TL;DR: NIS2 now requires organisations to treat risk management, incident handling, supply chain security, and vulnerability disclosure as ongoing obligations rather than annual checks, according to Synack. The compliance challenge is no longer documentation alone; it is proving continuous operational resilience under stricter enforcement and reporting expectations.
NHIMG editorial — based on content published by Synack: NIS2 is Live, Moving Beyond Check-Box Compliance to True Cyber Resilience
By the numbers:
- NIS2 penalties can reach up to €10M or 2% of global turnover.
- Article 23(4)(a) requires an early warning to the CSIRT within 24 hours of becoming aware of a significant incident.
- Synack says its Red Team includes 1,500+ expert researchers.
Questions worth separating out
Q: How should organisations prove NIS2 readiness beyond a one-time compliance review?
A: They should show continuous evidence that risk is being managed, not just documented.
Q: Why do supplier identities create so much NIS2 compliance risk?
A: Supplier identities often have legitimate access but weaker governance than internal users, which makes them easy to overlook in lifecycle reviews and offboarding.
Q: What breaks when organisations rely on annual testing for NIS2?
A: Annual testing creates a false sense of assurance because it only shows what was true on one date.
Practitioner guidance
- Map NIS2 obligations to live control evidence Replace annual-only compliance artefacts with recurring evidence for incident handling, vulnerability triage, cryptographic use, and supply chain oversight.
- Inventory supplier-linked access and integrations Document every third-party API, embedded service, and delegated access path that can affect essential functions.
- Tie discovery outputs to remediation SLAs Use continuous external attack surface discovery to identify new assets and immediately attach them to remediation workflows.
What's in the full article
Synack's full article covers the operational detail this post intentionally leaves for the source:
- How its continuous penetration testing approach is positioned for NIS2 evidence collection and validation.
- How the platform maps findings into SOC workflows and prioritisation decisions.
- How supplier testing and attack surface discovery are presented for compliance use cases.
- How the vendor frames validator output for audit support and remediation tracking.
👉 Read Synack's analysis of NIS2 resilience, supply chain risk, and continuous testing →
NIS2 and continuous resilience: what practitioners need to change?
Explore further
Continuous resilience is now the real compliance benchmark. NIS2 does not reward organisations for having a document set or a yearly penetration test. It rewards organisations that can demonstrate ongoing control over risk, incident handling, and supplier exposure. For practitioners, the shift is from proving intent to proving operational durability under change.
A question worth separating out:
Q: Who is accountable for NIS2 access decisions and incident reporting?
A: Top-level management remains accountable for risk governance, but identity, data, and security teams must supply the evidence and control operations that make accountability real. Practically, that means clear ownership for access policy, review outcomes, incident scope, and reporting artefacts. Without named stewardship, the organisation cannot demonstrate control.
👉 Read our full editorial: NIS2 is shifting compliance toward continuous cyber resilience