Legislation

NIS2 implementation at Fendix: from gap analysis to compliance

Implementation
Information Security
NIS2
Supply Chain

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

The starting gun has fired! The Network and Information Security Directive (NIS2) is now live. We frequently hear from directors and CISOs that becoming NIS2-compliant is perceived as time-consuming and abstract. We are certain it doesn't have to be. Our NIS2 implementation guides organizations to demonstrable compliance within 8 weeks, whether you are an SME or an enterprise organization. Together, we’ll ensure you stay ahead of the curve.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

This article was last updated on
24.08.2026
Written by
Jurre
't Lam
Information Security Consultant & Employer Branding and Marketing Specialist

Next-Gen Consultancy: what does a NIS2 implementation look like?

At Fendix, a NIS2 project isn't about dictating rigid rules, but about building a workable security foundation that aligns with your organization and IT infrastructure. We begin the process with a NIS2 GAP analysis.

The baseline assessment: NIS2 GAP analysis

Within one working day, we map out your current state of information security and supply chain risks. Our consultant checks what is already in order, what needs improvement, and how we can address it. This allows us to build upon what is already in place. For example, some organizations may already have ISO 27001.

The action plan and risk analysis

Following the NIS2 GAP analysis, you will receive all recommendations and a management summary in one clear action plan, giving you insight into what needs to be done regarding the duty of care, notification obligations, and registration requirements. We want you to understand exactly what still needs to be accomplished.

 

Simultaneously, we will conduct a joint risk analysis for your company. This is not only a legal requirement but also ensures clear prioritization within the action plan. We identify not only where internal risks lie, but also your role within the entire supply chain.

Implementation and embedding in the workplace

The priorities are clear and the risk analysis has been completed. You’ve left the starting blocks and are in motion. It’s time to execute the action plan. We set up the mandatory processes and train your staff in a way that accelerates your business rather than slowing it down. The added value of Fendix lies in our pragmatic and practical approach. We don't force our own templates and way of working on you. For example, would you prefer to manage your asset registration in a software platform? Let's go! Do you need help and does Excel work for you? Then we will provide you with the necessary tools.

{{LINKCARD}}

Continuous compliance

Our goal is for you to demonstrably meet legal obligations and the strict supply chain requirements of clients, without compromising your team's productivity. In short, we ensure you fulfill your duty of care, notification, and registration obligations, so your customers can enter into a partnership with peace of mind.

While many consultancy firms view compliance as the finish line, Fendix focuses on the journey. After all, compliance is a daily process, not a one-time event. Continuous improvement and review are therefore core components of our implementation. We don't just hand you a box of templates; we work with you to ensure those solid plans don't gather dust after a year. Our consultants integrate this approach from the very start.

Certification options

Certification against the NIS2 is unfortunately not possible. Although the Cyber Security Act (NIS2) is a law, you may still have a supply chain obligation to demonstrate NIS2 compliance. For this purpose, the NIS2 Supply Chain quality mark was established. The NIS2 Supply Chain offers organizations with supply chain obligations the opportunity to receive a quality mark through a standardized audit process.

 

What are the tangible benefits of a Next-Gen NIS2 trajectory?

Through our NIS2 implementation trajectory, you not only meet your management liability requirements but also proactively demonstrate that you are fulfilling your duty of care. This shows good faith to authorities (such as the Dutch Authority for Digital Infrastructure, RDI) and helps you retain partners and clients.

 

Implementing with Fendix also saves you time by resolving complex compliance questions while building on what you already have in place. Anyone can write a policy, but writing a policy that aligns with your organization's specific risks requires expertise. We provide a clear sparring partner who understands today's digital reality, ensuring a pragmatic NIS2 approach.

Want to know what your NIS2 implementation could look like?

Whether you are an SME owner looking to quickly meet legal obligations or a CISO seeking pragmatic momentum for your enterprise environment, you don't have to reinvent the wheel. We help you stay ahead of the curve.

  • Are you a NIS2-obligated organization falling directly under the law? Then check this page.
  • You might be one of the tens of thousands of suppliers that need to comply with the NIS2 Directive indirectly. Take a look at this page.

 

If you would like a no-obligation consultation, we can arrange that too. We will answer all your questions in one hour. Schedule your consultation below.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

How many people participate?

Request now

Thanks!
Oops! The form could not be submitted. Please try again.

More resources

Join our team

Employee Spotlight: from consultant to marketing specialist

by
Jurre
Blog
Legislation

Cybersecurity Act (NIS2) incident reporting procedure: the step-by-step plan as a download

by
Mathijs
Download
Legislation

What is the difference between NIS and NIS2?

by
Mathijs
Kennisartikel