What is NIS2?
At its core, NIS2 is the updated cybersecurity framework for the European Union. It is designed to strengthen the digital defenses of organizations that provide essential services to our society. This directive replaces the older 2016 version and introduces a much higher "bar" for security.
For the Netherlands, it is important to note that NIS2 will be formalized as the Cyberbeveilighingswet (Cbw). Although the general EU deadline has passed, the Dutch mandate is now officially set for July 1, 2026.
Not sure how your current security aligns with the new requirements? Schedule a NIS2 Gap Analysis to identify the 5 steps you need to take before July 2026.
Where does it apply?
NIS2 distinguishes between essential entities and important entities. In general terms: medium-sized and large organisations (50+ employees or more than €10 million in annual turnover) in the sectors below need to be compliant.
Unsure whether your organisation needs to be compliant under NIS2? Contact your national cybersecurity authority or request a Safesecur Group baseline assessment via our contact form to find out exactly where you stand.
The four pillars of NIS2
The directive is build on four key obligations that every organisations must fulfill.
Significant incidents must be reported to the designated authority within 24 hours as an early warning, followed by a full incident report within 72 hours.
Organisations are also responsible for the cybersecurity practices of their suppliers and service providers.
Board members bear ultimate responsibility and can be held personally liable in case of demonstrable negligence.
Core obligations
What does management accountability mean in practice?
This is one of the most significant changes compared to the previous directive. Senior management must demonstrate involvement in the organisation's cybersecurity governance. In specific terms, this means:
- Cybersecurity is a boardroom priority. Ensure your leadership team has the required knowledge with our 4 hour Executive NIS2 Session.
- Formal approval and endorsement of the security policy.
- Active follow-up on risk reports and audit findings.
Regulators expect the leadership team to understand the risks and actively driving mitigation efforts.
Penalties. Non-compliance can result in fines of up to €10 million or 2% of global annual turnover for essential entities, and up to €7 million or 1.4% for important entities. Regulators can also impose temporary management bans.
Where to start: a practical approach
- Determine your status
- Verify whether your organisation qualifies as essential or important under NIS2. Your sector, size, and any cross-border activities all play a role in this assessment.
- Conduct a baseline assessment
- Measure your current information security posture against NIS2 requirements. This immediately surfaces gaps and helps you prioritize what needs to be addressed first.
- Build a risk register
- Identify your critical systems, processes and dependencies. Map targeted security measures to each identified risk.
- Set up incident reporting processes
- Establish an internal escalation path that enables you to report an incident within 24 hours, including the right contracts, templates and communication flows.
- Engage your supply chain
- Map your critical suppliers and set minimum cybersecurity requirements for them, formalized in contracts and vendor assessments.
- Implement a managementsystem
- An ISMS (Information Security Management System), ideally aligned with ISO 27001, provides the structure needed to maintain and demonstrate
July 1st getting uncomfortably close?
We get it, the deadline is looming and the to-do list is growing. Instead of hitting the panic button, hit the PDCA4YOU button. Our platform breaks down the complex NIS2 legislation into manageable steps. No stress, just a clear plan of action!
Don’t wait until the July 2026 deadline. Start your transition to NIS2 compliance today with our expert-led assessments and training. Get in touch with our specialists.
Do you know where your organisation stands?
Safesecur Group supports you with baseline assessments, implementation guidance, and a practical management system used by many organisations that makes NIS2 compliance within reach.