Direct naar inhoud
Back to Insights
Security

NIS2 Directive: does it apply and what to arrange?

3 April 2026Updated on 5 October 2026Mohammad MoghtaderMohammad Moghtader

Mohammad Moghtader — CTO of Virtual Computing

NIS2 richtlijn compliance voor Nederlandse bedrijven

The NIS2 directive (Network and Information Security Directive 2) is the European Union's updated cybersecurity legislation. It replaces the original NIS directive from 2016 and significantly expands both the scope and the requirements. For many Dutch businesses, this means new obligations around cybersecurity, risk management and incident reporting.

In this article we explain what NIS2 is, whether your organisation falls under it, what you need to arrange and how to prepare — step by step.

What is the NIS2 Directive?

NIS2 is a European directive that requires EU member states to implement stricter cybersecurity rules into national law. The directive was adopted by the European Parliament in November 2022 and member states were given until October 2024 to transpose it into national legislation.

In the Netherlands, NIS2 has been implemented through the Cyberbeveiligingswet (Cybersecurity Act), which has applied since 15 August 2026.

The goals of NIS2 are clear:

  • Raise the overall level of cybersecurity across the EU
  • Harmonise requirements between member states
  • Improve incident reporting and cross-border cooperation
  • Strengthen supply chain security
  • Increase accountability of management

Who does NIS2 apply to?

NIS2 significantly expands the number of organisations that fall under cybersecurity regulation. The directive distinguishes between two categories:

Sectors of high criticality (Annex 1)

Large organisations in these sectors are essential entities; medium-sized organisations are important entities:

  • Energy — electricity, gas, oil, district heating
  • Transport — air, rail, water, road
  • Banking and financial infrastructure
  • Healthcare — hospitals, laboratories, pharmaceutical companies
  • Drinking water supply and waste water
  • Digital infrastructure — DNS providers, data centres, cloud services, internet exchange points
  • ICT service management — managed service providers (MSPs), managed security service providers (MSSPs)
  • Public administration
  • Space

Other critical sectors (Annex 2)

Medium-sized and large organisations in these sectors are, as a rule, important entities:

  • Postal and courier services
  • Waste management
  • Chemical manufacturing and production
  • Food production and distribution
  • Manufacturing — medical devices, electronics, machinery, motor vehicles
  • Digital providers — online marketplaces, search engines, social platforms
  • Research organisations

Size thresholds

Generally, NIS2 applies to organisations in these sectors that meet the following criteria:

CategoryEmployeesAnnual revenueBalance sheet
Medium50-249€10-50 million€10-43 million
Large250+€50 million+€43 million+

Important exceptions: Some organisations fall under NIS2 regardless of size, including DNS service providers, TLD name registries, trust service providers, telecoms providers, government bodies and entities designated by the government, for example because they are the sole provider of an essential service. Cloud and data centre providers and MSPs are only covered from medium size, like the other sectors.

Supply chain implications

Even if your organisation doesn't directly fall under NIS2, you may be affected indirectly. NIS2 requires covered entities to manage cybersecurity risks in their supply chains. This means your clients may require you to meet certain security standards as a condition of doing business.

What are the key requirements?

NIS2 imposes obligations in four main areas:

1. Risk management measures

Organisations must implement appropriate technical, operational and organisational measures to manage cybersecurity risks. At minimum, this includes:

  • Risk analysis and information security policies
  • Incident handling — prevention, detection and response
  • Business continuity — backup management, disaster recovery, crisis management
  • Supply chain security — assessing and managing supplier risks
  • Security in network and system acquisition, development and maintenance
  • Policies for assessing the effectiveness of measures — regular testing and auditing
  • Cryptography and encryption
  • Human resource security — access control, asset management
  • Multi-factor authentication and secure communication

2. Incident reporting

NIS2 introduces strict incident reporting obligations:

TimeframeRequirement
Within 24 hoursEarly warning to the CSIRT and the competent authority
Within 72 hoursInitial assessment including severity and impact
Within 1 monthFinal report with root cause, measures taken and cross-border impact

Incidents that must be reported are those that have or could have a significant impact on the provision of services. This includes incidents affecting availability, integrity or confidentiality.

3. Management accountability

This is a significant change from the original NIS directive. Under NIS2, management bodies (board of directors, executive management) must:

  • Approve the cybersecurity risk management measures
  • Oversee their implementation
  • Be held liable for non-compliance
  • Undergo cybersecurity training

Management can no longer delegate cybersecurity to the IT department and consider it handled. They are personally accountable.

4. Registration and cooperation

Organisations must register in the national register at mijn.ncsc.nl and cooperate with supervisory bodies during inspections and audits.

Timeline and enforcement

When does it take effect?

  • November 2022: directive adopted by the EU
  • 17 October 2024: deadline for national transposition (the Netherlands missed it)
  • 15 August 2026: the Dutch Cyberbeveiligingswet entered into force
  • From that date: registration, the duty of care and the reporting obligation apply; board members have two years to meet the knowledge requirement

Penalties

NIS2 introduces significant penalties for non-compliance:

Entity typeMaximum fine
Essential entities€10 million or 2% of global annual turnover (whichever is higher)
Important entities€7 million or 1.4% of global annual turnover (whichever is higher)

Additionally, a board member who does not meet the knowledge and training requirement can be fined personally (up to €25,000), and for essential entities the supervisory authority can ask the court to temporarily suspend board members.

How to prepare: 7 steps

Step 1: Determine if NIS2 applies to you

Check whether your organisation operates in one of the covered sectors and meets the size thresholds. Also consider whether your clients are covered entities that may impose requirements on your organisation.

Step 2: Conduct a gap analysis

Compare your current security measures against the NIS2 requirements. Identify what you already have in place and what needs to be improved. Key areas to assess:

  • Risk management policies and procedures
  • Incident detection and response capabilities
  • Business continuity and backup strategy
  • Supply chain risk management
  • Access control and authentication (MFA)
  • Employee awareness and training

Step 3: Get management on board

NIS2 requires management accountability. Ensure your board or executive team understands the implications, approves the security strategy and allocates the necessary budget.

Step 4: Implement technical measures

Based on your gap analysis, implement the required technical controls:

Step 5: Establish incident response procedures

Create and document your incident response plan, including:

  • How to detect and classify incidents
  • Who to notify (internal and external)
  • How to meet the 24-hour and 72-hour reporting requirements
  • Post-incident review process

Step 6: Address supply chain security

Map your critical suppliers and assess their security posture. Include cybersecurity requirements in contracts and conduct periodic reviews.

Step 7: Document and test

Document all policies, procedures and measures. Conduct regular tests — including penetration tests, phishing simulations and disaster recovery exercises — and keep records for audit purposes.

How ISO 27001 helps with NIS2 compliance

If your organisation is already ISO 27001 certified — or works with a certified IT partner — you have a significant head start. ISO 27001 covers many of the same areas as NIS2:

NIS2 requirementISO 27001 coverage
Risk analysis and policiesAnnex A.5 — Information security policies
Incident handlingAnnex A.5.24-5.28 — Incident management
Business continuityAnnex A.5.29-5.30 — BCM and ICT readiness
Supply chain securityAnnex A.5.19-5.23 — Supplier relationships
Access controlAnnex A.5.15-5.18, A.8.2-8.5 — Access management
CryptographyAnnex A.8.24 — Use of cryptography
HR securityAnnex A.6 — People controls

Virtual Computing is ISO 27001 certified. That certificate covers our own infrastructure, processes and management. It does not make your organisation compliant, but the part of your IT that we manage does run on a certified foundation.

NEN 7510 for healthcare

For healthcare organisations, the Dutch NEN 7510 standard adds additional requirements for handling medical data. NIS2 lists healthcare as a sector of high criticality, making NEN 7510 compliance more important than ever. Virtual Computing helps healthcare organisations navigate both NIS2 and sector-specific requirements.

Frequently asked questions

Generally, NIS2 targets medium and large organisations. However, certain types of organisations fall under NIS2 regardless of size, including DNS service providers, TLD name registries, trust service providers, telecoms providers and designated sole providers of essential services. A company with fewer than 50 employees also counts as medium-sized if both its annual turnover and balance sheet total exceed €10 million. Additionally, supply chain requirements may affect smaller businesses indirectly.

Essential entities face stricter supervision (proactive) and higher penalties. Important entities are supervised reactively — meaning authorities act after an incident or complaint rather than conducting routine inspections.

Yes. NIS2 explicitly states that management must approve and oversee cybersecurity measures. Under the Dutch act every board member must be trained, and a board member who fails to meet that requirement can be fined personally (up to €25,000). For essential entities, the supervisory authority can also ask the court to temporarily suspend board members.

NIS2 and the GDPR are complementary. GDPR focuses on protecting personal data, while NIS2 focuses on the security of networks and information systems. An incident can trigger obligations under both regulations — for example, a data breach requires GDPR notification to the Data Protection Authority AND NIS2 incident reporting to the cybersecurity authority.

NIS2 does not explicitly require certification. However, implementing an information security management system based on ISO 27001 is widely regarded as the most effective way to demonstrate compliance. Working with an ISO 27001-certified IT partner also provides a strong foundation.

Yes. The Cyberbeveiligingswet has applied since 15 August 2026. If your organisation falls under it, you must be registered at mijn.ncsc.nl and the duty of care and reporting obligation already apply.

You can outsource the implementation and management of security measures to a managed IT services provider, but accountability remains with your organisation's management. Choose a partner that is certified and can demonstrate compliance — like Virtual Computing.

Start with a gap analysis. Compare your current security posture against the NIS2 requirements and identify the areas that need improvement. If you're unsure where to start, contact us for a free assessment.

Get ahead of NIS2

The legislation is now in force. If you are not ready yet, start now and turn compliance into a competitive advantage. Organisations that can demonstrate strong cybersecurity will increasingly win trust — from clients, partners and regulators.

Virtual Computing helps SMBs across the Netherlands achieve and maintain the security standards required by NIS2. Want your company to be ISO 27001, NEN 7510 or NIS2 compliant? Then choose Virtual Computing.

Get in touch for a free NIS2 readiness assessment, or become a client and let us handle your IT security and compliance.

Written by

Questions about this topic?

Contact our team for personal advice.