Skip to main content

Compliance Guide

NIS2 & Cyberbeveiligingswet — Readiness Guide

The NIS2 Directive is the EU's most significant cybersecurity legislation. It covers 18 sectors, introduces personal board liability, and mandates incident reporting within 24 hours. The Netherlands transposed it as the Cyberbeveiligingswet. UK businesses serving EU clients must comply.

By Ben Gray · 10 April 2026 · 18 min read

Who Is in Scope?

NIS2 applies to essential and important entities across 18 sectors. The size threshold is 50+ employees OR €10M+ annual turnover.

Essential EntitiesImportant Entities
Energy (electricity, oil, gas, hydrogen)Postal and courier services
Transport (air, rail, water, road)Waste management
Banking and financial market infrastructureChemical manufacturing
Healthcare (hospitals, labs, pharma)Food production and distribution
Drinking water and wastewaterManufacturing (medical, electronics, machinery)
Digital infrastructure (DNS, TLD, cloud, data centres)Digital providers (marketplaces, search, social)
ICT service management (MSPs, MSSPs)Research organisations
Public administration 
Space 

IT service providers are in scope

If you provide managed IT services, cloud hosting, security services, or software to any entity in the 18 sectors, you are classified as an ICT service management provider — an essential entity under NIS2. This directly affects Genitco and similar IT consultancies.

The 10 Minimum Measures (Article 21)

NIS2 Article 21 mandates 10 cybersecurity risk management measures. These are not optional.

  1. Risk analysis and information security policies — Documented ISMS, regular risk assessments, board-approved security policy
  2. Incident handling — Detection, response, recovery procedures. Tested regularly.
  3. Business continuity and crisis management — BCP, DR plans, backup management, tested recovery
  4. Supply chain security — Assess supplier cybersecurity, contractual requirements, right to audit
  5. Security in network and information systems — Acquisition, development, maintenance with security by design
  6. Policies for assessing effectiveness — Regular vulnerability assessments, penetration testing, audit
  7. Cybersecurity hygiene and training — Awareness programmes for all staff, board-level training (mandatory)
  8. Cryptography and encryption policies — Documented use of cryptography, key management
  9. Human resources security — Background checks, access control tied to employment lifecycle
  10. Multi-factor authentication and secure communications — MFA for all privileged access, encrypted voice/video/text

Board Liability (Article 20)

NIS2 Article 20 requires management bodies to:

  • Approve cybersecurity risk management measures
  • Oversee their implementation
  • Complete cybersecurity training (and ensure staff do too)
  • Be held personally liable for non-compliance

Article 32 allows Member States to impose temporary management bans on individuals found responsible for breaches. This is not a corporate fine — it is personal liability for named directors.

Incident Reporting

DeadlineRequirementTo Whom
24 hoursEarly warning — is this a significant incident?CSIRT / competent authority
72 hoursIncident notification — initial assessment, severity, impact, IoCsCSIRT / competent authority
1 monthFinal report — root cause, remediation, cross-border impactCSIRT / competent authority

Penalties

Entity TypeMaximum FineAdditional
Essential€10M or 2% global turnover (whichever higher)Temporary management bans possible
Important€7M or 1.4% global turnover (whichever higher)Compliance orders, binding instructions

Readiness Checklist

  • Determine if your organisation is essential or important under NIS2
  • Confirm board awareness and schedule cybersecurity training
  • Review and update your information security policy (board approval required)
  • Conduct a risk assessment against the 10 minimum measures
  • Assess supply chain cybersecurity (all ICT service providers)
  • Implement or verify MFA for all privileged access
  • Test incident response procedures (tabletop exercise)
  • Verify 24h/72h/1m reporting capability
  • Test business continuity and disaster recovery plans
  • Document encryption policies and key management procedures
  • Register with national competent authority if required

Need help with NIS2 readiness?

We help organisations implement the 10 minimum measures, prepare for board reporting, and build incident response capability. Sovereign infrastructure, zero CLOUD Act exposure.

Global infrastructure·Your data, never ours·AI and infrastructure you control·GDPR by design