NIS2 Directive: What Does It Mean for Your Business?

NIS2 richtlijn Wat Betekent Het Voor Jouw Bedrijf

The digital world is changing rapidly, and so are the threats. Cyberattacks are becoming increasingly sophisticated and no longer target only large multinationals, but also medium-sized businesses and essential service providers. To anticipate this, the European Union has introduced the NIS2 Directive. But what exactly does this legislation entail, and why should you, as an entrepreneur, be concerned about it?

At Tech Resolve, we understand that laws and regulations can seem complex. That’s why we’ve created this comprehensive guide to explain what the NIS2 Directive means, who it applies to, the consequences of non-compliance, and—most importantly—how you can prepare your organization.

What Is the NIS2 Directive

What Is the NIS2 Directive?

NIS2 stands for Network and Information Security Directive and is the second European directive on the security of network and information systems. It is a legal framework designed to improve the digital resilience of organizations and limit the impact of cyberattacks.

The directive was published on December 27, 2022, and entered into force on January 17, 2023. Member states had until October 17, 2024, to transpose the directive into national legislation, but many countries, including the Netherlands, did not meet this deadline. The expectation is that the implementation law in the Netherlands will come into effect in mid-2026.

Why Is NIS2 Necessary?

NIS2 replaces the earlier NIS Directive from 2016. The need for a more stringent version is clear: the digital landscape has changed, and cyber threats have evolved. The old directive proved insufficient to address current risks. NIS2 aims to:

  • Guarantee a high, common level of cybersecurity across the EU.
  • Increase the resilience of critical sectors.
  • Harmonize cybersecurity rules across the EU, so that businesses in all member states meet the same minimum requirements.

Who Does the NIS2 Directive Apply To?

The NIS2 Directive is not for everyone. It targets medium-sized and large entities operating in specific, critical sectors. It is crucial to determine whether your organization falls within its scope.

There are two main groups:

  1. Essential Entities (highly critical sectors)
  2. Important Entities (other critical sectors)

Essential Sectors (Annex I)

These sectors have a major impact on society and the economy. Examples include:

  • Energy (electricity, oil, gas, hydrogen)
  • Transport (air, rail, water, road)
  • Banking and financial market infrastructures
  • Healthcare (healthcare providers, manufacturers)
  • Drinking water and wastewater
  • Digital infrastructure (data centers, cloud services)
  • ICT service management (business-to-business)
  • Public administration (central and regional)
  • Space

Other Critical Sectors (Annex II)

  • Postal and courier services
  • Waste management
  • Chemical sector
  • Food industry
  • Manufacturing (medical devices, electronics, vehicles)
  • Digital providers (online marketplaces, search engines, social networks)
  • Research organizations

And What About Small and Medium-Sized Enterprises (SMEs)?

Small and micro-enterprises generally do not fall under the NIS2 Directive. However, there are exceptions:

  • If you provide a unique service that is essential for critical societal or economic activities.
  • If a disruption at your organization could have a major impact on public safety or health.
  • If you provide services to companies that do fall under NIS2, the directive may also apply to you. Responsibility for supply chain security is an important part of NIS2.

Check if the NIS2 Directive applies to your organization using this online self-assessment from the government. This will help you determine whether your organization falls under the NIS2 legislation.

Note: The NIS2 Directive has extraterritorial effect. Non-European companies that offer services within the EU may also fall under the directive.

What Are the Obligations

What Are the Obligations?

If your organization falls under the NIS2 Directive, you will face a range of obligations designed to ensure a solid cybersecurity foundation.

1. Cybersecurity Risk Management

Organizations must take appropriate and proportionate technical, operational, and organizational measures to manage cyber risks. This includes:

  • Risk analysis and policy: Identifying vulnerabilities and establishing security policies.
  • Incident handling: Procedures to respond quickly and effectively to cyber incidents.
  • Business continuity and crisis management: Ensuring the business can continue operating after an attack.
  • Supply chain security: Imposing security requirements on suppliers and partners.
  • Cyber hygiene: Basic principles such as strong passwords, updates, and security training for employees.
  • Cryptography and encryption: Using encryption to protect data.

2. Incident Reporting Obligation

One of the most important pillars is the reporting obligation. An incident must be reported to the competent authority in three phases:

PhaseDeadlineDescription
Phase 1Within 24 hoursAn early warning that a significant incident has occurred.
Phase 2Within 72 hoursA more detailed notification with additional information.
Phase 3Within 30 daysA final report describing the cause and measures taken.

3. Management Responsibility

A notable and strict requirement is the personal liability of directors. Management is responsible for NIS2 compliance. This means:

  • Directors must approve the cybersecurity policy and oversee its implementation.
  • Directors can be held accountable in cases of negligence.
  • Directors are required to undergo training on cyber risks.

What Are the Consequences of Non-Compliance?

The sanctions for non-compliance are significant and are designed to serve as a strong deterrent. The amount depends on the classification of the entity.

Fines

Entity TypeMaximum Fine
Essential€10,000,000 or 2% of global annual turnover (whichever is higher)
Important€7,000,000 or 1.4% of global annual turnover (whichever is higher)

Other Sanctions

In addition to high fines, competent authorities may impose other measures, including:

  • Public disclosure of the violation
  • Orders to take specific measures
  • Temporary suspension of activities or revocation of permits
How Can Tech Resolve Prepare Your Business

How Can Tech Resolve Prepare Your Business?

Before you engage with us, you can already take a first step yourself.

  1. Check if the NIS2 Directive applies to your organization using this online self-assessment from the government.
  2. Determine to what extent you already comply with the new legislation using this quick scan.

The NIS2 Directive is complex legislation that can have a significant impact on your organization. It is never too early to start preparing. Tech Resolve offers services to make your business more resilient and compliant with the upcoming requirements.

1. The NIS2 Scan

We begin with a thorough analysis to determine whether your organization falls under the NIS2 Directive and where the biggest risks and gaps are. This is the first and most crucial step.

2. Developing an Action Plan

Based on the scan, we develop a concrete, step-by-step plan to meet the NIS2 requirements. This includes both technical and organizational measures.

3. Implementation of Solutions

We help you implement the necessary security measures, such as:

  • Multi-Factor Authentication (MFA)
  • Vulnerability Management
  • Total Endpoint Security
  • Network infrastructure security (firewalls)
  • Backup solutions to prevent data loss

4. Awareness and Training

We provide Security Awareness Training for employees, because the human factor is one of the biggest risks.

Conclusion

The NIS2 Directive is more than just a new law; it is an opportunity to take your digital resilience to the next level. By taking action now, you not only avoid hefty fines and reputational damage, but you also build a safer and more resilient business for the future.

Don’t wait until the legislation takes effect. Start your preparations today.

Schedule a no-obligation NIS2 Scan and discover what the NIS2 Directive means for your organization.

Frequently Asked Questions About NIS2

What does NIS2 mean?

NIS2 stands for Network and Information Security Directive, the second European directive on network and information security.

Who does the NIS2 Directive apply to?

The directive applies to medium-sized and large organizations in critical sectors such as energy, transport, healthcare, digital infrastructure, and more.

When will the NIS2 Directive take effect?

The directive was published in 2022, but national legislation in the Netherlands is expected to take effect in mid-2026.

What are the fines for non-compliance?

For essential entities, the fine can be up to €10,000,000 or 2% of global annual turnover.

Do I fall under the NIS2 Directive?

You can determine this through a NIS2 scan. Tech Resolve is happy to help you with this.

Tech Resolve – Your partner for a secure and future-proof digital environment.

Leave a Reply