Defaults.Exposed

Defaults.ExposedReports

NIS2 Compliance and Email Authentication: What the Directive Requires

Published

NIS2 compliance means meeting the obligations of Directive (EU) 2022/2555 — the European Union’s updated network-and-information-security law — which requires in-scope “essential” and “important” entities, and by extension the suppliers they depend on, to take “appropriate and proportionate technical, operational and organisational measures” to manage cybersecurity risk. The directive does not name SPF, DKIM, or DMARC anywhere in its text, but email authentication is a textbook example of the “basic cyber hygiene” it demands — and one of the very few such measures anyone can verify from public DNS without touching your systems. The August 2026 defaults.exposed census graded 376,928,750 domains for email authentication and found that 214,276,774 of them — 56.8% — publish neither SPF nor DMARC, and only 20.0% publish any DMARC record at all. That is the baseline email-hygiene gap NIS2’s technical measures are meant to close, measured across the whole internet.

If a regulator, a customer’s procurement team, or your own board asks whether your domains meet the email-security bar NIS2 implies, the honest answer for most organisations is “not yet.” The controls are cheap, public, and checkable — which is exactly why the gap is uncomfortable once someone looks. The figures throughout come from the defaults.exposed August 2026 census, an independent scan of 432,127,908 domains graded as of 2026-08-16. This article is general information about a regulatory regime and how it maps to a measurable technical control; it is not legal advice, and your specific obligations depend on your sector, your national transposition, and your own counsel.


What is NIS2 compliance?

NIS2 is shorthand for Directive (EU) 2022/2555, the second Network and Information Security Directive. It replaced the original 2016 NIS Directive (Directive (EU) 2016/1148), entered into force in January 2023, and set a transposition deadline of 17 October 2024 for European Union member states to write it into national law. Because it is a directive rather than a regulation, the binding detail lives in each country’s implementing statute, and those national laws vary — several member states transposed late, so the exact rules and enforcement timing differ by jurisdiction.

The directive’s purpose is to raise the baseline of cybersecurity across the sectors the EU considers critical to its economy and society, and to make senior management accountable for it. At its core, NIS2 asks in-scope organisations to do three things:

NIS2 divides in-scope organisations into two tiers. Essential entities are the largest operators in the most critical sectors and face the most active supervision. Important entities sit a rung below, with lighter-touch, largely reactive oversight. The security obligations are broadly the same for both; the difference is mainly in how closely regulators watch and how penalties are scaled.”NIS2 compliance,” in practice, means being able to demonstrate — to a regulator, an auditor, or a customer — that the measures in Article 21 are actually in place, not merely written down.


Who NIS2 applies to — and its supply-chain reach beyond the EU

NIS2 casts a far wider net than the original directive. It applies, as a general rule, to medium-sized and larger organisations (broadly, 50 or more staff or more than €10 million in annual turnover) operating in the sectors listed in the directive’s annexes — with some smaller entities pulled in regardless of size when they are uniquely critical.

Essential-entity sectors (Annex I) include energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space.

Important-entity sectors (Annex II) include postal and courier services, waste management, chemicals, food, manufacturing of certain products, digital providers such as online marketplaces and search engines, and research organisations.

If your organisation sits in one of those sectors and clears the size threshold, you are very likely in scope somewhere in the EU. But the reach does not stop at the directly regulated entities — and this is the part that catches organisations who assume NIS2 is “an EU problem, not ours.”

Article 21 explicitly requires in-scope entities to address supply-chain security and the security of their supplier relationships. In practice that means an essential or important entity must assess and manage the cyber risk of the vendors it depends on. So the obligation flows downhill through contracts: a supplier anywhere in the world — including outside the EU — that sells to an EU essential or important entity can find email authentication, and evidence of it, written into a procurement questionnaire or a contract clause. You do not have to be named in the directive to feel it. The commercial pressure to demonstrate baseline hygiene reaches every tier of the supply chain, which is why this piece is relevant well beyond Europe’s borders.

None of this is a substitute for a scoping assessment. Whether any specific organisation is in scope, and under which national law, is a legal question — confirm it with qualified advisers rather than inferring it from a sector list.


Email authentication under NIS2: SPF, DKIM and DMARC as baseline hygiene

Here is the honest starting point, and it matters for credibility: NIS2 does not mandate DMARC by name. The directive text does not mention SPF, DKIM, DMARC, or email authentication as such. Anyone who tells you “NIS2 requires DMARC” as a bare legal fact is overstating the letter of the law.

What NIS2 does require, in Article 21(2), is a set of measures that in-scope entities must take. The list is deliberately outcome-oriented rather than a checklist of named products, and several items map directly onto email authentication:

Email authentication is also singled out by the technical guidance that surrounds the directive. European cybersecurity guidance and, for certain digital-infrastructure and service-provider sectors, the Commission’s implementing rules point to email-security controls including SPF, DKIM, and DMARC as expected measures. So the accurate framing is this: NIS2 requires appropriate technical measures and basic cyber hygiene; email authentication is a widely accepted, externally verifiable instance of both; and for some sectors the supporting technical rules name it directly.

That framing is stronger than an overclaim, not weaker. It means email authentication is not a box you can argue your way out of — it is the cheapest, most visible way to demonstrate that the “basic cyber hygiene” language means something at your organisation. For the record-by-record grading logic, see the DMARC policy methodology, the SPF methodology, and the DKIM methodology. For a plain-language primer on the control itself, what is DMARC walks through every field of the record.


The compliance gap: 56.8% of domains publish neither SPF nor DMARC

Take the “basic cyber hygiene” expectation and measure it against reality, and the gap is not a rounding error — it is the majority of the internet.

Of the 376,928,750 domains graded for email authentication in the August 2026 census, 214,276,774 — 56.8% — publish neither SPF nor DMARC. Not a weak policy, not a monitor-only record: nothing. For more than half the graded web there is no email-authentication posture at all for a regulator, an auditor, a customer’s scan, or an attacker to read. This silent majority is profiled in depth in The Silent Domain: 56.8% of the Internet Has No Email Authentication — the article this one is a compliance-framed sibling of.

That 56.8% is the baseline NIS2’s “appropriate technical measures” are meant to lift. It is worth being precise about what it represents. A domain with neither SPF nor DMARC has done none of the following:

Even the domains that have started often stop short. SPF is present on just 38.8% (146,413,297) of graded domains — meaning nearly two in three publish no sender policy whatsoever. And publishing SPF alone protects the invisible envelope address, not the visible From: line a recipient reads, which is why SPF without an enforcing DMARC policy on top is a half-measure rather than a control. Deliverability suffers too, not just security; when authentication is missing, legitimate mail is more likely to be filtered, a problem examined in why are my emails going to spam.

For a compliance officer, the practical implication is uncomfortable but clarifying. If your organisation’s domains sit in that 56.8%, you are not “partway to hygiene” — you are at the starting line, and any attestation that claims otherwise is contradicted by a public DNS lookup. Check your domain free at defaults.exposed to see, in about 30 seconds, exactly which side of that line each of your domains sits on — the same read a customer’s due-diligence scan would perform.


Only 20.0% publish any DMARC — the NIS2 email-security shortfall

Move from “any authentication at all” to the specific control that closes domain spoofing — DMARC — and the shortfall gets sharper.

Only 20.0% (75,571,248) of the 376,928,750 graded domains publish any DMARC record at all, enforcing or not. That is the most generous possible reading of “has taken the DMARC step,” and four domains in five fail even that. Tighten the test to a DMARC policy that actually does something and the number collapses further: 90.7% (341,945,132) of domains have no enforcing DMARC policy, and only 9.3% (34,983,618) publish an enforcing policy of p=quarantine or p=reject.

The distinction between the 20.0% and the 9.3% is the single most important thing a compliance function can understand about DMARC, because it is where attestations quietly go wrong:

More than half of the domains that bother to publish DMARC leave it at p=none — published, visible, and doing nothing to stop impersonation. So “we have DMARC” is not the finding a regulator or auditor should accept; “our DMARC enforces” is. An external scan grades enforcement, not mere presence, and the honest question under NIS2’s hygiene language is whether the control actually reduces risk — which p=none does not. How to read the aggregate reports that let you move safely from monitoring to enforcement is set out in the DMARC reporting methodology.

This is the same measurement an insurer runs at renewal, incidentally. The commercial and regulatory pressures point the same way, which is why the email-authentication control shows up in cyber-insurance questionnaires and NIS2 supply-chain assessments alike; the underwriting angle is covered in Cyber Insurance Requirements 2026: The Email Controls Underwriters Check.


NIS2 penalties and the path to email-auth compliance

NIS2 gives supervisory authorities real teeth, which is why “appropriate technical measures” has stopped being a purely voluntary aspiration for in-scope entities.

The directive sets maximum administrative fines that member states must provide for. For essential entities, up to €10 million or 2% of total worldwide annual turnover, whichever is higher. For important entities, up to €7 million or 1.4% of total worldwide annual turnover, whichever is higher. Beyond fines, supervisory authorities can issue binding instructions, order entities to remediate, and — for essential entities — temporarily suspend authorisations or bar individuals from management functions. And under Article 20, management bodies are expected to approve and oversee the risk-management measures, with the possibility of personal accountability where they fail to.

Two caveats keep this accurate. First, penalties are set and applied under each member state’s national transposition, so the exact ceilings, triggers, and enforcement practice vary by country. Second, a fine is not automatic for a missing SPF record — enforcement generally follows a significant failing, an incident, or an inspection, not a single technical gap in isolation. The point is not that a p=none policy invites a €10 million fine tomorrow; it is that email authentication is the cheapest way to be visibly on the right side of the hygiene expectation the fines ultimately back. This is general information, not legal advice — the specifics of penalty exposure are a question for qualified counsel.

The path from “would fail” to “would pass” is a sequence of DNS changes plus a few weeks of listening. It is low-risk when done in order, and — crucially for compliance — every step produces evidence you can keep:

  1. Measure your current posture. Establish what each of your sending domains publishes today. If you are among the 56.8% with neither SPF nor DMARC, you are starting from zero; a record at p=none is a monitoring posture, not a protective one.
  2. Publish SPF and DKIM for every legitimate sender. List the services that send mail as you — mail platform, CRM, invoicing, marketing, ticketing — and bring each under SPF and DKIM so genuine mail authenticates and aligns.
  3. Start DMARC at p=none with reporting. Publish a DMARC record in monitor mode with an rua address you actually watch. This changes nothing about delivery while the aggregate reports reveal every sender using your domain. This is the only stage at which p=none is the right answer — a temporary listening post, not a destination.
  4. Move to p=quarantine, then p=reject. Once the reports confirm your legitimate senders align, tighten the policy. Set pct=100 and a matching sp=reject so subdomains are covered and no mail is exempted.
  5. Keep the evidence. NIS2 accountability rewards being able to show, not just assert. A dated record of your enforcing policy and monitoring is the difference between an attestation and proof — and it is exactly what a supply-chain due-diligence request will ask for.

Domains that break legitimate mail almost always skipped the listening phase and jumped straight to p=reject. Sequenced properly, the risk is minimal and the outcome is a control you can defend to a regulator, an auditor, or a customer. If you want the gaps closed properly and kept closed — SPF, DKIM, an enforcing DMARC policy, and continuous monitoring that produces audit-ready evidence — see how the fix works.


What this means

For compliance officers and CISOs, email authentication is the rare NIS2 control that is objective, external, and cheap to verify — which cuts both ways. It is easy for you to check and easy for a regulator, auditor, or customer to check, so an optimistic attestation is a liability rather than an asset. At a 56.8% neither-SPF-nor-DMARC rate and a 9.3% enforcement rate across the internet, the base case is that your organisation’s domains would fail a strict reading of the hygiene expectation. Finding out first, on your own terms, and fixing it, converts a governance risk into documented evidence of the “basic cyber hygiene” the directive asks for.

For IT and security teams, the mapping from directive language to action is direct: “appropriate technical measures” and “basic cyber hygiene” mean, among other things, an enforcing DMARC policy backed by SPF and DKIM on every sending domain.”We have a DMARC record” is not the finding; p=reject, pct=100, sp=reject, and aligned senders are. A domain at p=none will be read as unprotected by any competent scan, and a stakeholder who saw a green result somewhere may believe otherwise. Closing the gap and holding it closed with monitoring is the whole job.

For suppliers and vendors to EU entities, NIS2’s supply-chain provisions mean the pressure reaches you even if you are not directly regulated — even if you are outside the EU entirely. A spoofable domain is a risk you export to every EU essential or important entity you sell to, and it is one they are increasingly obliged to assess in you. Reaching enforcing DMARC before a procurement questionnaire asks for it is the difference between a contract that proceeds and one that stalls on due diligence.


FAQ

What is NIS2 compliance? NIS2 compliance means meeting the obligations of Directive (EU) 2022/2555, the EU’s updated network-and-information-security law, as transposed into your national law. In-scope “essential” and “important” entities must take appropriate and proportionate technical and organisational measures to manage cyber risk (Article 21), report significant incidents on defined deadlines (Article 23), and have management approve and oversee the measures (Article 20). Email authentication is a textbook example of the “basic cyber hygiene” the directive expects — yet the August 2026 census found 56.8% (214,276,774) of 376,928,750 graded domains publish neither SPF nor DMARC, so most organisations start well short of that baseline.

Who does NIS2 apply to? As a general rule, NIS2 applies to medium-sized and larger organisations — broadly 50 or more staff or over €10 million turnover — operating in the sectors listed in the directive’s annexes, split into essential entities (energy, transport, banking, health, digital infrastructure, public administration and more) and important entities (postal, waste, chemicals, food, manufacturing, digital providers and more). Some smaller but uniquely critical entities are included regardless of size. Its supply-chain provisions also reach suppliers — including non-EU ones — that sell to in-scope entities. Whether any specific organisation is in scope, and under which national law, is a legal question to confirm with qualified advisers, not something to infer from a sector list alone.

What are the NIS2 requirements? Article 21(2) sets out the risk-management measures: risk-analysis and information-system security policies; incident handling; business continuity and backups; supply-chain security; secure acquisition, development and maintenance including vulnerability handling; policies to assess the effectiveness of the measures; basic cyber-hygiene and training; cryptography and encryption; human-resources security and access control; and multi-factor authentication. Email authentication (SPF, DKIM, and enforcing DMARC) maps directly onto the basic-hygiene, cryptography, and supply-chain items and is externally verifiable from public DNS. Add the incident-reporting deadlines and management accountability, and that is the shape of the obligation — with the binding detail set by each member state’s transposition.

Does NIS2 require DMARC? Not by name. The directive text does not mention SPF, DKIM, or DMARC, so it is inaccurate to state that NIS2 legally mandates DMARC as such. What it requires is “appropriate and proportionate technical measures” and “basic cyber hygiene,” and email authentication is a widely accepted, externally verifiable instance of both — with supporting technical guidance and some sector-specific implementing rules pointing to it directly. In practice, an enforcing DMARC policy is one of the cheapest ways to demonstrate the hygiene the directive expects. Only 20.0% (75,571,248) of graded domains publish any DMARC record, and just 9.3% (34,983,618) enforce it — so the control is as rare as it is expected. Check your domain free at defaults.exposed to see where yours stands.

Data to cite

See where your own domain stands

NIS2’s email-hygiene bar is public, external, and objective: each of your sending domains either publishes an enforcing DMARC policy backed by SPF and DKIM, or it does not. For most organisations the honest answer is “does not” — 56.8% publish neither SPF nor DMARC, and only 9.3% enforce DMARC — and most owners have never seen it stated plainly, because a record showed up somewhere and a questionnaire got a hopeful tick.

Check your domain free at defaults.exposed — it reads your live SPF, DKIM, and DMARC records from public DNS and tells you instantly whether your policy actually enforces, whether your subdomains are covered, and whether your domain can be forged. It takes about 30 seconds and needs no account — the same read a regulator’s, customer’s, or auditor’s scan would perform, run on your own terms first. If you want the gaps closed properly and kept closed with audit-ready monitoring for supply-chain due diligence, see how the fix works.

Read the flagship census report: The State of Domain Security 2026 →

Related from this series: The Silent Domain: 56.8% of the Internet Has No Email Authentication · Cyber Insurance Requirements 2026: The Email Controls Underwriters Check · What Is DMARC · The Google and Yahoo Deadline, Two Years On

Aggregate data only. Data stored and processed in the EU.


Data source: defaults.exposed August 2026 census, methodology v9, as of 2026-08-16. 376,928,750 domains graded for email authentication from 432,127,908 scanned. All figures are counts of graded domains. References: Directive (EU) 2022/2555 (NIS2), RFC 7489 (DMARC), RFC 7208 (SPF), RFC 6376 (DKIM). This article is general information about a regulatory regime and is not legal, compliance, or coverage advice; NIS2 obligations depend on your sector, national transposition, and your own advisers.


How to cite this report

Press / blog: defaults.exposed (2026). NIS2 Compliance and Email Authentication: What the Directive Requires. defaults.exposed August 2026 Domain Security Census (432,127,908 domains scanned, asOf 2026-08-16). Retrieved from https://defaults.exposed/v9/articles/nis2-compliance-and-email-authentication-what-the-directive-requires

Academic: defaults.exposed. (2026, August 21). NIS2 Compliance and Email Authentication: What the Directive Requires. In defaults.exposed Domain Security Census: August 2026. https://defaults.exposed/v9/articles/nis2-compliance-and-email-authentication-what-the-directive-requires

In-line citation: (defaults.exposed, August 2026 Domain Security Census, n=376,928,750 email-graded domains)


About the defaults.exposed August 2026 Census

The defaults.exposed Domain Security Census is a recurring independent measurement of the public domain namespace. The August 2026 edition scanned 432,127,908 domains between 1–16 August 2026 and graded 376,928,750 of them for email authentication using methodology v9. Scans are conducted from EU infrastructure. No individual domain, registrant, or business is named in any report. All figures are aggregate distributions. Data is stored and processed within the EU.

Methodology: defaults.exposed/v9/methodology Full census report: defaults.exposed/en/articles/the-state-of-domain-security-2026

Data sourced from the August 2026 grading methodology (v9) — 34 checks, 376 million domains. Browse the census statistics or the Census Explorer, or see all August 2026 research →