Legislation

What is the difference between NIS and NIS2?

NIS2
Legislation

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

The NIS2 directive is not just an update to the original NIS. Where the first directive focused on network and information security within a limited group of organizations, NIS2 takes a more fundamental approach. More companies are included, requirements have been tightened and the responsibility of directors has increased. But what does that mean for your organization in concrete terms? And how do you properly prepare for NIS2 compliance?

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

This article was last updated on
14.07.2026
Written by
Mathijs
Oppelaar
Operational Manager & Partner

What was the NIS?

The NIS (Network and Information Systems Directive) was introduced in 2016 to strengthen digital resilience across Europe. Its goal: to ensure that vital sectors properly secure their IT systems against cyber threats. At the time, the directive primarily applied to a small group of organizations, such as energy companies, telecom providers, and water boards. For many other sectors, the NIS had little direct impact.

In practice, this approach proved too limited. Cyberattacks affected not only critical infrastructure but also municipalities, healthcare institutions, suppliers, and SMEs. This led to a revision: NIS2.

What changes with NIS2?

The NIS2 directive significantly expands these obligations. Not only vital organizations, but also essential and important entities must demonstrate that their information security is in good order. The key differences at a glance:

Onderdeel NIS NIS2
Toepassing Vitale sectoren (bijv. energie, transport, telecom) Breder: ook zorg, overheid, ICT, financiële dienstverlening en meer
Verantwoordelijkheid Vooral operationeel Ook bestuurders krijgen expliciete verantwoordelijkheid
Sancties Nationale handhaving, minder concrete boeteregels Striktere handhaving en duidelijke boetes
Leveranciersketen Beperkte aandacht voor keten Keten en leveranciers vallen expliciet onder de eisen
Beveiligingsmaatregelen Algemene verplichtingen voor beveiliging Concretere eisen voor risicomanagement, incidentrespons en governance
Rapportageplicht Melden bij grote incidenten Striktere meldplicht met korte termijn (bijv. binnen 24 uur bij significante incidenten)

A directive is not a law in itself. NIS2 is a mandate from the EU to its member states to transpose its content into national legislation. In the Netherlands, this is the Cybersecurity Act (Cbw), which replaces the Wbni. The act will officially take effect on August 15, 2026.

NIS2 and ISO 27001: how do they relate to each other?

NIS2 and ISO 27001 have many commonalities. ISO 27001 provides a structured framework (ISMS) to implement and safeguard NIS2 security measures. With a well-structured ISMS, you already meet a large portion of the NIS2 requirements. It is not a one-to-one replacement, but it helps your organization demonstrably comply with requirements regarding risk management, documentation, and periodic evaluations. Many organizations therefore use ISO 27001 as the foundation for their NIS2 implementation. From that base, you can specifically add the directive's requirements—for example, regarding governance and supply chain management.

{{LINKCARD}}

What does NIS2/the Cyber Security Act mean for your organization?

There is a good chance that your organization falls under NIS2, even if that was not the case under the old NIS. Consider:

  • Municipalities and government organizations
  • ICT service providers
  • Healthcare institutions (in addition to NEN 7510)
  • Suppliers of vital or essential services
  • SMEs that are part of a supply chain

In this context, not only technical security is important, but also policy, risk management, and awareness within the organization. Furthermore, executives are given explicit responsibility. They must be able to demonstrate that they have taken measures and have knowledge of the risks.

Where do you start with NIS2?

The first step is insight. With a free NIS2 check you get a clear picture of where your organization currently stands and what steps are still needed to achieve compliance. From there, we guide organizations through NIS2 implementation, conducting internal audits, and setting up processes that meet the directive's requirements. Want to take it a step further? Then the NIS2 Supply Chain certificate (NIS2 SC) is a valuable quality mark that allows suppliers to demonstrate that they meet the requirements set by NIS2 organizations for their partners.

Demonstrable NIS2 compliance

The transition from NIS to NIS2 requires more than just technical measures. It is about demonstrable accountability, risk management, and collaboration throughout the entire supply chain. By starting now with a baseline assessment or NIS2 check, you avoid having to act under time pressure later. And with the right guidance, you ensure that your organization is not only compliant but also truly operates more securely.

 

Schedule a free, no-obligation 45-minute consultation or start the free NIS2 check immediately to discover where your organization stands.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

How many people participate?

Request now

Thanks!
Oops! The form could not be submitted. Please try again.

More resources

NIS2

Cybersecurity Act effective August 15, 2026: what you need to know

thru
Henry
Kennisartikel
Information Security

NIS2 & ISO 27001: the overlap, differences and how your organization becomes compliant

thru
Mathijs
Download
Legislation

Does the Cyber Security Act (NIS2) apply to me?

thru
Mathijs
Download