Summary
The NIS2 Directive (Network and Information Security Directive 2) sets stricter cybersecurity requirements for a far wider group of businesses than the original NIS Directive. Small and medium-sized enterprises in certain sectors also fall under this legislation.
What is NIS2?
The NIS2 Directive is the successor to the original NIS Directive of 2016. Its aim is to raise the level of cybersecurity across the European Union. The directive entered into force in January 2023 and has to be transposed into national legislation by the EU member states.
The Netherlands is working on the Dutch Cybersecurity Act (Cyberbeveiligingswet, Cbw), the Dutch implementation of NIS2. This act replaces the current Dutch Network and Information Systems Security Act (Wbni).
Does your business fall under NIS2?
NIS2 distinguishes between essential and important entities. The following sectors fall under the directive:
Essential sectors
- Energy
- Transport
- Banking & financial
- Healthcare
- Drinking water
- Digital infrastructure
- Government services
- Space
Important sectors
- Postal and courier services
- Waste management
- Chemicals industry
- Food production
- Manufacturing
- Digital service providers
- Research organisations
Please note: suppliers too
If your business supplies an organisation that falls under NIS2, you may indirectly have to deal with the requirements as well. More and more clients are demanding NIS2 compliance from their suppliers.
What are the obligations?
The NIS2 Directive requires organisations to put a number of measures in place:
- Risk assessment - Regular analysis of cybersecurity risks
- Incident handling - Procedures for detecting, responding to and reporting incidents
- Business continuity - Measures to maintain continuity during cyber incidents
- Supplier security - Security of the supply chain
- Encryption and access control - Appropriate technical measures
- Training - Awareness and training of staff
- Notification duty - Report significant incidents within 24 hours
How do you prepare?
Start with these concrete steps:
Determine whether you fall under NIS2
Check whether your sector and the size of your business fall within the scope.
Carry out a gap analysis
Map out where you stand today and which measures you still need to take.
Implement an ISMS
An Information Security Management System (ISO 27001) covers a large part of the NIS2 requirements.
Arrange incident response
Draw up procedures for detecting, reporting and handling security incidents.
Use tooling
A compliance tool such as ComplianceGuard helps you manage all the requirements clearly and stay audit-ready.
ComplianceGuard & NIS2
ComplianceGuard includes a dedicated NIS2 extension module that makes it straightforward to meet the NIS2 requirements. Combined with the ISO 27001 module, you have a solid foundation for your cybersecurity compliance.
Request a demo →