NIS2 Directive: what is it, who does it apply to, and what do you need to arrange?

As of August 15, 2026, the Cyber Security Act has been in effect in the Netherlands: the national implementation of the European NIS2 Directive. This introduces new legal cybersecurity obligations for an estimated 8,000 Dutch organizations. Despite this, many organizations remain unclear about what the NIS2 Directive entails, whether it applies to them, and what is specifically expected of them. In this article, we explain the NIS2 legislation step by step: what it is, who it applies to, what the associated obligations are, and how choosing a sovereign cloud in Dutch data centers contributes to your NIS2 compliance.

‍

Written by
Iris Nicolaas
&
Posted on
01
-
10
-
2026
2024
Written by
Iris Nicolaas
&
Posted on
01
-
10
-
2026
2024

What is the NIS2 Directive?

NIS2 stands for the European Union's second Network and Information Security Directive. The goal of the directive is to increase the collective level of cybersecurity within the EU by requiring organizations in vital and important sectors to demonstrably maintain their digital resilience. NIS2 is the successor to the original 2016 NIS Directive and is significantly broader: it covers more sectors, has stricter requirements, and provides for more robust oversight.

In the Netherlands, the directive has been transposed into national law via the Cyber Security Act, which replaces the previous Security of Network and Information Systems Act (Wbni). Following the final phase of parliamentary review, this act entered into force on August 15, 2026. From that date, the duty of care and the reporting obligation apply directly to all organizations covered by the law.

It is important to realize that NIS2 is not optional advice or a certification label, but legally binding regulation with severe penalties for non-compliance. As such, the directive affects not only the IT department but also the management and board of an organization.

Who does the NIS2 Directive apply to?

NIS2 focuses on organizations active in sectors considered vital or socially important. The directive distinguishes between two types of organizations:

•   Essential entities – active in sectors such as energy, drinking water, digital infrastructure, transport, banking, financial market infrastructure, healthcare, public administration, and space.

•   Important entities – active in sectors such as digital providers, postal and courier services, waste management, food, chemicals, research, and manufacturing.

Whether an organization actually falls under the law depends on its size as well as its sector. As a rule of thumb:

•   Medium-sized organizations: 50 or more employees, or an annual turnover or balance sheet total exceeding 10 million euros.

•   Large organizations: more than 250 employees, or a turnover exceeding 50 million euros combined with a balance sheet total exceeding 43 million euros.

•   Small and micro-organizations generally fall outside the scope, with the exception of specific providers such as trust service providers, domain name registry services, and providers of electronic communications networks, which are always covered by the law regardless of their size.

Organizations not active in a designated sector may also be indirectly affected by NIS2. Essential and important entities are required to manage risks in their supply chain and will translate this into requirements for their IT and cloud suppliers.

NIS2 in healthcare

The healthcare sector has been explicitly designated as an essential sector under NIS2. This is no coincidence: healthcare institutions work with data that is not only privacy-sensitive but also directly critical to patient care, and any disruption to healthcare ICT can have immediate consequences for the continuity of care. For hospitals, mental healthcare institutions, health insurers, and other healthcare providers that meet the size criteria, this means that NIS2 compliance goes hand-in-hand with existing obligations regarding the GDPR and the European Health Data Space (EHDS) initiative. In practice, we see that healthcare organizations often combine their NIS2 journey with the NEN 7510 standard, which we explain later in this article. You can read more about how we support healthcare organizations with a sovereign, compliant cloud environment on our Cloud for healthcare page.

‍

What do you need to arrange? The most important NIS2 obligations

When your organization falls under the NIS2 directive, it brings a number of concrete obligations. Here are the most important NIS2 obligations:

•   Registratieplicht. Organisaties die onder de wet vallen, moeten zich registreren in het entiteitenregister bij het Nationaal Cyber Security Centrum, via mijn.ncsc.nl. Deze registratie is de basis waarop toezicht en communicatie vanuit de overheid plaatsvindt.

• Duty of care. You are required to conduct a risk analysis of your network and information systems and, based on that, take appropriate technical, operational, and organizational measures. Think of access security, encryption, backup and recovery policies, vulnerability management, and supply chain security.

• Reporting obligation. For significant incidents, a strict timeline applies: within 24 hours of becoming aware of the incident, you must submit an initial, early warning to the CSIRT and the supervisory authority. A more detailed report, including the nature and severity of the incident, must follow within 72 hours. No later than one month after the full report, you must provide a final report with an analysis of the cause, the measures taken, and the impact.

• Management responsibility. The management or board must approve the cybersecurity measures taken, actively monitor risk management, and can be held personally liable for this. Executives must also undergo training to be able to assess risks.

• Supply chain risk management. You are required to identify and manage risks associated with suppliers and service providers, including the security of the cloud and hosting parties you work with.

• Enforcement and fines. In the event of non-compliance, the supervisory authority can take enforcement action, with fines that can reach up to 10 million euros or 2% of the total global annual turnover for essential entities, and up to 7 million euros or 1.4% of the total global annual turnover for important entities, in addition to any periodic penalty payments.

In short: NIS2 compliance is not a one-time checkbox, but an ongoing process of risk management, documentation, and accountability.

‍

NIS2 compliance and cloud sovereignty

A large part of the duty of care under NIS2 revolves around the question: where are your data and systems located, who has access to them, and how well is that secured? This makes the choice of your cloud infrastructure directly relevant to your NIS2 compliance.

When business-critical or personal data is hosted by parties outside the EU, or by providers subject to foreign legislation such as the US Cloud Act, a risk arises that is difficult to manage within your own risk analysis. A sovereign cloud, fully hosted in Dutch data centers and under Dutch law, significantly limits this risk: data remains within the Dutch jurisdiction, under your own control over people, processes, and technology.

With its sovereign cloud, Fundaments offers an infrastructure that is fully hosted in the Netherlands, distributed across data centers in the East, Central, and West of the Netherlands, and where data is demonstrably subject to Dutch laws and regulations. This makes it a logical building block for organizations that want to fulfill their NIS2 duty of care without compromising on control over their data. You can find more information about this on our page about the Fundaments sovereign cloud.

Demonstrating that you are in control: certifications

Under NIS2, it is not enough to say that you "have things well organized"; you must be able to demonstrate it. Independent certifications are an important tool for this, both for supervisory authorities and for your own customers and supply chain partners. When choosing a cloud partner, it is therefore wise to look for the following certifications:

•   ISO 27001. The international standard for information security. An ISO 27001 certification demonstrates that an organization has implemented a structured Information Security Management System (ISMS), including risk assessment, policy, and continuous improvement. This is directly relevant to the duty of care under NIS2.

•   NEN 7510. The Dutch standard for information security in healthcare, based on ISO 27001 and 27002 but supplemented with sector-specific requirements. For healthcare organizations falling under NIS2, a NEN 7510-certified cloud provider is often a prerequisite for being able to demonstrate their own compliance.

•   ISAE 3402. An international assurance standard through which a service provider, via an independent auditor, demonstrates that internal control measures regarding continuity, change management, and access security are effectively in place (Type II report). For organizations that must manage supply chain risks under NIS2, an ISAE 3402 statement from their cloud provider serves as concrete evidence for their own auditor or regulator.

Fundaments holds these certifications for its infrastructure and organization, allowing customers to use them directly in their own NIS2 documentation.

How Fundaments helps you with NIS2 compliance

Whether you operate in healthcare, government, or another sector covered by the NIS2 directive, the foundation of your compliance begins with a cloud environment where you know where your data is stored, who has access to it, and how continuity is guaranteed. Fundaments provides that foundation with a fully Dutch, sovereign cloud infrastructure, supported by recognized certifications and personal guidance. Curious about what this means for your sector? View our page for the public sector or contact our experts for a no-obligation discussion on how to make your organization NIS2-proof.

This article is based on the most recent information regarding the Cybersecurity Act and the NIS2 directive at the time of publication. Because laws and regulations are subject to change, we recommend consulting the NCSC website for the latest updates.

No items found.
No items found.
No items found.