
Why is NIS2 important for organizations in the Netherlands?
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript

Stronger digital resilience
The first NIS directive laid the foundation for European cooperation in the field of cybersecurity. However, that approach proved too limited. Only vital sectors were covered by the legislation, while other organizations were also falling victim to cyberattacks.
With NIS2, that is changing. The directive significantly expands the obligations and ensures that many more organizations must actively demonstrate that their information security is in order. The goal is clear: to strengthen the digital resilience of the Netherlands. Not just for large institutions, but throughout the entire supply chain – from suppliers to service providers.
Who is affected by NIS2?
The new directive does not only apply to government agencies or energy companies. Organizations in sectors such as healthcare, ICT, education, transport, financial services, food, and waste management are also covered. In addition, NIS2 explicitly focuses on suppliers to these organizations. Do you provide services or software to a party subject to NIS2? Then the requirements indirectly apply to you as well.
The directive distinguishes between:
- Essential entities – for example, government organizations, telecom, energy, or healthcare.
- Important entities – such as ICT service providers, manufacturing companies, data centers, and transport companies.
For both groups, the requirement is the same: you must demonstrate that you have taken measures to mitigate cyber risks and are capable of handling incidents effectively.
The Cyber Security Act (Cbw)
In the Netherlands, NIS2 has been transposed into national legislation: the Cyber Security Act (Cbw). The effective date is August 15, 2026, once the legislation has been formally passed by parliament. The Cbw defines which organizations fall under the law, who is responsible for oversight (such as the Radiocommunications Agency and sectoral regulators), and what sanctions may be imposed. Fines can be substantial, but the primary goal is awareness and prevention.
No certification, but NIS2 compliance is required
There is no such thing as an official NIS2 certification. However, organizations must be compliant, meaning they must be able to demonstrate that they meet the requirements of the directive and the national law.
In practical terms, this means:
- Systematically mapping risks and documenting control measures.
- Ensuring governance and accountability within the board.
- Reporting incidents to the competent authority within 24 hours.
- Establishing supply chain agreements with vendors regarding security and reporting.
- Regularly assessing whether policies and measures remain effective.
An ISO 27001 certification is a huge help in this regard. The ISO standard provides a practical framework (ISMS) that already covers many NIS2 requirements. You can then build on that foundation to address the specific obligations of NIS2.
{{LINKCARD}}
Why you need to start now
The implementation of the Cyber Security Act is fast approaching, and it takes time to get processes, responsibilities, and systems in order. In practice, waiting until the law comes into effect often means starting too late. With a NIS2 GAP analysis you gain insight into your current status and immediately see which steps are needed to achieve compliance. This allows you to take measures in time and avoid surprises during future audits or inspections.
Start your NIS2 compliance journey
NIS2 is important because it strengthens the digital resilience of the Netherlands—not just for large organizations, but for the entire supply chain. The directive requires structural attention to information security, governance, and risk management. By working on NIS2 compliance now, you not only increase your security but also boost the trust of your customers and partners.
Schedule a free, no-obligation consultation below.


.avif)


















