Knowledge NIS2

What is NIS2 and what does the directive mean for your organisation?

Published on , last updated on · 13 min read
By Martijn de Visser, founder of NOVARO. He builds the connecting layer between business systems: AI, integrations and intelligent automation for SMEs and enterprises.

NIS2, in full Directive (EU) 2022/2555, is the European directive on a high common level of cybersecurity across the Union. It requires essential and important entities in eighteen sectors to take risk-management measures and to report significant incidents in stages, and places final responsibility with the management body. Unlike a regulation, a directive works through national law.

What is NIS2?

NIS2 is Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. It was adopted on 14 December 2022, published in the Official Journal on 27 December 2022 and entered into force twenty days later, on 16 January 2023 (Article 45).

The main difference with DORA is the instrument. NIS2 is a directive, not a regulation: it does not apply directly, but through national law. Member States had to adopt and publish the transposing measures by 17 October 2024 and apply them from 18 October 2024 (Article 41). On that same date, the old NIS Directive, Directive (EU) 2016/1148, was repealed (Article 44). What applies in your country is therefore set out in the national transposition act.

For an organisation, the directive comes down to four questions: who falls within scope (Articles 2 and 3), which measures you must take (Article 21, the duty of care), what you must report and within which deadlines (Article 23, the reporting duty), and who supervises that with what consequences (Articles 20 and 32 to 34). This guide walks through those four, and then covers the Dutch transposition and the relationship with DORA.

Up front: this article is general information based on the text of the directive and on public official sources, not legal advice. A self-assessment or checklist is not a certification and does not mean your organisation complies with NIS2; the competent authority ultimately determines how the rules apply to your organisation. The state of Dutch legislation described here is that of 26 July 2026.

Who does NIS2 apply to?

NIS2 combines a sector list with a size threshold. Article 2(1) provides that the directive applies to entities of a type referred to in Annex I or Annex II which qualify as medium-sized enterprises under Article 2 of the Annex to Recommendation 2003/361/EC, or which exceed the ceilings for medium-sized enterprises. In practice, the directive starts to bite around fifty staff or ten million euro in turnover or balance sheet total.

Annex I lists eleven sectors of high criticality:

  • energy;
  • transport;
  • banking;
  • financial market infrastructures;
  • health;
  • drinking water;
  • waste water;
  • digital infrastructure;
  • ICT service management (business-to-business);
  • public administration;
  • space.

Annex II lists seven other critical sectors:

  • postal and courier services;
  • waste management;
  • chemicals;
  • food;
  • manufacturing (certain branches);
  • digital providers, such as online marketplaces and search engines;
  • research.

There are exceptions upwards from the size threshold. Regardless of their size, the directive covers providers of public electronic communications networks and of publicly available electronic communications services, trust service providers, top-level domain name registries and DNS service providers; the same goes for the sole provider in a Member State of a service that is essential for the maintenance of critical societal or economic activities, and for certain public administration entities (Article 2(2)). Entities identified as critical entities under Directive (EU) 2022/2557 are covered regardless of size as well (Article 2(3)), as are entities providing domain name registration services (Article 2(4)).

Article 3 splits that group into two classes. Essential entities include entities of a type referred to in Annex I which exceed the ceilings for medium-sized enterprises (paragraph 1, point (a)), qualified trust service providers, top-level domain name registries and DNS service providers regardless of size (point (b)), providers of public electronic communications networks or services which qualify as medium-sized enterprises (point (c)), certain public administration entities (point (d)) and entities a Member State designates itself or which are identified as critical entities (points (e) and (f)). All other entities of a type referred to in Annex I or II are important entities (paragraph 2).

That distinction does not change what you have to do, but how closely it is supervised and how high a fine can go. The duty of care in Article 21 and the reporting duty in Article 23 apply to essential and important entities alike. Member States keep a list of both, which had to be established by 17 April 2025 and is reviewed at least every two years thereafter (Article 3(3)).

Duty of care: which measures does NIS2 require? (Article 21)

Article 21(1) requires essential and important entities to take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of their network and information systems, taking into account the state of the art and the costs of implementation. Those measures follow an all-hazards approach: not only attacks, but also outages, errors and physical events. Article 21(2) lists ten subjects the measures must cover as a minimum:

  • policies on risk analysis and information system security;
  • incident handling;
  • business continuity, such as backup management and disaster recovery, and crisis management;
  • supply chain security, including security-related aspects concerning the relationships between the entity and each direct supplier or service provider;
  • security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure;
  • policies and procedures to assess the effectiveness of the measures;
  • basic cyber hygiene practices and cybersecurity training;
  • policies and procedures regarding the use of cryptography and, where appropriate, encryption;
  • human resources security, access control policies and asset management;
  • where appropriate: multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the entity.

Note the fourth point: NIS2 extends the duty of care to your suppliers. When deciding which measures are appropriate, you take into account the vulnerabilities specific to each direct supplier and service provider and the overall quality of their products and cybersecurity practices, including their secure development procedures (Article 21(3)). At Union level, coordinated security risk assessments of critical ICT supply chains can be carried out on top of that (Article 22).

If you find yourself that you do not comply with the measures of paragraph 2, Article 21(4) requires you to take all necessary, appropriate and proportionate corrective measures without undue delay. Recording and fixing a gap is part of the norm, not an infringement in itself.

Reporting duty: what do you report and by when? (Article 23)

Essential and important entities notify significant incidents without undue delay to their CSIRT or, where applicable, their competent authority (Article 23(1)). An incident is significant if it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned, or if it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage (Article 23(3)).

The notification runs in stages, and the clock starts when you become aware of the incident (Article 23(4)):

  1. 01Within 24 hours: the early warning. Without undue delay and in any event within 24 hours of becoming aware of the significant incident. Where applicable, it indicates whether the incident is suspected of being caused by unlawful or malicious acts and whether it could have a cross-border impact (point (a)).
  2. 02Within 72 hours: the incident notification. Without undue delay and in any event within 72 hours of becoming aware of the incident. This notification updates the early warning and contains an initial assessment of the incident, including its severity and impact and, where available, the indicators of compromise (point (b)).
  3. 03On request: the intermediate report. The CSIRT or, where applicable, the competent authority may request an intermediate report on relevant status updates (point (c)).
  4. 04Within one month: the final report. Not later than one month after the incident notification you submit a final report with a detailed description of the incident, the type of threat or root cause, the mitigating measures applied and ongoing, and, where applicable, the cross-border impact (point (d)).

Beyond notifying the authorities, Article 23 contains a duty towards your own customers. Recipients of your services that are potentially affected by a significant cyber threat must be informed without undue delay of any measures or remedies they can take themselves, and where appropriate of the threat itself (Article 23(2)). That is as much a communication question as a technical one: who calls whom, with what story, within which hour?

What does NIS2 mean for the management body? (Article 20)

Article 20 puts responsibility squarely in the boardroom. The management body of an essential or important entity approves the measures of Article 21, oversees their implementation and can be held liable for infringements by the entity of that article (Article 20(1)). Under NIS2, cybersecurity is not a subject a board can delegate and then forget.

Training comes with it. Member States ensure that members of the management body follow training, and encourage entities to offer similar training to their employees on a regular basis, so that they can identify risks and assess cybersecurity risk-management practices and their impact on the services provided (Article 20(2)).

The enforcement toolkit has a sharp edge that reaches the individual. Where earlier measures prove ineffective, the competent authority may, for essential entities, temporarily suspend or have suspended a certification or authorisation concerning part of the services, and may request a temporary prohibition on the responsible person exercising managerial functions (Article 32(5)). Natural persons who represent or effectively direct an essential entity can be held liable for failing to ensure compliance (Article 32(6)).

Supervision and sanctions: what is at stake? (Articles 32 to 34)

This is where the two classes diverge in practice. For essential entities, the supervisor may act without a prior trigger: on-site inspections and off-site supervision, regular and targeted security audits by independent bodies, ad hoc audits after an incident, security scans based on risk assessment, and requests for documentation and for evidence that policies were actually implemented (Article 32(2)). For important entities, the competent authority acts in principle after the fact, when there is evidence or an indication that the entity does not comply with the directive (Article 33(1)).

On finding an infringement, the authority can issue warnings, adopt binding instructions with a deadline, order the infringement to cease, order that service recipients be informed of the threat, order the implementation of audit recommendations, designate a monitoring officer, require public disclosure of the infringement and impose or request the imposition of an administrative fine (Article 32(4)).

For fines, the directive sets floors on the maximum that Member States must make possible. For infringements of Article 21 or Article 23, essential entities face a maximum of at least ten million euro or at least 2 % of the total worldwide annual turnover in the preceding financial year, whichever is higher (Article 34(4)). For important entities that floor is at least seven million euro or at least 1,4 % of that same turnover (Article 34(5)). In all cases fines must be effective, proportionate and dissuasive, taking into account the circumstances of the case.

How is NIS2 transposed in the Netherlands?

Because NIS2 is a directive, the norm you are actually held to sits in national law. The Netherlands transposes NIS2 through the Cyberbeveiligingswet (Cybersecurity Act), which replaces the Wet beveiliging netwerk- en informatiesystemen (Wbni). The House of Representatives adopted the bill on 15 April 2026 and the Senate on 7 July 2026.

The Cyberbeveiligingsbesluit of 8 July 2026 provides in Article 35 that the Cyberbeveiligingswet and the decree enter into force on 15 August 2026 (Staatsblad 2026, 189). According to the joint Dutch government announcement of 7 July 2026, new obligations apply from that date to more than eight thousand organisations in the Netherlands.

That same announcement summarises the obligations in four lines that track the directive closely: registration in the national entity register, the duty of care (a risk analysis and, on that basis, appropriate measures to manage the risks to network and information systems), the reporting duty (significant incidents within the statutory deadlines to the CSIRT and the supervisor) and the final responsibility of the management body for managing cyber risk.

Two things to hold on to. First: the Netherlands was late. The directive set 17 October 2024 as the deadline for adopting the transposing measures (Article 41); the Dutch act enters into force almost two years later. Second: the date of this guide matters. The state described above is that of 26 July 2026 and the supervisory practice is still being filled in. When in doubt, check the current publications in the Staatsblad and the information from your supervisor.

How does NIS2 relate to DORA?

For the financial sector the route is different. Article 4(1) of NIS2 provides that the directive, including the provisions on supervision and enforcement in Chapter VII, does not apply to entities for which sector-specific Union legal acts require cybersecurity risk-management measures or the notification of significant incidents that are at least equivalent in effect. Article 4(2) sets out when requirements count as equivalent, among other things by mirroring them against Article 21(1) and (2).

DORA is exactly such a sector-specific act. Article 1(2) of Regulation (EU) 2022/2554 provides that, in relation to financial entities identified as essential or important entities pursuant to national rules transposing Article 3 of NIS2, the regulation is to be considered a sector-specific Union legal act for the purposes of Article 4 of that directive. In plain terms: if you work in the financial sector, DORA is your framework for digital operational resilience.

What DORA requires exactly is set out in the guide What is DORA?. Two caveats. The exception attaches to the entity and to whether the sector-specific requirements are equivalent in effect (Article 4(1) and (2)), not to the sector as a whole. And if you supply ICT services to financial clients, your own organisation may still fall under NIS2 in its own right on the basis of Annex I or II, for instance in ICT service management or digital infrastructure.

How does a structured self-assessment help?

If you want to know where your organisation stands, you can walk through the directive and its national transposition article by article. A structured self-assessment makes that manageable: for each requirement you record whether it applies (with a reason if it does not), how mature the implementation is on a scale from 0 (absent) to 5 (optimised), and which reasoning and evidence support that score. Article 21 asks for appropriate and proportionate measures; that proportionality should be visible in the assessment, with the reasoning attached.

Novaro Compliance helps structure the self-assessment. The platform is in development and is being built with launching partners; NIS2 is one of the frameworks the first release focuses on. To be clear: a completed self-assessment is not a certification and does not mean your organisation complies with NIS2. What it does give the board is a substantiated picture of where the organisation stands and where the work is, which is precisely what Article 20 expects of a management body.

More context: the Cybersecurity & compliance service describes how Novaro approaches security and demonstrability in the broader environment, and the frequently asked questions explain, among other things, how the platform handles your data.

Frequently asked questions about this topic.

Does NIS2 apply to my organisation?
That depends on two questions. Is your type of entity referred to in Annex I or Annex II, and do you qualify as a medium-sized enterprise or larger under Recommendation 2003/361/EC? If the answer to both is yes, the directive applies (Article 2(1)). Some types are covered regardless of size, such as DNS service providers, top-level domain name registries, trust service providers and providers of public electronic communications networks and services (Article 2(2)). The precise implementation is set out in the national transposition act.
What is the difference between an essential and an important entity?
Article 3 draws the line: entities of a type referred to in Annex I which exceed the ceilings for medium-sized enterprises are essential, among others, and all other entities of a type referred to in Annex I or II are important. The duty of care in Article 21 and the reporting duty in Article 23 are identical for both classes. The difference lies in supervision (also ex ante for essential entities, Article 32; in principle ex post for important entities, Article 33) and in the floors for the maximum fine (Article 34(4) and (5)).
Within how many hours must I report an incident under NIS2?
Significant incidents follow a staged reporting duty (Article 23(4)): an early warning without undue delay and in any event within 24 hours, an incident notification within 72 hours, an intermediate report on request, and a final report not later than one month after the incident notification. The deadlines start when you become aware of the incident, not when it began.
Does NIS2 still apply if DORA already applies to my organisation?
For financial entities, DORA is considered a sector-specific Union legal act for the purposes of Article 4 of NIS2 (Article 1(2) of Regulation (EU) 2022/2554). Where sector-specific requirements are at least equivalent in effect, the relevant provisions of NIS2 do not apply (Article 4(1)). If you supply ICT services to the financial sector, however, your own organisation may still fall under NIS2 in its own right on the basis of Annex I or II.