Member states had until 17 October 2024 to transpose the NIS2 Directive into national law. Almost two years later, only 16% of the businesses required to comply say they are confident they fully do, according to a survey of 670 in-scope business leaders published in April 2026. Another 11% were not sure what NIS2 is.
That gap is no longer an abstract one. National authorities have started auditing, the first deadlines for proving compliance have passed in some countries, and in Romania the most serious cyber incident in the country's history, the 2025 ransomware attack that shut down the national cadastre agency, was traced by the national cybersecurity directorate to a vulnerability known since 2021 and a reused password. NIS2 exists to make exactly those failures a legal problem, not just a technical one.
This page collects the numbers that describe where NIS2 compliance actually stands in 2026: scope, readiness, spending, enforcement, and a Romanian dataset that no other English-language source compiles. Every figure links to its source, we flag the ones that are directional rather than official, and we update the page quarterly.
NIS2 in 2026: the key figures
- ~160,000 entities are estimated to fall within NIS2 scope across the EU, roughly ten times the number covered by the original 2016 directive (European Commission estimate).
- 16% of in-scope businesses are confident they are fully compliant; 11% do not know what NIS2 is (CyberSmart, April 2026).
- 70% of organisations in the EU's high-criticality sectors name regulatory compliance as the main driver of their cybersecurity investment (ENISA, December 2025).
- 30% of those organisations had not run a security assessment in the previous twelve months (ENISA, 2025).
- €10 million or 2% of global turnover is the maximum fine for essential entities; €7 million or 1.4% for important entities (Directive (EU) 2022/2555, Article 34).
- +153% is the year-on-year increase in ransomware attacks recorded in Romania in 2025, with 256 major incidents handled by the DNSC (DNSC, 2025 annual report).
- 105 GDPR fines were issued in Romania in 2025, up from 83 in 2024, most often for inadequate technical measures and missing periodic testing (ANSPDCP, 2025 activity report).
The scope: from 15,000 organisations to 160,000
The original NIS Directive of 2016 covered roughly 15,000 operators of essential services and digital service providers across the EU. NIS2 replaced a list of designated operators with size and sector rules, and the European Commission's own estimate puts the result at around 160,000 entities. The directive covers 18 sectors: eleven of high criticality in Annex I, including energy, transport, banking, health, water, digital infrastructure, ICT service management and public administration, and seven "other critical" sectors in Annex II, including postal services, waste, chemicals, food, manufacturing of medical devices and electronics, digital providers and research.
The size test is the part most companies get wrong. An organisation in one of those sectors is in scope from 50 employees or €10 million in annual turnover or balance sheet. It becomes an essential entity, with heavier supervision, at 250 employees or €50 million turnover in an Annex I sector; everything else in scope is an important entity. The Commission expects roughly a third of in-scope entities to be essential and two thirds important. Some entities are in scope regardless of size, such as trust service providers, DNS providers and sole providers of a service critical to a member state.
The obligations attached to that status are concrete. Article 21 lists ten minimum risk-management measures, from incident handling and business continuity to supply-chain security, vulnerability management, cryptography and multi-factor authentication. Article 23 sets a three-step incident-reporting clock: an early warning within 24 hours of becoming aware of a significant incident, a full notification within 72 hours, and a final report within one month. Article 20 makes management bodies responsible for approving and overseeing the measures, and allows them to be held liable for failures. Article 34 caps fines at €10 million or 2% of worldwide turnover for essential entities and €7 million or 1.4% for important ones, whichever is higher.
The readiness gap
The most quoted readiness figure of 2026 comes from CyberSmart, a UK managed-security vendor, which commissioned OnePoll to survey 670 business leaders in late 2025 across the UK, Poland, the Netherlands, Ireland, France, Germany, Italy, Denmark and Belgium. The sample was restricted to companies that qualify as important entities, meaning 50 to 249 employees or more than €10 million in turnover, so it describes the mid-market rather than large enterprises. In that group, 16% were confident they were fully compliant and 11% were unsure what NIS2 was. The barriers were practical rather than strategic: 20% cited budget constraints, 16% a lack of implementation guidance and 11% insufficient internal expertise. At the same time, 75% saw compliance as a competitive advantage, and the pressure to prove it was coming from outside: 42% had been asked to demonstrate NIS2 compliance by partners, 41% by investors and 36% by customers.
ENISA's data covers the other end of the market. Its NIS Investments 2025 report surveyed 1,080 professionals in high-criticality sectors across all 27 member states, 83% of them at large enterprises. Even there, 30% of organisations had not conducted a security assessment in the previous twelve months, and 28% took three months or longer to patch critical vulnerabilities. Among the SMEs in the sample, 63% had run no assessment at all. Asked which parts of NIS2 were hardest to implement, respondents named vulnerability and patch management (50%), business continuity and disaster recovery (49%) and supply-chain risk management (37%). Those are not documentation problems. They are the operational basics the directive was written to force.
ENISA's sector-level assessment, NIS360 2026, published in May 2026, does not ask organisations whether they comply; it scores each Annex I sector on maturity and criticality using supervisory data from national authorities. Its conclusion is that electricity, telecommunications and banking are the most mature sectors, and that seven sectors remain in what ENISA calls the risk zone, including public administration, ICT service management and water.
Where the money goes
NIS2 is changing budgets more than headcount. ENISA reports a median cybersecurity budget of €1.5 million among surveyed organisations, and 70% of them name compliance with NIS2, DORA and the Cyber Resilience Act as the main driver of that spending. The spending is not only paperwork: 41% reported stronger risk management as a result, 35% better detection and 26% better response.
What the money cannot buy is people. In the same survey, 76% of organisations reported difficulty recruiting qualified cybersecurity staff and 71% difficulty retaining them. The ratio of cybersecurity staff to IT staff fell to 10.6%, and ENISA estimates the EU's cybersecurity talent shortfall at close to 300,000 professionals. The predictable consequence, visible in the investment data, is a shift from internal teams toward technology and outsourced services. For a mid-sized company in scope, the realistic compliance model in 2026 is a managed one: an external assessment, a hardening programme, monitored infrastructure and a retained partner for incident response.
Enforcement is no longer theoretical
By mid-2026 most member states had completed transposition, with a handful still finalising national law, and the first hard deadlines for demonstrating compliance have passed. Belgium's essential entities had until 18 April 2026 to submit a verified conformity assessment, through the national CyberFundamentals framework, ISO/IEC 27001 certification or direct inspection by the Centre for Cybersecurity Belgium; self-declarations were not accepted. Germany, France and the Netherlands have active supervisory programmes. First national fines have been reported in several countries.
Two cautions belong here. There is no central EU register of NIS2 sanctions, so any Europe-wide count of fines is assembled by consultancies and vendors from press reports and is directional at best. And the absence of a fine is not evidence of compliance: supervisory authorities audit essential entities proactively and important entities after an incident, which means most important entities will first hear from their regulator when something has already gone wrong.
Romania: the law, the deadlines and the incident data
Romania transposed NIS2 through Government Emergency Ordinance 155/2024, in force since 30 December 2024, approved with amendments by Law 124/2025, which took effect on 10 July 2025 and widened the national scope beyond the directive's minimum, notably to pharmaceutical distribution and retail and to parts of the food sector. The competent authority is the National Cyber Security Directorate, DNSC. Its Orders 1/2025 and 2/2025, in force from 20 August 2025, set the registration procedure on the NIS2@RO platform and the risk-assessment methodology; in-scope entities had 30 days from that date to register. The DNSC has not published the number of registered entities, and no official count of in-scope Romanian organisations exists; law-firm estimates run to tens of thousands. The registration procedure, the scope tests and the deadlines are set out step by step in our NIS2 guide for Romanian companies (in Romanian).
The threat data the DNSC publishes shows what is at stake. Its 2025 annual report, released in August 2026 after approval by the Supreme Council of National Defence, records 25,033,446 relevant cybersecurity events captured by its sensors during 2025, down from 27,079,485 in 2024 but with a marked intensification in the second half of the year. Ransomware attacks rose by more than 153% year on year. The directorate handled 256 major ransomware incidents and assisted 22 public institutions, 119 companies and 115 individuals hit by ransomware, against 101 incidents in 2024. Within the sectors it analysed, banking accounted for 71.09% of reported incidents, postal and courier services for 10.8% and financial-market infrastructure for 6.34%. The DNSC rated the overall threat level in Romania for 2025 as high.
The incident that defined the year was the ransomware attack on the National Agency for Cadastre and Land Registration, ANCPI, which halted property transactions for weeks. According to the DNSC's findings as reported by Ziarul Financiar, the attacker entered through a vulnerability that had been publicly known since 2021, and a password reused across accounts gave them access to the administration console of the virtual infrastructure. That is a patch-management failure and an authentication failure, the first and the last items on NIS2's Article 21 list. It is also the same combination ENISA's data flags as the most common gap: 28% of organisations taking three months or more to patch critical vulnerabilities.
Romania's data-protection authority shows what enforcement looks like once a regulator is established. ANSPDCP received 12,297 complaints, notifications and breach reports in 2025 and completed 488 investigations, according to its 2025 activity report. It issued 105 fines totalling 2,565,020 lei, roughly €511,000, along with 145 warnings and 182 corrective measures. In 2024 it had issued 83 fines totalling 1,855,807 lei. The most frequent ground for a fine was the lack of adequate technical and organisational measures and of periodic testing, leading to security incidents. Across the EU, the CMS GDPR Enforcement Tracker counted 2,685 fines totalling €6.11 billion by March 2026, and ranks Romania among the most active authorities by number of fines. There is no reason to expect the DNSC to behave differently once its supervisory machinery is running.
What the numbers say to do
Three actions follow directly from the data, in order of cost-effectiveness.
Find out whether you are in scope, precisely. The 11% who do not know what NIS2 is are not the only problem; a larger group assumes it does not apply to them because they are not a utility. Romanian companies can check their obligations under both NIS2 and GDPR in a few minutes with our free obligations checker by CAEN code (in Romanian). If you are in scope and not yet registered with the DNSC, that is the first gap to close.
Run the assessment nobody has run. Thirty percent of ENISA's respondents, and 63% of its SMEs, had no security assessment in the last year. A penetration test and security audit is the cheapest way to discover whether your ANCPI-style vulnerability exists, and it produces the evidence Article 21 requires you to be able to show.
Fix the two failures that keep recurring. Patching and authentication account for the worst incidents in the Romanian data and the hardest gaps in the EU data. A structured infrastructure hardening programme and continuously monitored infrastructure address both; for organisations that keep systems on their own hardware, that starts with properly administered on-premises Linux infrastructure. The related risk of employees moving sensitive data into unmanaged AI tools, which Article 21 also covers under data governance, is quantified in our shadow AI statistics for 2026.
Common misreadings of the NIS2 numbers
- The 16% figure is not an ENISA finding. It comes from CyberSmart's commissioned survey of mid-market business leaders in nine countries. ENISA's NIS360 report never asks organisations whether they are compliant; it scores sectors on maturity. Both are legitimate, but they measure different things and should not be cited as one.
- "Events" are not "incidents". The DNSC's 25 million figure counts sensor-level events, most of them automated scanning and blocked attempts; the 256 figure counts major ransomware incidents it handled. Quoting the first as an attack count overstates the picture by five orders of magnitude.
- There is no official EU or Romanian count of in-scope entities. The 160,000 figure is a Commission estimate; Romanian figures in the tens of thousands are law-firm estimates. Neither the Commission nor the DNSC has published a registry-based count.
- Fine trackers are directional. Aggregated lists of NIS2 fines are compiled from press coverage and should be verified against the national authority before being quoted as fact.
- Transposition is not enforcement. A member state having passed its law says nothing about whether its authority is auditing yet. Check the national supervisory programme, not the transposition map.
Methodology and sources
This page uses the text of Directive (EU) 2022/2555 for scope, obligations and penalties; ENISA's NIS Investments 2025 (1,080 respondents, EU-27, high-criticality sectors) and NIS360 2026 for EU-level readiness; the CyberSmart NIS2 Survey (670 mid-market leaders, nine countries, fielded by OnePoll in late 2025) for self-reported compliance; the DNSC's 2024 and 2025 annual activity reports for Romanian incident data; ANSPDCP's 2025 activity report for Romanian GDPR enforcement; and the CMS GDPR Enforcement Tracker for EU-wide fine totals. Where a primary document is only available in Romanian or through a press summary, we link the most accessible version and name the original. Figures we could not trace to an official or primary source are excluded or explicitly marked as estimates. Any statistic on this page may be cited with a link back.
Frequently asked questions
Who has to comply with NIS2?
Organisations in the 18 sectors listed in Annexes I and II of the directive that have at least 50 employees or €10 million in annual turnover or balance sheet, plus certain providers that are in scope regardless of size. National transpositions can extend the scope; Romania's Law 124/2025 added pharmaceutical distribution and retail and parts of the food sector.
What are the NIS2 fines?
Up to €10 million or 2% of worldwide annual turnover for essential entities, and up to €7 million or 1.4% for important entities, whichever is higher. Management bodies can be held personally liable for failing to approve and oversee the required measures.
What are the NIS2 incident-reporting deadlines?
An early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month. Intermediate reports can be requested by the authority.
How was NIS2 transposed in Romania?
Through Government Emergency Ordinance 155/2024, in force from 30 December 2024, approved with amendments by Law 124/2025 in July 2025. The DNSC is the competent authority, and its Orders 1/2025 and 2/2025 set the registration and risk-assessment rules, with registration on the NIS2@RO platform due within 30 days of 20 August 2025.
How many companies are compliant with NIS2?
No official figure exists. The most cited survey, from CyberSmart in April 2026, found 16% of in-scope mid-market businesses confident they were fully compliant. ENISA's data shows 30% of organisations in high-criticality sectors had not run a security assessment in the previous year.
