Cybersecurity act
Jul 27, 2026Cyber SecurityWhat does cybersecurity regulation mean for your organization?
Cybersecurity legislation is a timely and urgent issue for many organizations. Whereas information security used to be primarily a technical responsibility, it has now become a top priority. European regulations are imposing increasingly stringent requirements on how organizations manage cyber risks, report incidents, and ensure the security of their supply chain partners.
From policy to evidence
For organizations, this primarily means that they must take demonstrable steps to strengthen their digital resilience. The NIS2 directive, in particular, has a major impact. This European cybersecurity regulation applies to a much broader group of organizations than the original NIS Directive and requires companies to demonstrate that they are actively working to strengthen their digital resilience. DEKRA offers audits and certifications to help organizations meet these requirements. With the right cybersecurity support, organizations can effectively and demonstrably fulfill these obligations.
What is the cybersecurity act?
Cybersecurity act encompasses all laws, guidelines, and standards that require organizations to adequately secure their network and information systems. The goal is to prevent cyberattacks, data breaches, and disruptions to essential processes, or to mitigate their impact.
Legislation focuses not only on technical security measures, but also on organizational processes, governance, and risk management. This means that organizations must, among other things:
- Systematically assess cyber risks;
- Implement appropriate security measures;
- Report incidents promptly;
- Evaluate suppliers and supply chain partners;
- Raising employee awareness of cyber threats;
- Demonstrate that processes are effectively organized.
Cybersecurity laws therefore affect the entire organization, from IT and operations teams to procurement and management. As a result, organizations are increasingly turning to external cybersecurity support to accelerate compliance and better manage risks.
NIS2: Europe's most important cybersecurity act
The NIS2 directive (Network and Information Security Directive 2) is currently the most important piece of European cybersecurity law. NIS2 is the successor to the original NIS legislation, which was introduced in 2016. The NIS2 Directive is designed to enhance the cyber resilience of essential and important organizations.
NIS2 applies to sectors such as energy, transportation, healthcare, manufacturing, food, digital services, and government organizations. Medium-sized organizations may also fall under the directive if they operate in critical sectors.
For many organizations, this means that cybersecurity is no longer optional but a legal requirement. The NIS2 Directive distinguishes between two categories of organizations: essential entities and important entities.
The key obligations under NIS2 are:
- A duty of care for risk management;
- A mandatory reporting requirement for serious incidents;
- Supervision by competent authorities;
- Directors' liability;
Essential Entities
Essential entities are subject to more intensive oversight by the regulator. They may be subject to random checks at any time, even when no cyber incident has occurred. This oversight may include audits, security scans, and on-site inspections.
These organizations are subject to stricter accountability requirements. They must be able to demonstrate, through documentation and evidence, that they comply with the requirements of the NIS2 Directive.
Key Entities
Significant entities are also subject to the NIS2 Directive, but supervision is less intensive in practice. An audit is generally conducted only when there are indications that the organization is not complying with the regulations, for example, following a cyber incident or based on reports received.
These organizations must also be able to demonstrate that, at the time of an incident, they complied with the applicable cybersecurity requirements and had taken appropriate measures.
The main difference between essential and important entities is the intensity of supervision. Essential entities are subject to proactive oversight and may be audited even without a specific trigger. For significant entities, oversight is primarily reactive, and audits typically take place when there are indications that the organization is not complying with legal requirements. Both categories are subject to, among other things, a duty of care, a reporting obligation, and a registration requirement.
Cybersecurity legislation requires demonstrable compliance
A frequently asked question is how organizations can prove that they comply with cybersecurity legislation. The NIS2 Directive does not specify exactly which certification is required, but it does require organizations to demonstrate that they have implemented appropriate measures.
Internationally recognized standards provide a solid foundation for this. They help organizations structure processes, manage risks, and objectively demonstrate compliance. Depending on your organization, various standards may be relevant:
Cybersecurity isn't just about taking measures; it's also about being able to demonstrate that your organization is adequately prepared. In our white paper, you'll learn about the European developments, risks, and standards that are important for your cybersecurity strategy.
International Organization for Standardization (ISO) 27001 is the globally recognized standard for information security. This standard helps you establish an Information Security Management System (ISMS) that enables you to manage risks and continuously work toward improvement. For organizations subject to NIS2, ISO 27001 is often a logical starting point. Many of the requirements set forth in the legislation align directly with the standard, such as:
- Risk Management;
- Access Control;
- Supplier Evaluation;
- Incident Management;
- Internal audits;
- Management review.
Although certification is not mandatory, ISO 27001 helps organizations comply with cybersecurity regulations in a structured and verifiable manner. Read more about ISO 27001 and NIS2 here.
International Electrotechnical Commission (IEC) 62443 is the leading cybersecurity standard for industrial automation and control systems (IACS). This standard is particularly relevant for organizations that use operational technology (OT), such as manufacturing companies, energy companies, and infrastructure operators.
The standard covers both technical and organizational measures and helps organizations demonstrate compliance with NIS2. Although NIS2 and IEC 62443 focus on different aspects of cybersecurity, they complement each other perfectly. IEC 62443 is relevant for, among other things:
- Secure product development;
- System Security;
- Requirements for service providers;
- Security levels for products and systems.
For industrial organizations, IEC 62443 is a powerful tool for the practical implementation of cybersecurity legislation. Read more about IEC 62443 and NIS2 here.

CCV pentesting quality mark
With the CCV pentesting quality mark you demonstrate that your organization works professionally and safely. In order to obtain this quality mark, you must, among other things, show that you have qualified employees who carry out the test in a professional manner.
Details

ISO 27001 certification
Demonstrate that information security is a high priority within your organization with the ISO/IEC 27001 certification.
Details

RED Directive testing
You must comply with the Delegated Act of the Radio Equipment Directive (RED) from August 2025. Read more about future legislation and how DEKRA can help you here.
Details
An important aspect of modern cybersecurity legislation is supply chain security. This is because organizations share responsibility for the cybersecurity resilience of suppliers, software partners, and other external parties. This requires a structured approach, such as assessing supplier risks, stipulating security requirements in contracts, and periodically evaluating critical suppliers. Organizations with complex international supply chains, in particular, view this as one of the greatest challenges under NIS2.
Cybercrime in the EU
How does your organization contribute to strengthening the EU’s digital resilience? In this white paper, we discuss the impact of cybercrime.
Request a White Paper
Overview of Cybersecurity Legislation
This white paper provides a clear overview of NIS2, RED-DA, and CRA, and explains how you can comply with the stricter requirements.
Request a White Paper
How DEKRA Helps with cybersecurity regulation
DEKRA supports organizations with independent audits, GAP analyses, and certifications in the field of cybersecurity. With DEKRA’s expertise, you’ll gain insight into:
- Which cybersecurity laws apply to your organization;
- Where the most significant compliance gaps lie;
- Which standards are the best fit;
- What next steps are needed.
Whether you’re just starting your NIS2 process, working toward ISO 27001 certification, or looking to certify industrial systems in accordance with IEC 62443, DEKRA guides your organization from baseline assessment and gap analysis through implementation, audit, and certification. This allows you to demonstrate compliance with applicable cybersecurity legislation and build future-proof cyber resilience.
Would you like to learn more about how DEKRA can support your organization in the area of cybersecurity? Simply contact us using the form below.