For two years, NIS2 was a planning problem. Legal teams reviewed the directive. Compliance teams built frameworks. Security teams mapped controls against Article 21. The assumption across most ...