
In cybersecurity, regulation can function as a collective defense tool.
That is why the debate around NIS2 is different from traditional debates about regulatory burden.
1. The NIS2 Paradox
The paradox is simple.
The European Union is taking France and several other Member States to court because they have not fully transposed NIS2.
At the same time, companies are already suggesting that NIS2 may not be sufficient.
This creates a striking legal and political tension.
How can a directive be both late and already perceived as insufficient?
The answer lies in the speed of cyber risk.
Legislation moves through consultation, negotiation, adoption, transposition, implementation, guidance, and enforcement.
Cyber threats move through automation, ransomware ecosystems, supply-chain compromise, cloud concentration, identity theft, industrial espionage, AI-assisted phishing, and geopolitical pressure.
The regulatory clock and the threat clock do not move at the same speed.
NIS2 was designed to raise the European cybersecurity baseline.
By the time Member States implement it fully, many companies may already be facing risks that go beyond the minimum legal framework.
2. What Is NIS2?
NIS2 is the European Union’s updated cybersecurity directive on network and information systems.
It replaces and expands the first NIS Directive.
Its purpose is to ensure a high common level of cybersecurity across the European Union.
NIS2 covers a broader range of sectors than the previous framework and introduces stronger obligations on cybersecurity risk management, incident notification, governance, supervision, and enforcement.
Its logic is not limited to technical security.
NIS2 treats cybersecurity as an organizational and governance issue.
Companies within scope must implement appropriate risk management measures, address supply-chain risks, report significant incidents, and involve management bodies in cybersecurity governance.
This is one of the major changes.
Cybersecurity is no longer treated as a purely technical matter delegated to IT teams.
It becomes a board-level and legal compliance issue.
3. Why the European Commission Referred France to the Court of Justice
Member States were required to transpose NIS2 into national law by October 17, 2024.
In July 2026, the European Commission referred France, Spain, Ireland, and the Netherlands to the Court of Justice of the European Union for failing to notify complete transposition measures.
This is not a minor procedural issue.
NIS2 depends on national transposition.
Without national implementation, companies cannot fully know which authority will supervise them, how national thresholds will apply, how procedures will operate, which sanctions will be used, and how compliance will be assessed in practice.
This creates legal uncertainty.
For France, the issue is especially sensitive because the expected scope of NIS2 is much wider than previous cybersecurity regulation.
The French cybersecurity authority, ANSSI, and market observers have emphasized that the number of regulated entities will increase dramatically.
This means that many organizations that were not historically regulated as critical operators may become subject to cybersecurity obligations.
The delay therefore has two effects.
It exposes France to infringement proceedings.
It also delays operational clarity for companies that need to prepare.
4. What NIS2 Changes for Companies
NIS2 changes cybersecurity compliance in several ways.
A broader scope
NIS2 applies to many more sectors than the original NIS Directive.
It covers essential and important entities across sectors such as energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, space, postal services, waste management, chemicals, food, manufacturing, digital providers, and research.
The message is clear: cybersecurity is no longer reserved for a small number of critical infrastructure operators.
Stronger governance expectations
Management bodies are expected to approve and oversee cybersecurity risk management measures.
This increases the responsibility of directors and senior executives.
Cybersecurity becomes a governance duty.
Supply-chain security
Companies must pay attention not only to their own systems, but also to their suppliers and service providers.
This is critical because many cyber incidents originate in supply chains.
Incident notification
NIS2 strengthens incident reporting obligations and timelines.
This improves situational awareness but also creates operational pressure for legal, IT, compliance, and crisis management teams.
Supervision and sanctions
NIS2 gives authorities stronger supervisory and enforcement powers.
The directive is therefore not just an internal policy framework. It is a compliance regime with potential financial and reputational consequences.
5. Why Some Companies Say NIS2 Is Already Insufficient
The Cohesity study reported in France found that 62% of French companies surveyed believe cybersecurity rules should be strengthened.
This is unusual.
Companies generally resist additional regulation.
However, cybersecurity is different because risk is interconnected.
A company can invest heavily in cybersecurity and still be compromised through a supplier, a cloud provider, a managed service provider, a SaaS vendor, or a partner with weaker security.
In this context, stronger rules may be seen as a way to reduce systemic vulnerability.
Companies may not be asking for regulation for its own sake.
They may be asking for a more reliable security baseline across the ecosystem.
This is the key to understanding the paradox.
More regulation can mean more cost.
It can also mean more trust.
In cybersecurity, trust has economic value.
6. Is Europe Overregulating Cybersecurity?
The answer is not simple.
Europe is undoubtedly building a dense cybersecurity and digital regulation framework.
NIS2 is not isolated.
It interacts with DORA, the Cyber Resilience Act, the AI Act, the GDPR, sector-specific rules, cloud security frameworks, and digital sovereignty initiatives.
For companies, this creates complexity.
The risk of regulatory overload is real.
Compliance teams may face overlapping requirements, different reporting channels, multiple supervisory authorities, uncertain national implementation, and recurring documentation obligations.
This is especially difficult for mid-sized companies.
The danger is that cybersecurity compliance becomes a paperwork exercise rather than a genuine resilience strategy.
However, the opposite risk is also real.
If Europe regulates too slowly or too weakly, companies may remain structurally exposed to ransomware, supply-chain attacks, cloud dependency, industrial espionage, and AI-powered cyber threats.
The debate is therefore not “more rules” versus “less rules.”
The real question is whether Europe can create rules that are clear, enforceable, proportionate, operational, and strategically useful.
7. Is Europe Too Slow to Regulate?
NIS2 illustrates the problem of regulatory timing.
The directive was adopted to address a growing cybersecurity threat.
Member States were required to transpose it by October 2024.
By July 2026, several major Member States had still not fully transposed it.
This delay matters because cyber threats do not wait for legislative calendars.
Delayed transposition weakens harmonization.
It creates uncertainty for companies.
It reduces Europe’s credibility in cybersecurity governance.
It may also reduce the influence of late Member States in shaping future cybersecurity policy.
For France, this is particularly important because France has historically played a major role in cybersecurity doctrine, cloud sovereignty, and security certification through frameworks such as SecNumCloud.
A delay in NIS2 implementation may therefore have political and strategic consequences beyond domestic compliance.
8. The Cloud and AI Dimension
NIS2 is part of a broader European movement.
Europe is increasingly treating cybersecurity, cloud sovereignty, and artificial intelligence as connected issues.
This is logical.
Cybersecurity now depends on digital infrastructure.
Digital infrastructure increasingly depends on cloud providers.
Cloud providers increasingly support AI workloads.
AI systems create new risks for phishing, code generation, vulnerability discovery, fraud, misinformation, and automated attacks.
This is why European policy is moving beyond traditional cybersecurity.
The European Commission’s work on sovereign cloud and related frameworks shows that Europe is not only thinking about security controls. It is thinking about dependency, jurisdiction, resilience, data, AI, supply chain, and strategic autonomy.
In that sense, NIS2 may already look insufficient because it is only one piece of a larger puzzle.
It strengthens cybersecurity governance.
It does not fully solve cloud concentration.
It does not fully solve AI-enabled attacks.
It does not fully solve dependence on non-European infrastructure.
It does not fully solve software supply-chain exposure.
It does not fully solve operational resilience across cross-border digital services.
This does not make NIS2 useless.
It means NIS2 is a baseline, not the final architecture.
9. Why Cybersecurity Regulation Is Different From Other Regulation
Many regulatory debates oppose compliance and competitiveness.
Cybersecurity is more complex.
Weak cybersecurity directly damages competitiveness.
A major cyberattack can stop production, expose data, paralyze public services, damage reputation, trigger contractual liability, and destroy customer trust.
In this context, regulation may help create a common minimum level of security.
Companies may support stronger rules because they do not want to be exposed by weaker partners.
This is especially true in sectors where interdependence is high.
A hospital depends on software vendors.
A manufacturer depends on logistics providers.
A bank depends on cloud infrastructure and third-party IT services.
A public administration depends on contractors and shared digital systems.
A retailer depends on payment systems and SaaS platforms.
A critical infrastructure operator depends on suppliers, maintenance providers, and industrial control systems.
Cybersecurity is collective.
That is why purely individual compliance is insufficient.
10. NIS2 as a Collective Security Instrument
NIS2 can be understood as a collective security instrument.
It does not merely tell individual companies to protect themselves.
It aims to raise the security level of sectors that are interconnected and economically essential.
This is why it imposes requirements on governance, risk management, incident reporting, supply chain, and supervision.
A weak actor can create risk for others.
A delayed incident report can prevent authorities from detecting a broader campaign.
A vulnerable supplier can become an entry point into a critical organization.
A poorly governed company can become a systemic weakness.
NIS2 responds to this reality by creating common obligations.
This explains why companies may ask for stronger rules.
They may not want more bureaucracy.
They may want fewer weak links.
11. The Legal Department’s Role
NIS2 makes cybersecurity a legal and governance issue.
Legal departments should not treat it only as an IT compliance project.
They should be involved in:
scope assessment,
contractual risk allocation,
supplier due diligence,
incident notification procedures,
board governance,
internal policies,
insurance coverage,
evidence preservation,
regulatory communication,
and crisis management.
NIS2 also changes the relationship between legal, IT, compliance, risk, procurement, and executive management.
Cybersecurity can no longer be managed in silos.
It requires coordinated governance.
12. The Board-Level Dimension
One of the most important shifts in NIS2 is the role of management bodies.
Cybersecurity risk management becomes a matter of executive responsibility.
This matters because cyber risk is no longer only technical.
It affects business continuity, public trust, contractual obligations, regulatory exposure, and strategic dependency.
Boards and senior executives will need to understand the organization’s cyber risk profile.
They will need to approve security policies.
They will need to allocate resources.
They will need to oversee incident preparedness.
They will need to understand supplier exposure.
They will need to ensure that cybersecurity is not treated as a secondary operational matter.
In practice, NIS2 pushes cybersecurity from the server room to the boardroom.
13. The Supply-Chain Problem
Supply-chain cybersecurity is one of the main reasons companies may support stronger regulation.
Many organizations are now highly dependent on external providers.
These include cloud providers, software vendors, managed service providers, data processors, IT integrators, hosting providers, cybersecurity vendors, maintenance providers, and subcontractors.
If one of these actors is compromised, the consequences can spread.
NIS2 recognizes this by requiring attention to supply-chain security.
However, supply-chain risk is difficult to control.
A company may not have full visibility into its supplier’s subcontractors.
A supplier may rely on foreign cloud infrastructure.
A SaaS provider may use multiple subprocessors.
A critical vendor may be difficult to replace.
This is where stronger standards, certifications, contractual clauses, and sector-wide expectations become valuable.
Companies may ask for tougher rules because they need leverage over their ecosystem.
14. The Incident Reporting Challenge
Incident reporting is a central feature of NIS2.
It is also one of the most operationally difficult obligations.
Companies must detect incidents quickly, assess their significance, escalate internally, notify authorities when required, communicate appropriately, preserve evidence, and coordinate remediation.
This requires preparation before the incident.
The main risk is improvisation.
If companies do not know who decides, who notifies, who drafts, who validates, who communicates, and who preserves evidence, reporting obligations can become a source of legal and operational confusion.
NIS2 therefore requires not only technical detection capabilities, but also governance workflows.
The legal function has a direct role here.
15. The Risk of Compliance Theater
A stronger regulatory framework does not automatically produce stronger security.
There is always a risk of compliance theater.
Companies may produce policies without changing practices.
They may complete questionnaires without improving resilience.
They may rely on certifications without understanding operational dependencies.
They may create incident procedures that are never tested.
They may treat NIS2 as a legal checkbox instead of a resilience program.
This would be a failure.
NIS2 will be effective only if companies translate legal obligations into operational security.
The law can set the floor.
It cannot replace execution.
16. The Risk of Regulatory Overload
The opposite risk is regulatory overload.
European companies must now navigate multiple overlapping frameworks.
NIS2 addresses cybersecurity.
DORA addresses operational resilience for the financial sector.
The Cyber Resilience Act addresses cybersecurity requirements for digital products.
The AI Act addresses artificial intelligence systems.
The GDPR addresses personal data.
Sector-specific rules add more layers.
For large organizations, this is complex.
For small and mid-sized companies, it can be overwhelming.
The challenge for Europe is to avoid turning cybersecurity into a regulatory maze.
If compliance becomes too fragmented, companies may spend more time interpreting obligations than improving security.
That is not resilience.
That is administrative fatigue.
17. The Strategic Autonomy Question
The NIS2 debate also raises a broader question: can Europe secure its digital economy without addressing dependency?
Cybersecurity controls matter.
However, many European organizations depend on non-European cloud providers, software vendors, hardware supply chains, and AI infrastructure.
This creates strategic exposure.
A company may comply with NIS2 while remaining dependent on infrastructure it does not fully control.
This is why the European discussion increasingly includes cloud sovereignty, secure cloud frameworks, data localization, supply-chain resilience, and AI infrastructure.
Cybersecurity is no longer only about preventing attacks.
It is about preserving operational autonomy.
18. Does NIS2 Go Far Enough?
NIS2 goes further than the previous framework.
It expands scope, strengthens governance, addresses supply chains, improves incident reporting, and increases enforcement.
However, it may not be enough by itself.
It does not fully solve cloud dependency.
It does not fully solve the concentration of critical digital infrastructure.
It does not fully address AI-enabled cyberattacks.
It does not eliminate supply-chain opacity.
It does not automatically ensure operational resilience.
It does not compensate for delayed national implementation.
This is why some companies may already ask for stronger rules.
They may see NIS2 as necessary, but not sufficient.
19. The Future of European Cybersecurity Regulation
The future of European cybersecurity regulation will likely be defined by integration.
Cybersecurity will be connected with:
critical infrastructure protection,
cloud sovereignty,
AI governance,
data protection,
digital product security,
operational resilience,
supply-chain control,
and executive accountability.
This integration is necessary because the threat landscape is integrated.
Attackers do not respect regulatory categories.
A ransomware group does not care whether a weakness belongs to cybersecurity, data protection, cloud dependency, or software supply chain.
European regulation will therefore continue moving toward a broader concept of digital resilience.
NIS2 is a central pillar.
It is not the whole building.
20. Final Analysis: The Real Lesson of the NIS2 Paradox
The NIS2 paradox is not that companies suddenly love regulation.
The paradox is that cyber risk has changed the economic meaning of regulation.
In cybersecurity, the absence of common standards can become a competitive and operational risk.
Companies may ask for stronger rules not because they want more bureaucracy, but because they want fewer weak links, clearer expectations, stronger suppliers, faster incident reporting, and a more resilient digital ecosystem.
The danger is that Europe may fail in two opposite ways.
It may regulate too slowly and leave companies exposed.
It may regulate too heavily and turn resilience into paperwork.
The challenge is to build regulation that is fast enough to matter, clear enough to apply, proportionate enough to sustain, and operational enough to improve real security.
NIS2 is necessary.
It may already be insufficient.
That does not mean Europe should simply add more rules.
It means Europe must make cybersecurity law more effective, more coherent, and more aligned with the reality of cyber threats.
The core question is no longer whether Europe needs cybersecurity regulation.
The question is whether its regulation can keep pace with the systems, dependencies, and attacks it is supposed to govern.
What is NIS2?
NIS2 is the European Union directive on measures for a high common level of cybersecurity across the Union. It updates and expands the previous NIS Directive and introduces stronger obligations for cybersecurity risk management, incident reporting, governance, supervision, and enforcement.
Why did the European Commission take France to the Court of Justice?
The European Commission referred France, Spain, Ireland, and the Netherlands to the Court of Justice of the European Union for failing to notify complete transposition of the NIS2 Directive into national law.
What was the deadline to transpose NIS2?
Member States had until October 17, 2024 to transpose NIS2 into national law.
Why is NIS2 important for companies?
NIS2 expands the number of regulated entities, strengthens cybersecurity governance obligations, increases supply-chain security expectations, imposes incident notification duties, and increases supervisory and enforcement powers.
Why do some companies say NIS2 is not enough?
Some companies believe NIS2 may not be enough because cyber threats are evolving faster than regulation. Ransomware, supply-chain attacks, cloud dependency, AI-enabled cyber threats, and strategic infrastructure concentration create risks that go beyond minimum compliance.
Is cybersecurity regulation only a burden?
No. Cybersecurity regulation can be burdensome, but it can also create collective resilience by raising the security baseline across suppliers, partners, and critical sectors.
Does NIS2 apply only to critical infrastructure?
No. NIS2 significantly expands the scope compared with the previous NIS framework. It covers essential and important entities across 18 critical sectors.
What is the role of management bodies under NIS2?
NIS2 increases the role of management bodies in cybersecurity governance. Cybersecurity risk management becomes a board-level and executive responsibility, not only an IT matter.
How does NIS2 affect suppliers?
Even suppliers not directly covered by NIS2 may be affected indirectly through contracts, audits, security requirements, incident reporting clauses, and supply-chain due diligence imposed by regulated customers.
Is NIS2 enough to secure Europe’s digital economy?
NIS2 is necessary, but it is not sufficient by itself. It must be coordinated with cloud sovereignty, AI governance, software supply-chain security, operational resilience, data protection, and digital infrastructure policy.
