lock on laptop keyboard
Cybersecurity with NIS2

What do you need to know about the NIS2 directive in the EU?

NIS2 directive EU

Increasing levels of digital developments are putting pressure on the security of our society and economy. The NIS2 cybersecurity legislation has been drawn up to improve cybersecurity and the resilience of essential services in EU member states. This is the successor to the old NIS directive, that no longer provided adequate protection. The NIS2 directive EU applies to more sectors, and sets stricter security standards and incident reporting requirements. As a cybersecurity expert, DEKRA offers certifications that enable you to demonstrate compliance with NIS2 guidelines. The NIS2 scope consists of (parts of) ISO 27001, IEC 62443 and NIST Cybersecurity Framework (CSF), in combination with additional documentation, depending on your situation.

What is the NIS2 directive EU?

The NIS2 directive EU is a European directive, and stands for Network and Information Security Directive. NIS2 is the successor to the original NIS legislation, which was introduced in 2016. The aim of the NIS2 directive EU is to ensure that organisations providing essential services, such as healthcare facilities and energy companies, identify and address their cybersecurity risks. Various monitoring and enforcement measures are also included in the NIS2 directive EU. NIS2 is a law. You are therefore required to comply with the NIS2 directive EU since the summer of 2025.

Harmonization of the NIS2 directive EU

ENISA is the European Network and Information Security Agency and is responsible for ensuring that Europe becomes cybersecure. They have made it known that there will not be a harmonised standard for the NIS2 scope in the future.

From the NIS2 Directive to the Cybersecurity Law

The NIS2 Directive is European legislation that sets out the minimum cybersecurity obligations that organizations must comply with. In the Netherlands, NIS2 is being transposed into national legislation: the Cybersecurity Law. This Law makes the NIS2 obligations legally binding for organizations that fall within its scope. This means that regulators can enforce and impose sanctions when organizations fail to demonstrate compliance with the requirements for cybersecurity, incident reporting, and risk management.
When the Cybersecurity Law takes effect, it will replace the current Network and Information Systems Security Law (Wbni).

What is covered by the scope of the NIS2 directive EU?

The NIS2 directive EU distinguishes between essential entities and important entities.

Essential entities

Essential entities can be subjected to random audits. These organisations can be audited without an incident having occurred. Audits can include security scans and on-site inspections. These organisations are under a magnifying glass, so to speak. An essential organisation must be able to demonstrate that it complies with the EU directive of NIS2, bearing the burden of proof for this.

Important entities

Important entities, on the other hand, will only be audited if there is evidence, an indication or information that they are not compliant with the NIS2 directive EU. This is done after a cybersecurity breach. But even for them, it is of course mandatory and very important to comply with NIS2 legislation. These entities must be able to prove that the organisation was compliant with cybersecurity regulations at the time of the cybersecurity breach.
Company size
The NIS2 directive EU applies to medium-sized and large companies (50+ employees or an annual turnover of 10 million euros) across various sectors, including. In principle, micro and small businesses are not covered by the NIS2 directive EU. Exceptions to this rule are trust service providers, which do fall within the scope of NIS2. In addition, the minister of a particular sector can choose to require that a micro or small business comply with the NIS2 directive EU if the risk assessment shows that this is essential.

Industries and the NIS2 directive EU

The NIS2 directive EU covers all organisations also covered by the first NIS directive. In addition, a few new sectors have been added that are also included in the scope of NIS2. Below is an overview of all sectors, divided into essential and important entities.
Sectors of High Criticality (essential entities):
  • Energy: Electricity, district heating, petroleum/crude oil, natural gas, and hydrogen
  • Transport: Air, rail, road, and water transport
  • Banking: Credit institutions
  • Financial Market Infrastructure: Trading venues and central counterparties
  • Health: Hospitals, medical laboratories, pharmaceutical research, and manufacturing of medical devices
  • Drinking Water: Water supply and distribution
  • Waste Water: Wastewater collection and treatment
  • Digital Infrastructure: Cloud providers, data centers, DNS service providers, TLD registries, and telecommunications networks
  • ICT Service Management: Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs)
  • Public Administration: Central government and regional authorities
  • Space: Operators of ground-based infrastructure supporting space services
Other Critical Sectors (important entities):
  • Manufacturing
  • Postal and courier services
  • Waste management
  • Foodstuffs
  • Chemicals
  • Research
  • Digital providers

New: supplier chain also monitored

An important aspect of the NIS2 scope is the emphasis on the responsibility of organisations to also identify and address cybersecurity risks within their supplier chain. This means that businesses need to secure not only their own systems but also those of their partners and suppliers, the full chain. After all, suppliers often also have access to cybersecurity-sensitive information. The ultimate goal is to protect data and create a more resilient digital ecosystem, in which the likelihood of disruption from cyberattacks is significantly reduced.
Your suppliers or service partners may not be active in any of the listed sectors or have fewer than 50 employees, so they may not be designated as 'essential' or 'important'. However, they must still comply with the NIS2 directive EU at all times. Moreover, the EU may still label these organisations as essential or important in the future.
With this tool (in Dutch) from the Dutch government, you can quickly check whether the EU directive of NIS2 applies to your organization.
Personn on laptop, receiving NIS2 directive updates
NIS2: Stay informed
Don't miss important updates on the latest developments surrounding NIS2. Subscribe and automatically receive the latest information directly in your inbox.

What are the obligations under the NIS2 directive EU?

Why DEKRA for NIS2 directive EU?

You are responsible for working in compliance with the NIS2 scope. However, independent certification by a certification body such as DEKRA will contribute immensely to meet the NIS2 scope. We provide certificates that allow you to self-certify your compliance with NIS2. Moreover, independent testing gives a much broader insight into the level of your organisation. For example, whether you are fully compliant with the essential ISO 27001 directive.

Cybersecurity expertise

DEKRA has positioned itself as a leading expert in cybersecurity. With in-depth knowledge and extensive experience, DEKRA offers a wide range of services to support organisations in complying with the NIS2 directive EU. Here are some of the reasons why DEKRA is considered the leading authority in this field:
DEKRA offers a comprehensive range of cybersecurity services, including assessments, audits, and certifications. With regard to the NIS2 directive, these include ISO 27001, IEC 62443 and NIST Cybersecurity Framework (CSF). NIST CSF is a set of voluntary cyber guidelines, for which you do not receive certification. All these services are directly or indirectly designed to help organisations identify vulnerabilities, implement effective security measures and ensure ongoing compliance with the NIS2 scope.
Demonstrating how you comply with the NIS2 directive varies from organisation to organisation. Sometimes ISO 27001 + additional documentation is sufficient (read DEKRA's blog about ISO 27001 and NIS2). Other businesses will have to comply with parts of ISO 27000 and parts of IEC 62443 (+extra documentation). It is not compulsory to have these standards certified, but this can certainly help you demonstrate compliance with the EU directive NIS2. And the latter is mandatory. Since most sectors fall under the essential entities - and will therefore be subject to greater scrutiny in terms of the NIS2 directive since 2025 - it is very likely that you would do well to get certified on the basis of the above standards.
More information on all our cybersecurity services can be found on our cybersecurity page.
Cybersecurity solutions
DEKRA offers a broad portfolio of independent cybersecurity testing and certifications. Discover how we can support you in securing your systems.
Read more
In addition to the EU directive NIS2, DEKRA has in-depth knowledge of other important cybersecurity standards and regulations, such as IEC 62443 and ISO 27001. This expertise helps DEKRA assist organizations in integrating multiple standards and developing a comprehensive cybersecurity strategy.
Read more about the relationship between the NIS2 directive EU and IEC 62443 in DEKRA's blog on NIS2 and IEC 62443.
DEKRA has years of experience certifying organizations against various security standards. This experience allows DEKRA to conduct thorough and reliable audits, which is essential for demonstrating that you meet the NIS2 directive EU. DEKRA's certification process helps organizations not only comply with regulations but also strengthen their overall security posture.
For more information about the synergy between ISO 27001 and the NIS2 directive EU, read DEKRA's blog on ISO 27001 and NIS2.

How we support you in meeting the NIS2 directive

Complying with the NIS2 directive EU can be a challenging process, but DEKRA offers a structured approach to guide organizations through this process. Here are some steps DEKRA takes to help organizations achieve the EU directive NIS2:
  • Risk Analysis: DEKRA starts with a comprehensive risk analysis and gap analysis to evaluate the current situation. This includes identifying potential weaknesses and assessing the effectiveness of existing security measures.
  • Implementation of Security Measures: Based on the findings from the analyses, DEKRA assists organizations in implementing the necessary security measures. This can range from policy adjustments to staff training.
  • Continuous Monitoring and Evaluation: The NIS2 directive EU requires continuous monitoring and evaluation of security measures. DEKRA offers services for regular audits and assessments to ensure organizations remain compliant with the directive and can quickly respond to new threats.
  • Incident Response and Recovery: In the event of a security incident, a quick and effective response is crucial. DEKRA helps organizations develop and evaluate incident response plans and recovery strategies to minimize the impact of incidents and resume operations quickly.

Let's get in touch about NIS2 and cybersecurity

DEKRA provides a comprehensive range of testing and certification services in the field of cybersecurity. Our experts would be happy to get in touch with you to ensure that you stay ahead of the curve regarding cybersecurity, regulatory requirements, and new standards.

Frequently asked questions about the NIS2 Directive

Large and medium-sized organizations in critical and regulated sectors, as well as public authorities, must comply. Indirectly, companies that are part of a NIS2-relevant supply chain are also affected.
NIS2 mainly applies to public and private entities in Annex I and Annex II sectors that are at least medium-sized, normally 50 or more employees and annual turnover and/or a balance-sheet total above €10 million; certain entity types are in scope regardless of size. Suppliers are not automatically subject to NIS2 solely because of a customer relationship, but in-scope entities must manage supply-chain risk and may impose security requirements by contract.
Classification depends on the entity type; sector and size, not simply on whether a sector is “essential.” Essential entities include qualifying Annex I entities and certain named types regardless of size; other in-scope entities are important entities.
Essential entities face proactive supervision, while important entities are generally supervised after evidence of non-compliance. National implementing law should be checked for the final classification.
Entities must implement proportionate cybersecurity risk-management measures, including risk analysis, incident handling, business continuity, supply-chain security, secure system development and maintenance, effectiveness testing, training, access control and, where appropriate, encryption and multi-factor authentication. Management bodies must approve and oversee these measures and undertake cybersecurity training.
Significant incidents must be reported in stages: an early warning within 24 hours, incident notification within 72 hours and a final report generally within one month.
NIS2 stipulates that Member States must be able to impose substantial sanctions.
  • For essential entities, maximum fines of at least €10 million or 2% of global annual turnover may apply, whichever amount is higher.
  • For major entities, the amount is at least €7 million or 1.4% of global annual turnover.
In addition, supervisory authorities may, for example, issue binding instructions, order audits, or require organizations to remedy deficiencies.
Directors also have responsibilities regarding cybersecurity. The precise sanctions and rules regarding liability depend on national legislation.
The European NIS2 Directive entered into force on 16 January 2023. EU Member States were subsequently required to transpose the directive into national legislation.
In the Netherlands, NIS2 was implemented via the Cybersecurity Act (Cbw). This Act entered into force on 15 August 2026. Organizations subject to the Cybersecurity Act must comply with statutory obligations from that date.
Yes, in certain cases. NIS2 can also apply to specific service providers established outside the EU but offering services within the European Union. Examples include certain providers of DNS services, cloud computing, data centers, content delivery networks, managed services, online marketplaces, search engines, and social networks.
In some cases, an organization outside the EU must appoint a representative within the European Union.
A supplier outside the EU does not automatically fall under NIS2 simply because it supplies a European customer. However, a customer subject to NIS2 may include cybersecurity requirements in contracts with suppliers due to obligations regarding supply chain security.
The GDPR focuses on the processing and protection of personal data. NIS2 focuses on cybersecurity, risk management, and the digital resilience of organizations.
In the event of a cyber incident, both regulations may apply simultaneously. However, the conditions for reporting an incident, the time limits, and the supervisory authorities involved differ.
Therefore, a report under NIS2 does not automatically replace any potential report under the GDPR. Conversely, compliance with the GDPR does not automatically mean that an organization complies with NIS2.
Yes. The European Commission must evaluate NIS2 by 17 October 2027 at the latest and subsequently reassess it at least every 36 months.
In addition, supplementary European and national rules and guidelines may be adopted. Organizations would therefore do well to continue monitoring developments within European and Dutch legislation, instructions from supervisors, and sector-specific requirements.
Yes. DEKRA offers cybersecurity services worldwide, including assessments, testing, training, and services aimed at compliance.
For internationally operating organizations, DEKRA can, for example, assess which cybersecurity requirements under NIS2 are relevant and how they relate to local legislation and sector-specific requirements.
NIS2 directive blogs