NIS2 is the second European Directive on the security of network and information systems. Its full name is the Network and Information Security Directive 2.
It raises cybersecurity requirements for organisations that are important to society and the economy, including organisations in healthcare, energy, transport, digital infrastructure, public administration, drinking water, manufacturing and parts of the food chain.
“The practical meaning of NIS2 is that directors understand which digital risks can disrupt continuity, which choices have been made and where uncertainty remains.”
Wouter Parent
What does NIS2 mean in the Netherlands?
NIS2 is an EU Directive. The Netherlands has implemented it through the Dutch Cybersecurity Act and the Cybersecurity Decree. The Act entered into force on 15 August 2026.
For Dutch organisations, compliance therefore follows the national Act, the Decree and any relevant sector rules. Our guide to NIS2 legislation in the Netherlands explains the distinction between these legal layers.
Who does NIS2 apply to?
The rules cover medium-sized and large organisations in designated sectors, alongside specific entity types and exceptions. Size alone is not enough to determine scope.
Use When is NIS2 mandatory? for the assessment route: statutory sector, entity type, size, exceptions and possible designation.
Which obligations come with NIS2?
- registration: entities within scope register in the national entity register;
- duty of care: risks are assessed and appropriate, proportionate measures are implemented;
- incident reporting: significant incidents are reported within statutory timelines;
- board responsibility: directors approve measures, oversee implementation and maintain sufficient knowledge.
The framework also covers suppliers, business continuity, incident response, access control, cryptography, vulnerability handling and supply-chain security.
What does NIS2 mean for boards?
Directors do not need to become technical specialists. They do need to understand the organisation's critical digital dependencies, assess whether measures are proportionate and make traceable decisions about priorities and residual risk.
- Which services and processes are digitally critical?
- Which scenarios could cause serious disruption?
- Which residual risks have been accepted, and by whom?
- How do we know that measures work in practice?
- Which suppliers create a critical dependency?
- Can the organisation identify, escalate and report an incident in time?
NIS2, the Cybersecurity Act and ISO 27001
NIS2 sets legal objectives and obligations. ISO 27001 provides a management system for organising information security. Certification can offer a strong foundation, but it does not by itself demonstrate compliance with every requirement of the Dutch Cybersecurity Act.
Frequently asked questions
What does NIS2 stand for?
NIS2 is the second European Directive on the security of network and information systems.
Is NIS2 a Dutch law?
NIS2 is an EU Directive. In the Netherlands it is implemented through the Dutch Cybersecurity Act and Cybersecurity Decree.
What does NIS2 mean for directors?
Directors approve duty-of-care measures, oversee implementation and need sufficient knowledge to assess cyber risks and measures.
Does NIS2 also affect suppliers?
Some suppliers fall directly within the law. Others receive security, evidence and continuity requirements through customers and contracts.
Translate NIS2 into board-level decisions
Read the Dutch Cybersecurity Act guide, compare NIS2 boardroom training or use the NIS2 Quick Scan guide for a first assessment.