European organizations are facing significant challenges in implementing the NIS2 Directive, with many CISOs reporting that compliance efforts are being hampered by excessive documentation requirements and unclear regulatory expectations. The process often results in a heavy administrative burden, where compliance is measured by the ability to produce extensive paperwork rather than demonstrable improvements in actual security posture. This disconnect between regulatory intent and practical outcomes has led to concerns that the focus on documentation may not translate into meaningful risk reduction.
A recent study highlights that NIS2 is projected to reach around 70% adoption by the end of 2025, which is lower than other frameworks such as HIPAA and GDPR but higher than PCI DSS. The study attributes this to the stronger enforcement mechanisms of NIS2, which, like GDPR and HIPAA, relies on public authorities for oversight and sanctions, as opposed to the contractual enforcement model of PCI DSS. The comparison underscores the importance of independent regulatory oversight in driving compliance and suggests that while NIS2's adoption is progressing, the effectiveness of its implementation remains a concern due to the administrative complexities involved.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
An article published in late 2025 described how organizations can implement NIS2 through automation, Infrastructure as Code, and DevSecOps rather than manual documentation-heavy processes. It highlighted identity and access management, vulnerability management, and incident reporting as areas where embedded technical controls can improve both compliance and security outcomes.
A report published in late 2025 argued that PCI DSS adoption remains low because enforcement is handled indirectly by acquiring banks and lacks the strong, independent oversight seen in public regulatory regimes. It recommended stronger enforcement authority, clearer guidance, and greater transparency, including possible public disclosure of compliance status.
A study found that only about 32% of organizations were fully compliant with PCI DSS requirements in 2022. The report said this represented a decline from 2020 and trailed compliance levels seen under frameworks such as HIPAA, GDPR, and NIS2.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.