Summary

The NIS2 Directive (Network and Information Security Directive 2) sets stricter cybersecurity requirements for a far wider group of businesses than the original NIS Directive. Small and medium-sized enterprises in certain sectors also fall under this legislation.

What is NIS2?

The NIS2 Directive is the successor to the original NIS Directive of 2016. Its aim is to raise the level of cybersecurity across the European Union. The directive entered into force in January 2023 and has to be transposed into national legislation by the EU member states.

The Netherlands is working on the Dutch Cybersecurity Act (Cyberbeveiligingswet, Cbw), the Dutch implementation of NIS2. This act replaces the current Dutch Network and Information Systems Security Act (Wbni).

Does your business fall under NIS2?

NIS2 distinguishes between essential and important entities. The following sectors fall under the directive:

Essential sectors

  • Energy
  • Transport
  • Banking & financial
  • Healthcare
  • Drinking water
  • Digital infrastructure
  • Government services
  • Space

Important sectors

  • Postal and courier services
  • Waste management
  • Chemicals industry
  • Food production
  • Manufacturing
  • Digital service providers
  • Research organisations

Please note: suppliers too

If your business supplies an organisation that falls under NIS2, you may indirectly have to deal with the requirements as well. More and more clients are demanding NIS2 compliance from their suppliers.

What are the obligations?

The NIS2 Directive requires organisations to put a number of measures in place:

How do you prepare?

Start with these concrete steps:

1

Determine whether you fall under NIS2

Check whether your sector and the size of your business fall within the scope.

2

Carry out a gap analysis

Map out where you stand today and which measures you still need to take.

3

Implement an ISMS

An Information Security Management System (ISO 27001) covers a large part of the NIS2 requirements.

4

Arrange incident response

Draw up procedures for detecting, reporting and handling security incidents.

5

Use tooling

A compliance tool such as ComplianceGuard helps you manage all the requirements clearly and stay audit-ready.

ComplianceGuard & NIS2

ComplianceGuard includes a dedicated NIS2 extension module that makes it straightforward to meet the NIS2 requirements. Combined with the ISO 27001 module, you have a solid foundation for your cybersecurity compliance.

Request a demo →

More articles