The regulation establishes a minimum level of security, but cyber threats evolve faster than legislation. For this reason, an organization that formally meets the requirements is not automatically resilient.
The difference becomes apparent when the measures are put to the test. Policies, procedures, and technical solutions should be complemented by periodic testing and cyber incident simulations to verify how the organization responds, recovers affected systems, and maintains its operations.
The question is not only whether a business continuity plan or an incident response procedure exists, but whether the organization can actually put that plan into practice when an incident affects critical systems and services.
Ultimately, cyber resilience means more than protecting IT infrastructure: it means the ability of the business to continue operating and delivering essential services during and after an incident.
Compliance must be demonstrable
With DNSC Order No. 1/2026, the question for organizations concerned is no longer simply “Does NIS2 apply to us?”, but also “Do we understand the risks we are exposed to, do we have the necessary measures in place, and can we demonstrate that they work?”
The objective is not simply to tick compliance boxes or prepare documentation for an audit. Risk assessment, maturity assessment, remediation, implementation, and testing of security measures must form a continuous process through which compliance effectively contributes to strengthening the organization's resilience.