11.08.2026

Eight Months of NIS2: Implementation Remains Challenging for Companies

eco snapshot survey reveals hurdles relating to evidence requirements, reporting processes and risk management

NIS2 has reached the business community, but practical implementation remains challenging for many companies. This is shown by a recent snapshot survey conducted by eco – Association of the Internet Industry among 38 companies from the eco network. Respondents regard documentation requirements, reporting processes governed by the 24- and 72-hour rules, as well as risk analysis and risk management, as the greatest implementation challenges.

The eco snapshot survey provides an insight into companies that were reached through eco channels and are already addressing NIS2 and cybersecurity. Even within this group, there is a clear need for support. More than one third of the companies already registered with the German Federal Office for Information Security (BSI) describe the registration process as “very complicated”, while 53 per cent consider it “fine”.

Evidence requirements and reporting processes create the greatest pressure

The additional effort involved in implementing NIS2 is noticeable: around 15 per cent of respondents assess it as very high, while approximately 38 per cent respectively describe it as high or medium. No company stated that NIS2 had created no additional work.

Almost 18 per cent of the participating companies say that they have already implemented the NIS2 requirements in full. Around 36 per cent are proceeding according to plan, while almost another 18 per cent report delays. Companies regard evidence requirements and audits as particularly challenging, accounting for around 26 per cent of responses, followed by reporting requirements at around 25 per cent and risk analysis and risk management at approximately 21 per cent.

eco KRITIS expert Ulrich Plate: Registration is only the beginning

“The fact that even companies from a security-oriented environment sometimes describe the registration process as very complicated demonstrates the importance of practical guidance,” says Ulrich Plate, Leader of the eco KRITIS Competence Group.

“The work does not end with registration. What matters now is that companies translate the regulatory requirements into effective processes: clear responsibilities, robust reporting channels, documented risks and functioning supply chain management. NIS2 must not be regarded purely as a compliance task. It must become an issue of leadership, resilience and risk management in companies’ everyday operations.”

Support must address practical needs

In June, the BSI launched a survey to gather feedback on businesses’ needs regarding its NIS2 support services, including applicability assessments, Managing Board training and information packages. eco believes this is the right approach: support should focus primarily on the areas that cause the greatest practical difficulties, namely evidence requirements, reporting channels, supply chain requirements, applicability assessments and the responsibilities of the Managing Board.

“Companies do not need abstract catalogues of obligations, but clear priorities and manageable implementation guidance,” says Plate. “Only if NIS2 works in companies’ everyday operations can it deliver genuine resilience benefits for the economy and society.”

About the eco snapshot survey

The snapshot survey is based on a short questionnaire conducted by eco among companies in its network with links to IT security, digital infrastructure and NIS2. The questionnaire was distributed through eco channels and received a total of 38 qualified responses.

The results provide a current snapshot of practical experiences and are not intended to be representative. As responses to individual questions were voluntary, the number of responses varies from question to question. Percentages refer in each case to the companies that answered the relevant question.

 

Eight Months of NIS2: Implementation Remains Challenging for Companies