Complying with the law and actually being resilient are two different things. An organization can fill in all the forms and still have no idea who gets out of bed at night when there's an incident.
Duty of care and reporting obligations sound bureaucratic, but they require real capacity: someone who assesses risks, someone who checks supply chain vendors, someone who reports an incident within the set deadline. Research shows that only 33% of European organizations consider themselves fully prepared for NIS2. The rest have the policy, but lack the people.
The difference between compliant and prepared sits exactly in the people who do the work. A risk analysis on paper protects nobody. A SOC analyst who spots an anomaly at three in the morning does.