All resources
Blog 7 min read

NIS2: what actually changed, and the awkward question for your board

C1The Compliance One team18 February 2026

NIS2 is the European Union's upgraded cybersecurity directive, and its most important change is not technical at all. It is who is now on the hook. Cybersecurity used to be something the board delegated downward and forgot about. NIS2 walks it back up to the top table and hands the directors a pen to sign next to it.

The three things that actually changed

  • Wider scope. Many more sectors and mid-sized companies are now in, including ones that assumed this was a big-utility problem.
  • Management accountability. Boards must approve and oversee cybersecurity risk measures, and can be held personally responsible for failing to.
  • Sharper incident reporting. An early warning within 24 hours, a fuller notification within 72, and a final report inside a month. The clock is unforgiving.

NIS2 did not just raise the security bar. It wrote the board's name on it. 'We left it to IT' is no longer a defence, it is an admission.

The awkward question to put to your directors

It is simply this: if a regulator asked tomorrow, could your board demonstrate that it has approved, and actively oversees, your cybersecurity risk measures? For a lot of organisations the honest answer is a wince. NIS2 turns that wince into a liability, because the accountability is now explicit and personal.

How Compliance One makes the board's job doable

The platform ships the full NIS2 obligation set, from the governance duties to the ten risk-management measures to the tight incident-reporting clock, mapped to evidence and to the other frameworks you run. That gives directors something they can actually point to: documented oversight, live posture, and an incident process that respects the 24, 72 and 30 timeline instead of discovering it mid-crisis. Board accountability is a lot less frightening when the board can see, on one screen, exactly what it is accountable for.

See it on your own frameworks

Book a 30-minute walkthrough and we'll map Compliance One to your environment.