What NIS2 actually requires
NIS2 is the revised EU directive on network and information security. It dramatically widens the circle of affected organisations – from energy and health to transport, digital infrastructure, manufacturing, food and public administration. It is no longer only large corporations: many mid-sized companies that previously sat outside such regulation are now in scope.
Four recurring obligations follow from the requirements, and all of them presuppose people:
- Risk management: identify and assess threats and derive technical and organisational measures.
- Reporting duties: report security incidents to the authority within tight deadlines – which requires readiness and clear processes.
- Supply chain security: service providers and suppliers must also be assessed and included.
- Management accountability: leadership is personally liable for compliance and must understand what is being implemented.
At its core, each point raises the same question: who does this? Software alone does not report an incident on time. A dashboard does not assess suppliers. People do.
The real bottleneck: security talent
The labour market for IT security was already tight before NIS2. Experienced security architects, incident responders and governance, risk and compliance specialists are rare – and they know it. With every wave of new regulation, demand rises faster than supply.
Timing makes it worse. Many companies postpone building their security team to the next quarter or to autumn. That is exactly when they compete with tens of thousands of other organisations for the same profiles. Act early and you have the pick. Wait, and you pay more for less.
Which roles you need now
NIS2 compliance is not a one-person project. In practice it takes a combination of the following profiles – internal, external or a mix, depending on company size:
- Security architects who design technical safeguards and integrate them into existing systems.
- Incident-response specialists who detect, contain and report incidents on time.
- GRC leads (governance, risk and compliance) who translate regulation into verifiable processes.
- Security analysts for ongoing monitoring and assessment.
For many mid-sized companies it is neither necessary nor realistic to hire all roles permanently at once. A mix of permanent hires for core functions and external specialists for project peaks is often faster, cheaper and more flexible.
How to proceed
Three steps help you move from obligation to action. First, assess your own maturity honestly – where do you stand on risk management, reporting processes and accountability? Second, prioritise the critical gaps rather than starting everything at once. Third, secure the right people early, before the market is swept clean.
NIS2 forces no one to buy technology. But having the right people who understand and implement security is now mandatory. That is the uncomfortable but freeing insight: compliance does not start with the tool, it starts with the team.
Want to find the right IT experts faster? At Suppliance we support you with a transparent process, real domain understanding and a strong partner network across the DACH region.

