NIS2 Directive: does it apply and what to arrange?
Mohammad Moghtader — CTO of Virtual Computing
The NIS2 directive (Network and Information Security Directive 2) is the European Union's updated cybersecurity legislation. It replaces the original NIS directive from 2016 and significantly expands both the scope and the requirements. For many Dutch businesses, this means new obligations around cybersecurity, risk management and incident reporting.
In this article we explain what NIS2 is, whether your organisation falls under it, what you need to arrange and how to prepare — step by step.
What is the NIS2 Directive?
NIS2 is a European directive that requires EU member states to implement stricter cybersecurity rules into national law. The directive was adopted by the European Parliament in November 2022 and member states were given until October 2024 to transpose it into national legislation.
In the Netherlands, NIS2 has been implemented through the Cyberbeveiligingswet (Cybersecurity Act), which has applied since 15 August 2026.
The goals of NIS2 are clear:
- Raise the overall level of cybersecurity across the EU
- Harmonise requirements between member states
- Improve incident reporting and cross-border cooperation
- Strengthen supply chain security
- Increase accountability of management
Who does NIS2 apply to?
NIS2 significantly expands the number of organisations that fall under cybersecurity regulation. The directive distinguishes between two categories:
Sectors of high criticality (Annex 1)
Large organisations in these sectors are essential entities; medium-sized organisations are important entities:
- Energy — electricity, gas, oil, district heating
- Transport — air, rail, water, road
- Banking and financial infrastructure
- Healthcare — hospitals, laboratories, pharmaceutical companies
- Drinking water supply and waste water
- Digital infrastructure — DNS providers, data centres, cloud services, internet exchange points
- ICT service management — managed service providers (MSPs), managed security service providers (MSSPs)
- Public administration
- Space
Other critical sectors (Annex 2)
Medium-sized and large organisations in these sectors are, as a rule, important entities:
- Postal and courier services
- Waste management
- Chemical manufacturing and production
- Food production and distribution
- Manufacturing — medical devices, electronics, machinery, motor vehicles
- Digital providers — online marketplaces, search engines, social platforms
- Research organisations
Size thresholds
Generally, NIS2 applies to organisations in these sectors that meet the following criteria:
| Category | Employees | Annual revenue | Balance sheet |
|---|---|---|---|
| Medium | 50-249 | €10-50 million | €10-43 million |
| Large | 250+ | €50 million+ | €43 million+ |
Important exceptions: Some organisations fall under NIS2 regardless of size, including DNS service providers, TLD name registries, trust service providers, telecoms providers, government bodies and entities designated by the government, for example because they are the sole provider of an essential service. Cloud and data centre providers and MSPs are only covered from medium size, like the other sectors.
Supply chain implications
Even if your organisation doesn't directly fall under NIS2, you may be affected indirectly. NIS2 requires covered entities to manage cybersecurity risks in their supply chains. This means your clients may require you to meet certain security standards as a condition of doing business.
What are the key requirements?
NIS2 imposes obligations in four main areas:
1. Risk management measures
Organisations must implement appropriate technical, operational and organisational measures to manage cybersecurity risks. At minimum, this includes:
- Risk analysis and information security policies
- Incident handling — prevention, detection and response
- Business continuity — backup management, disaster recovery, crisis management
- Supply chain security — assessing and managing supplier risks
- Security in network and system acquisition, development and maintenance
- Policies for assessing the effectiveness of measures — regular testing and auditing
- Cryptography and encryption
- Human resource security — access control, asset management
- Multi-factor authentication and secure communication
2. Incident reporting
NIS2 introduces strict incident reporting obligations:
| Timeframe | Requirement |
|---|---|
| Within 24 hours | Early warning to the CSIRT and the competent authority |
| Within 72 hours | Initial assessment including severity and impact |
| Within 1 month | Final report with root cause, measures taken and cross-border impact |
Incidents that must be reported are those that have or could have a significant impact on the provision of services. This includes incidents affecting availability, integrity or confidentiality.
3. Management accountability
This is a significant change from the original NIS directive. Under NIS2, management bodies (board of directors, executive management) must:
- Approve the cybersecurity risk management measures
- Oversee their implementation
- Be held liable for non-compliance
- Undergo cybersecurity training
Management can no longer delegate cybersecurity to the IT department and consider it handled. They are personally accountable.
4. Registration and cooperation
Organisations must register in the national register at mijn.ncsc.nl and cooperate with supervisory bodies during inspections and audits.
Timeline and enforcement
When does it take effect?
- November 2022: directive adopted by the EU
- 17 October 2024: deadline for national transposition (the Netherlands missed it)
- 15 August 2026: the Dutch Cyberbeveiligingswet entered into force
- From that date: registration, the duty of care and the reporting obligation apply; board members have two years to meet the knowledge requirement
Penalties
NIS2 introduces significant penalties for non-compliance:
| Entity type | Maximum fine |
|---|---|
| Essential entities | €10 million or 2% of global annual turnover (whichever is higher) |
| Important entities | €7 million or 1.4% of global annual turnover (whichever is higher) |
Additionally, a board member who does not meet the knowledge and training requirement can be fined personally (up to €25,000), and for essential entities the supervisory authority can ask the court to temporarily suspend board members.
How to prepare: 7 steps
Step 1: Determine if NIS2 applies to you
Check whether your organisation operates in one of the covered sectors and meets the size thresholds. Also consider whether your clients are covered entities that may impose requirements on your organisation.
Step 2: Conduct a gap analysis
Compare your current security measures against the NIS2 requirements. Identify what you already have in place and what needs to be improved. Key areas to assess:
- Risk management policies and procedures
- Incident detection and response capabilities
- Business continuity and backup strategy
- Supply chain risk management
- Access control and authentication (MFA)
- Employee awareness and training
Step 3: Get management on board
NIS2 requires management accountability. Ensure your board or executive team understands the implications, approves the security strategy and allocates the necessary budget.
Step 4: Implement technical measures
Based on your gap analysis, implement the required technical controls:
- Multi-factor authentication on all critical systems
- Endpoint protection and monitoring
- Network segmentation and firewall management
- Encryption for data at rest and in transit
- Logging and monitoring for incident detection
Step 5: Establish incident response procedures
Create and document your incident response plan, including:
- How to detect and classify incidents
- Who to notify (internal and external)
- How to meet the 24-hour and 72-hour reporting requirements
- Post-incident review process
Step 6: Address supply chain security
Map your critical suppliers and assess their security posture. Include cybersecurity requirements in contracts and conduct periodic reviews.
Step 7: Document and test
Document all policies, procedures and measures. Conduct regular tests — including penetration tests, phishing simulations and disaster recovery exercises — and keep records for audit purposes.
How ISO 27001 helps with NIS2 compliance
If your organisation is already ISO 27001 certified — or works with a certified IT partner — you have a significant head start. ISO 27001 covers many of the same areas as NIS2:
| NIS2 requirement | ISO 27001 coverage |
|---|---|
| Risk analysis and policies | Annex A.5 — Information security policies |
| Incident handling | Annex A.5.24-5.28 — Incident management |
| Business continuity | Annex A.5.29-5.30 — BCM and ICT readiness |
| Supply chain security | Annex A.5.19-5.23 — Supplier relationships |
| Access control | Annex A.5.15-5.18, A.8.2-8.5 — Access management |
| Cryptography | Annex A.8.24 — Use of cryptography |
| HR security | Annex A.6 — People controls |
Virtual Computing is ISO 27001 certified. That certificate covers our own infrastructure, processes and management. It does not make your organisation compliant, but the part of your IT that we manage does run on a certified foundation.
NEN 7510 for healthcare
For healthcare organisations, the Dutch NEN 7510 standard adds additional requirements for handling medical data. NIS2 lists healthcare as a sector of high criticality, making NEN 7510 compliance more important than ever. Virtual Computing helps healthcare organisations navigate both NIS2 and sector-specific requirements.
Frequently asked questions
Generally, NIS2 targets medium and large organisations. However, certain types of organisations fall under NIS2 regardless of size, including DNS service providers, TLD name registries, trust service providers, telecoms providers and designated sole providers of essential services. A company with fewer than 50 employees also counts as medium-sized if both its annual turnover and balance sheet total exceed €10 million. Additionally, supply chain requirements may affect smaller businesses indirectly.
Essential entities face stricter supervision (proactive) and higher penalties. Important entities are supervised reactively — meaning authorities act after an incident or complaint rather than conducting routine inspections.
Yes. NIS2 explicitly states that management must approve and oversee cybersecurity measures. Under the Dutch act every board member must be trained, and a board member who fails to meet that requirement can be fined personally (up to €25,000). For essential entities, the supervisory authority can also ask the court to temporarily suspend board members.
NIS2 and the GDPR are complementary. GDPR focuses on protecting personal data, while NIS2 focuses on the security of networks and information systems. An incident can trigger obligations under both regulations — for example, a data breach requires GDPR notification to the Data Protection Authority AND NIS2 incident reporting to the cybersecurity authority.
NIS2 does not explicitly require certification. However, implementing an information security management system based on ISO 27001 is widely regarded as the most effective way to demonstrate compliance. Working with an ISO 27001-certified IT partner also provides a strong foundation.
Yes. The Cyberbeveiligingswet has applied since 15 August 2026. If your organisation falls under it, you must be registered at mijn.ncsc.nl and the duty of care and reporting obligation already apply.
You can outsource the implementation and management of security measures to a managed IT services provider, but accountability remains with your organisation's management. Choose a partner that is certified and can demonstrate compliance — like Virtual Computing.
Start with a gap analysis. Compare your current security posture against the NIS2 requirements and identify the areas that need improvement. If you're unsure where to start, contact us for a free assessment.
Get ahead of NIS2
The legislation is now in force. If you are not ready yet, start now and turn compliance into a competitive advantage. Organisations that can demonstrate strong cybersecurity will increasingly win trust — from clients, partners and regulators.
Virtual Computing helps SMBs across the Netherlands achieve and maintain the security standards required by NIS2. Want your company to be ISO 27001, NEN 7510 or NIS2 compliant? Then choose Virtual Computing.
Get in touch for a free NIS2 readiness assessment, or become a client and let us handle your IT security and compliance.
Related services
Written by
Related articles
How do you create a secure cloud workspace?
Creating a secure cloud workspace requires a layered approach that starts with the foundation: identity management and access control.
SecurityWhy network security is essential
Working online is the norm today, but it also comes with risks. Hackers and cybercriminals prey on unsecured networks.
SecuritySecure cloud working with M365
Secure cloud working for SMBs in 5 steps. Learn how your SMB can work securely and efficiently with Microsoft 365 in the cloud.