Cybercrime in the EU



NIS2 directive EU
Increasing levels of digital developments are putting pressure on the security of our society and economy. The NIS2 cybersecurity legislation has been drawn up to improve cybersecurity and the resilience of essential services in EU member states. This is the successor to the old NIS directive, that no longer provided adequate protection. The NIS2 directive EU applies to more sectors, and sets stricter security standards and incident reporting requirements. As a cybersecurity expert, DEKRA offers certifications that enable you to demonstrate compliance with NIS2 guidelines. The NIS2 scope consists of (parts of) ISO 27001, IEC 62443 and NIST Cybersecurity Framework (CSF), in combination with additional documentation, depending on your situation.
What is the NIS2 directive EU?
Harmonization of the NIS2 directive EU
From the NIS2 Directive to the Cybersecurity Law
What is covered by the scope of the NIS2 directive EU?
The NIS2 directive EU distinguishes between essential entities and important entities.
Essential entities
Important entities
Industries and the NIS2 directive EU
- Energy: Electricity, district heating, petroleum/crude oil, natural gas, and hydrogen
- Transport: Air, rail, road, and water transport
- Banking: Credit institutions
- Financial Market Infrastructure: Trading venues and central counterparties
- Health: Hospitals, medical laboratories, pharmaceutical research, and manufacturing of medical devices
- Drinking Water: Water supply and distribution
- Waste Water: Wastewater collection and treatment
- Digital Infrastructure: Cloud providers, data centers, DNS service providers, TLD registries, and telecommunications networks
- ICT Service Management: Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs)
- Public Administration: Central government and regional authorities
- Space: Operators of ground-based infrastructure supporting space services
- Manufacturing
- Postal and courier services
- Waste management
- Foodstuffs
- Chemicals
- Research
- Digital providers
New: supplier chain also monitored
Cybersecurity legislation overview
Is your organization ready for NIS2?
What are the obligations under the NIS2 directive EU?
Why DEKRA for NIS2 directive EU?
Cybersecurity expertise

How we support you in meeting the NIS2 directive
- Risk Analysis: DEKRA starts with a comprehensive risk analysis and gap analysis to evaluate the current situation. This includes identifying potential weaknesses and assessing the effectiveness of existing security measures.
- Implementation of Security Measures: Based on the findings from the analyses, DEKRA assists organizations in implementing the necessary security measures. This can range from policy adjustments to staff training.
- Continuous Monitoring and Evaluation: The NIS2 directive EU requires continuous monitoring and evaluation of security measures. DEKRA offers services for regular audits and assessments to ensure organizations remain compliant with the directive and can quickly respond to new threats.
- Incident Response and Recovery: In the event of a security incident, a quick and effective response is crucial. DEKRA helps organizations develop and evaluate incident response plans and recovery strategies to minimize the impact of incidents and resume operations quickly.
Let's get in touch about NIS2 and cybersecurity
Frequently asked questions about the NIS2 Directive
- For essential entities, maximum fines of at least €10 million or 2% of global annual turnover may apply, whichever amount is higher.
- For major entities, the amount is at least €7 million or 1.4% of global annual turnover.
In addition, supplementary European and national rules and guidelines may be adopted. Organizations would therefore do well to continue monitoring developments within European and Dutch legislation, instructions from supervisors, and sector-specific requirements.
For internationally operating organizations, DEKRA can, for example, assess which cybersecurity requirements under NIS2 are relevant and how they relate to local legislation and sector-specific requirements.

