Skip to content
    All guides
    Guides

    NIS2 Directive Security Requirements: What Organisations Need to Know and Do

    The NIS2 Directive (Network and Information Security Directive 2) significantly expands the scope of mandatory cybersecurity and physical security obligations for organisations operating in the EU. Dutch organisations in critical and important sectors — including logistics, energy, finance, healthcare, and digital infrastructure — must implement risk management measures, report major incidents within 24–72 hours, and ensure supply chain security. Non-compliance carries administrative fines up to €10 million or 2% of global turnover.

    Looking for a certified security provider? View our Cyber Defence & Threat Exposure service →

    Which Organisations Fall Under NIS2?

    NIS2 distinguishes between 'essential entities' (formerly 'operators of essential services') and 'important entities' — a new category bringing many mid-sized organisations into scope for the first time. Essential entities include energy providers, transport and logistics operators, water utilities, financial market infrastructure, healthcare institutions, digital infrastructure providers, and certain public administration bodies. Important entities include postal and courier services, waste management, chemicals manufacturers, food processors, digital service providers, and manufacturing companies above defined size thresholds.

    Dutch organisations in the logistics sector — Rotterdam port operators, distribution centre operators, freight forwarders — are directly in scope. So are companies providing digital services across borders, technology companies with EU infrastructure, and organisations in the supply chains of essential entities (through the supply chain security requirements). If your sector is listed and you employ 50+ people or have annual turnover above €10M, assume you are in scope and verify with legal counsel.

    Core Security Obligations Under NIS2

    NIS2 mandates a risk-based approach rather than prescriptive controls. However, Article 21 specifies the minimum measures organisations must have in place: policies for risk analysis and information system security; incident handling procedures; business continuity and crisis management (backup management, disaster recovery, BCDR planning); supply chain security covering relationships with direct suppliers and service providers; security in network and information systems acquisition, development, and maintenance; policies and procedures to assess the effectiveness of cybersecurity risk management measures; basic cyber hygiene practices and cybersecurity training; policies and procedures regarding the use of cryptography; human resources security, access control policies, and asset management; use of multi-factor authentication or continuous authentication.

    Critically for many organisations: NIS2 does not limit 'security' to cyber. Physical access controls, personnel security, and environmental security fall explicitly within its risk management requirements. An organisation with robust cyber posture but weak physical security — uncontrolled server room access, no vetting of cleaning or maintenance contractors — is non-compliant.

    The NIS2 Incident Reporting Obligation (Meldplicht)

    NIS2's incident reporting regime — the meldplicht — is stricter and faster than its predecessor. Organisations must notify the competent authority (in the Netherlands: the NCSC for essential entities, sector-specific regulators for important entities) within 24 hours of becoming aware of a significant incident (an 'early warning'). A fuller notification follows within 72 hours. A final report, including root cause analysis and the measures taken, is due within one month.

    A 'significant incident' is one that causes or may cause severe operational disruption to services, financial loss to the entity, or significant damage to other persons. This threshold is broad enough to capture most ransomware attacks, major data breaches, sustained DDoS campaigns affecting service availability, and physical intrusions that compromise information systems. The reporting obligation applies regardless of whether the incident originated from a cyber or physical attack.

    Physical Security and NIS2: Where Mission Support Fits

    NIS2's physical security requirements are often the least-prepared element for organisations focused primarily on cyber. The Directive requires that access to premises, facilities, and information systems is controlled and that physical threats — theft, sabotage, natural hazards — are addressed in the risk management framework. For Dutch logistics operators, energy infrastructure, and financial institutions, this means: access control systems for server rooms, data halls, and network infrastructure rooms; vetting of maintenance and cleaning contractors with physical access to sensitive areas; TSCM sweeps to rule out planted surveillance devices in board and executive spaces; security driver and close protection measures for executives whose compromise would constitute an organisational risk.

    Mission Support provides the physical and operational security layer that completes a NIS2-compliant security programme: personnel screening, access control advisory, TSCM sweeps, and 24/7 response capability. Speak with a Mission Support specialist to scope the physical security elements of your NIS2 compliance plan.

    Frequently asked

    What is the NIS2 deadline for Dutch organisations?

    The NIS2 Directive entered into force in January 2023 with a transposition deadline of 17 October 2024. The Netherlands transposed NIS2 into national law via the Cyberbeveiligingswet. Organisations in scope are expected to comply now — there is no grace period for essential or important entities.

    Does NIS2 apply to logistics companies in the Netherlands?

    Yes. Transport and logistics — including road transport, rail transport, inland waterway transport, maritime transport, and air transport — are listed as essential sectors under NIS2. Rotterdam port operators, freight forwarders, and distribution operators above the size thresholds are directly in scope. Nis2 logistiek compliance requires both cyber and physical security measures.

    What are the fines for NIS2 non-compliance?

    Essential entities face maximum fines of €10 million or 2% of total global annual turnover (whichever is higher). Important entities face maximum fines of €7 million or 1.4% of total global annual turnover. Supervisory authorities can also require remediation measures, suspend management, and issue public notices of non-compliance.

    How does physical security fit into NIS2 compliance?

    NIS2 Article 21 explicitly requires that organisations address physical and environmental security as part of their cybersecurity risk management measures. This includes controlling physical access to premises housing information systems, vetting personnel with physical access to sensitive areas, and protecting against physical threats to infrastructure. TSCM sweeps, access control, and personnel screening all directly address NIS2 physical security requirements.

    Talk to a specialist about this service

    We will respond within one business day. Initial conversations are confidential and without obligation.