Is NIS2 creating Europe’s next cybersecurity champions?
To contact us: editorial@fw.media

For almost two decades, Europe developed recognised cybersecurity technologies without ever producing true global leaders capable of competing with the US giants. Innovation was plentiful, as were companies, but the market remained fragmented, funding was dispersed and demand was insufficiently harmonised to support the emergence of continent-wide platforms.
The implementation of the NIS2 Directive could permanently alter this trajectory. Behind the appearance of a regulatory text, it may constitute Europe’s first industrial policy applied to cybersecurity. By significantly extending security obligations to tens of thousands of organisations, it is creating an internal market large enough to support the emergence of new champions.
The debate now extends well beyond regulatory compliance. It concerns Europe’s ability to build its own digital resilience industry.
Europe excelled at technology components, not platforms
The contrast with the United States is striking. Europe has world-class academic research, internationally recognised cryptography experts and companies specialising in critical infrastructure protection, threat intelligence, industrial systems and penetration testing. It also trains a significant proportion of the sector’s best researchers and engineers.
Yet the most strategic layers of global cybersecurity remain largely dominated by US groups such as MICROSOFT, CROWDSTRIKE, PALO ALTO NETWORKS, FORTINET and SENTINELONE.
This dominance cannot be explained solely by the technological quality of their products. It is also the result of a favourable economic environment: a vast domestic market, substantial federal defence and intelligence budgets, abundant venture capital and relatively harmonised regulation.
Europe, by contrast, remained fragmented for years. Each country had its own requirements, national authorities, procurement practices and industrial ecosystems. European vendors frequently developed cutting-edge technologies but struggled to reach critical scale. NIS2 is beginning to challenge precisely this fragmentation.
Regulation creates a market
NIS2 is often described simply as a tightening of security obligations. That description is accurate, but incomplete.
The directive significantly expands the number of organisations within its scope. Alongside the traditional operators of critical sectors, it now covers many companies working in transport, energy, healthcare, telecommunications, digital services, manufacturing, logistics, local government and waste management. The suppliers serving these organisations are also gradually entering the scope of scrutiny.
This expansion is producing a major economic effect. Thousands of European organisations that until recently still regarded cybersecurity as a primarily technical function must now implement risk governance, maintain continuous monitoring, develop incident detection and response capabilities, document their procedures and involve senior management directly.
Cybersecurity is ceasing to be a one-off investment and becoming a permanent obligation. This development is profoundly transforming the structure of the market. Cybersecurity expenditure is no longer based solely on discretionary decisions made by IT departments; it is gradually becoming part of recurring budgets for compliance, risk management and business continuity.
The real NIS2 market lies beyond large corporations
Large companies already have security operations centres, specialist teams, incident-response capabilities and mature governance programmes. They will strengthen these systems, but their transformation is already well under way.
The real market lies among mid-sized companies, local authorities, healthcare institutions, regional manufacturers, local service operators and critical suppliers.
These organisations must meet comparable requirements without having the necessary human resources. Mass recruitment of SOC analysts, incident-response specialists and security officers is unrealistic while such profiles remain scarce. Their only viable alternative is to outsource a growing proportion of these functions to platforms capable of providing continuous protection.
The platform era succeeds the age of standalone tools
For two decades, cybersecurity was built through the accumulation of technologies. Companies successively purchased firewalls, antivirus software, backup solutions, EDR platforms, SIEM systems, identity-management tools and detection platforms.
This approach is now reaching its limits. Regulatory obligations, increasingly sophisticated attacks and skills shortages are prompting companies to look for partners capable of managing an entire resilience function. The objective is no longer to sell another piece of software, but to operate a critical function over the long term.
This explains the success of platforms combining round-the-clock monitoring, incident response, threat intelligence, AI-powered automation, regulatory compliance, vulnerability management and, in some cases, cyber insurance.
A new generation of European players
Several European companies with different but converging trajectories are positioning themselves across this emerging landscape.
Dutch company EYE SECURITY is a particularly clear illustration of this shift. Its recent €60 million funding round is not intended solely to finance commercial expansion. The company says it is building a “sovereign European cybersecurity platform” combining AI-assisted detection, a permanently available SOC, incident response, cyber insurance and a vendor-agnostic approach. Its ambition is less to market an individual technology than to become a European operator of digital resilience.
In France, CHAPSVISION is following a different route while pursuing a comparable ambition. Through a succession of acquisitions, the group is building a data-intelligence platform integrating cybersecurity, data analytics, intelligence, artificial intelligence and software for government, defence and critical-infrastructure applications. While EYE SECURITY primarily targets companies subject to NIS2, CHAPSVISION is seeking to establish a sovereign capability for processing strategic information.
Other companies also occupy promising positions.
SEKOIA.IO is developing a threat-detection and intelligence platform widely used by security operations centres and managed security service providers.
HARFANGLAB is gradually establishing itself as one of Europe’s leading EDR alternatives, with a strong presence among government bodies and operators of sensitive infrastructure.
In Germany, HORNETSECURITY is progressively transforming its expertise around Microsoft 365 into a comprehensive cloud-security, backup and compliance platform for European SMEs.
These companies may not share the same customers or technologies, but they are undergoing the same evolution: moving from specialist software vendor to trusted operator.
Sovereignty becomes a competitive advantage
Sovereignty is no longer merely a political argument. It is gradually becoming an economic purchasing criterion, significantly changing the commercial conversation.
Companies no longer ask only how well a solution performs. They also want to know where their data are hosted, which jurisdiction applies, who operates the security operations centre, what dependencies exist on foreign providers and under what conditions they can switch suppliers.
This change is being driven by geopolitical tensions as much as by the proliferation of European regulations, from NIS2 and the Cyber Resilience Act to DORA and the GDPR. European players are now seeking to turn these regulatory requirements into a commercial advantage.
Artificial intelligence accelerates market concentration
This dynamic is being amplified by AI. Attackers are automating phishing campaigns, accelerating vulnerability discovery and industrialising their operations. In response, cybersecurity platforms are using AI to correlate alerts, assist analysts, accelerate investigations, generate reports and automate response procedures.
This development naturally favours companies capable of investing heavily in data, infrastructure and research teams.
Platforms with large customer bases will improve their models more rapidly, attract more talent and strengthen their detection capabilities. As in other areas of artificial intelligence, economies of scale are becoming decisive.
Consolidation will be the next challenge
The directive alone does not guarantee the emergence of European champions.
Several obstacles remain. The transposition of NIS2 is still largely being handled at national level, with timetables and interpretations varying between member states. European companies continue to have access to less funding than their US competitors. A substantial part of their infrastructure still depends on major US cloud and cybersecurity providers. Finally, the chronic shortage of skilled professionals continues to constrain the sector’s growth capacity.
These limitations make a new wave of consolidation increasingly likely.
The coming years could see the emergence of a small number of pan-European platforms capable of combining technologies, managed services, artificial intelligence, compliance and insurance, while the most successful specialists become acquisition targets.



