NIS2 & Cybersecurity Act

    NIS2 asks for evidence, not a plan

    NIS2 asks the same thing across Europe: proof that your security measures actually work, not just a policy that says they should.

    We deliver that technical proof. A manual pentest, retest included, and an audit-ready report your regulator or your largest client can use directly. Whichever country you operate in and whichever framework applies.

    NIS2 Directive Overview
    ScopeEU-WIDE
    18
    Sectors
    €10M
    Max Fine
    Applies to essential and important entities across critical infrastructure sectors

    Key NIS2 Requirements

    Risk Management

    Implement clear and structured measures to identify, assess, and manage cyber risks across your organisation.

    Incident Reporting

    Report significant security incidents to the relevant authorities within the required 24 to 72-hour timeframe.

    Supply Chain Security

    Identify and manage cybersecurity risks introduced by suppliers, service providers, and partners.

    Continuous Monitoring

    Continuously monitor systems and environments to detect threats and suspicious activity in a timely manner.

    Access Control

    Enforce strong authentication and manage user accounts, roles, and access rights properly.

    Documentation

    Maintain clear policies, procedures, and evidence to demonstrate compliance and support audits.

    How We Help

    NIS2 gap analysis and readiness assessment
    Security policy development and documentation
    Technical controls implementation
    Incident response planning
    Supply chain risk assessment
    Management reporting and board presentations
    Complete
    NIS2 compliance program
    4-12
    Weeks to readiness
    100%
    Audit support

    Frequently Asked Questions

    NIS2 applies to essential and important entities across 18 sectors operating in the EU. Essential entities include operators in energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space. Important entities include postal services, waste management, manufacturing of critical products, food, chemicals, and digital services. Size thresholds also apply: medium-sized companies (50 or more employees or over €10M turnover) in covered sectors generally fall in scope. We can confirm applicability by reviewing your sector, size, and role in the supply chain.

    NIS2 Article 34 sets a two-tier fine structure. Essential entities face fines up to €10 million or 2% of global annual turnover, whichever is higher. Important entities face fines up to €7 million or 1.4% of global annual turnover, whichever is higher. In addition to financial penalties, supervisory authorities can order binding instructions, temporary management bans, and require organizations to notify affected parties.

    NIS2 Article 23 requires a three-stage process. Within 24 hours of awareness: an early warning to your national CSIRT or competent authority confirming the incident and whether a cyberattack is suspected. Within 72 hours: a formal incident notification with severity assessment, affected systems, and estimated impact. Within one month: a final report including root cause, measures taken, and any cross-border implications. We help you build the processes and documentation structures to meet all three deadlines.

    Yes. NIS2 Article 20 holds management bodies directly accountable for cybersecurity compliance. Board members must approve the organization's cybersecurity risk management measures and actively oversee their implementation. In cases of serious violations, national authorities can temporarily prohibit specific individuals from exercising management functions. This makes NIS2 compliance a board-level obligation, not only an IT responsibility.

    In Belgium, the Centre for Cybersecurity Belgium (CCB) is the national competent authority for most sectors under NIS2. In the Netherlands, the NCSC (Nationaal Cyber Security Centrum) coordinates national oversight, but sector-specific supervisors also have authority: for example, DNB for financial institutions and the RDI for digital infrastructure. We track which authority applies to your specific sector and help you align your compliance documentation accordingly.

    For most organizations, a first NIS2 readiness trajectory takes between 4 and 12 weeks, depending on your current security maturity, the scope of your organization, and the complexity of your supply chain. This covers gap analysis, policy development, technical controls implementation, and incident response planning. Organizations that already have ISO 27001 or an equivalent framework in place typically move faster because foundational documentation exists.

    NIS2 article 21 requires proportional, documented testing of the effectiveness of security measures, but does not specify a fixed frequency or method. Continuous testing platforms are one valid approach, periodic pentesting is another, and many organisations combine both. What matters to a NIS2 auditor is documented evidence of effectiveness with named accountability, not the technology you used. A signed pentest report from an independent tester is widely accepted; an automated dashboard alone usually is not.

    Turn NIS2 pressure into audit-ready proof

    A manual pentest with a report and free retest you can put straight into your NIS2 file.