
How do you prepare your organization for the NIS2 Directive? Everything about NIS2 compliance and awareness
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript

What does the NIS2 directive entail?
This directive not only introduces stricter rules for companies but also places extra emphasis on increasing cybersecurity awareness within organizations at every level. What does this mean in practice? Companies must not only keep their security systems up to date but also ensure that both management and employees understand the risks of cyberattacks. An important point to note about the NIS2 is that responsibility now explicitly lies with management. This ensures that cybersecurity is taken seriously at the highest level as well.
When does NIS2 come into effect?
The European NIS2 directive itself has been in force since January 2023. Each member state had to transpose the directive into national law; in the Netherlands, this was done via the Cyber Security Act. That legislative process took longer than planned. On July 7, 2026 the Senate approved the Cyber Security Act. The law will come into effect on August 15, 2026 , without a transition period. The latter is important. There is no grace period of six months or longer. The obligations apply immediately from August 15.
Key components of NIS2
The NIS2 directive introduces stricter requirements regarding governance and accountability than its predecessor, NIS1. The goal is to better equip organizations against cyberattacks. But what does this entail exactly? Here are the key components of NIS2:
- More sectors now fall under the directive, including healthcare, digital infrastructure, and public administration.
- Companies must establish a risk management strategy to identify and mitigate potential cyber risks.
- Serious security incidents must be reported to the authorities within 24 hours.
- Supervisory authorities have more powers to audit companies and can impose higher fines for non-compliance.
With these improvements, NIS2 establishes a solid foundation for network and information security and increases the resilience of critical infrastructure.
Challenges in implementing NIS2
Implementing the NIS2 directive brings several challenges. While these new rules are important for strengthening cybersecurity, organizations may encounter a number of obstacles:
Costs vs. benefits
Complying with the NIS2 directive often requires significant investment, both in technology and in staff training. New software, systems, and security measures can be costly. However, in the long term, the benefits—such as preventing data breaches and avoiding heavy fines—far outweigh these expenses.
Internal resistance
Change can trigger resistance within organizations, especially if employees do not immediately see the importance of cybersecurity. By actively involving employees and management in the implementation process and clearly communicating the benefits of NIS2 compliance, this resistance can be reduced.
How do you demonstrate NIS2 compliance?
There is no such thing as an official "NIS2 certificate." The law itself does not prescribe a specific quality mark. However, that does not mean you cannot take steps to demonstrate that you have your affairs in order. There are a few routes that work well in practice:
- The NIS2 Supply Chain quality mark: this independent label has three levels (SC10, SC20, and SC30), tailored to your risk profile and the role you play in the supply chain. Especially for suppliers who need to demonstrate that they work securely, this is a manageable route.
- ISO 27001: do you already have this certification? Then you are already well on your way. Large parts of your existing management system count toward compliance, making the path to demonstrable NIS2 compliance much faster.
- Sector-specific standards: if you work in healthcare, then NEN 7510 relevant. If you work in the public sector, the BIO plays a role. These standards align well with the requirements of the Cyber Security Act.
{{LINKCARD}}
How to increase NIS2 awareness?
Increasing awareness regarding the NIS2 directive is important, as many organizations are required to comply with it. Below are some accessible ways to create NIS2 awareness:
Training and education
NIS2 awareness can be increased in various ways, from traditional training sessions to innovative methods like gamification. Platforms such as Guardey, which offer gamified cybersecurity awareness, help employees get involved in an engaging way and improve their knowledge of threats.
Furthermore, the NIS2 directive explicitly places responsibility for cybersecurity on management. This means that executives are required to undergo NIS2 training to ensure they are well-prepared for their new responsibilities. These training programs are designed to make management aware of the risks and to provide them with the tools to implement cybersecurity strategies within their organization.
Internal communication
In addition to training, a strong internal communication strategy is essential. Regular updates, emails, and workshops on cybersecurity risks and the NIS2 directive help increase awareness among all employees. By reinforcing communication with visual aids such as infographics or internal campaigns, employees can be better informed about their role in protecting the organization against cyberattacks.
What does the NIS2 Executive Training entail?
The NIS2 Executive awareness training focuses on the following topics:
📌 Recognizing cyber threats
Executives must be aware of the various types of cyber threats that can affect their organization, such as ransomware, phishing attacks, and supply chain attacks. Understanding these threats is the first step toward protection.
📌 Developing a sector-specific cybersecurity strategy
Every sector has its own unique risks. Developing a cybersecurity strategy that aligns with the specific risks of the sector in which the organization operates is important for adequately warding off threats.
📌 Preparing for a cyber incident
Executives must know what steps to take in the event of a cyber incident. This includes both crisis communication and damage mitigation to minimize the impact on the organization.
📌 Understanding legal obligations
NIS2 brings legal and regulatory obligations, such as reporting incidents and complying with security measures. Executives must be well-informed about these to ensure legal compliance and avoid potential fines.
📌 Establishing an effective governance structure
It is up to directors to establish an effective governance structure for managing cybersecurity. This includes not only internal processes, but also accountability to regulatory bodies.
Need help?
At Fendix, we are happy to help you increase NIS2 awareness within your organization, for both employees and management. Curious about how we can support your organization? Let's have an introductory chat with no strings attached!


.avif)

















