8 April 2023 • NIS2
The European NIS2 Directive replaces NIS1, the EU’s first cybersecurity directive from 2016. Member states had until October 17, 2024 to transpose the new rules into national law. In the Netherlands, NIS2 is implemented through the Cyberbeveiligingswet, which was adopted in July 2026 and enters into force on August 15, 2026. What exactly has changed? We list the differences between NIS1 and NIS2 for you.
NIS1 only applied to essential businesses in a handful of sectors. Under NIS2, the rules also cover “important” companies: thousands of medium-sized and large organizations that fall under European cybersecurity legislation for the first time.
What is the NIS2 guideline?
NIS2 is the successor to NIS1, which was introduced years back for essential businesses. The new NIS2 directive (officially: Directive (EU) 2022/2555)) was published by ENISA, the European Union Agency for Cybersecurity. The directive prescribes minimum security requirements, as well as the obligation to report (serious) incidents to the national authority or the European Computer Security Incident Response Team (CSIRT). The new directive replaces the original one, which came into force in 2016.
Does NIS2 replace NIS1?
Yes. NIS2 fully replaces NIS1. When NIS2 became applicable in October 2024, the original NIS directive from 2016 was repealed. Everything that fell under NIS1 now falls under NIS2, together with many new sectors and stricter requirements.
These are the main differences between the NIS1 and NIS2:
- Directive applies to more sectors
The NIS2 applies to essential companies as well as major companies. More medium-sized and large companies must start complying with the directive. In addition, the Dutch government may designate smaller companies with a high security risk that must also begin to comply. - List of minimum basic security
The directive is more concrete, thanks to a list of minimum basic security that companies must implement. The directive imposes a risk management approach. - Division into essential and key sectors
The new NIS directive divides companies into essential and key sectors. The distinction between operators of essential services and providers of digital services disappears. - Address security in the chain
Companies must start addressing security risks in their supply chain. That includes risks created by supplier relationships. - Stricter supervision
National authorities are allowed stricter supervision and enforcement. The new directive pulls penalty regimes and reporting requirements in all member states equal(er).
What are essential businesses?
The NIS directive applies to essential businesses. These sectors are:
- Energy
- Drinking water
- Wastewater
- Transportation
- Banking
- Financial Markets
- Digital infrastructure
- Public Administrations
- Health care
- Space
Tip: Wondering exactly which companies are “essential” or “important”? Download the table Sectors covered by NIB2 from CBS.
The new NIS2 directive will also apply to major companies. These sectors are:
- Postal and courier services
- Processing and distribution
- Waste processing
- Digital providers
- Manufacturing companies
- Chemical industry
- Food industry
Difference in supervision between essential and important companies
Local authorities will proactively monitor key businesses. Supervision of key businesses will take place after the fact, if there is evidence of an incident.
Key and essential companies will have a duty to report and a duty of care. They have to put security in place in their supply chain and communicate clearly how they handle cyber incidents.
Why is the new guideline important?
The new NIS2 directive should make network and information systems at companies more secure. In this way, the Netherlands and the entire European Union should become less vulnerable to cyber attacks.
Minister Dilan Yeşilgöz-Zegerius (Justice and Security) said, “We are increasingly dependent on digital processes, especially since corona we are working more and more from home. In addition, we see a growing digital threat from both criminals and state actors that, with a war on Europe’s eastern border, is not going to abate for the time being. It is therefore now necessary to take the next step to raise the level of cybersecurity in the EU. In doing so, we will prevent digital incidents from disrupting our society.”
Minister Micky Adriaansens (Economic Affairs and Climate) adds: “We must be alert to the risks of cyber attacks. The impact can be significant, such as empty shelves in stores or industrial production outages. Managing digital security remains an individual responsibility of companies and consumers. But with this legislation we can take a step to ensure that the level of cyber security goes up among (medium) sized parties in more important sectors.”
Is your organization ready for NIS2?
NIS2 requires cyber security training for your employees and your board. Guardey makes it easy with gamified security awareness training that takes just a few minutes per week.
Start your free 14-day trialWill you be fined if you fail to comply?
Companies that fail to comply with the new directive will receive a warning, then a reminder and then risk a large fine. For essential companies, the maximum fine is 10 million euros or 2 percent of the worldwide annual turnover, whichever is higher. For important companies, the maximum is 7 million euros or 1.4 percent. New in NIS2: management can also be held personally liable for non-compliance.
NIS2 implementation per EU country (2026)
NIS2 is a European directive, so every member state has to turn it into national law. Not every country moves at the same speed. This is where the main markets stand in 2026:
- Belgium: one of the first to transpose. The Belgian NIS2 law has applied since October 18, 2024, supervised by the Centre for Cybersecurity Belgium (CCB).
- Italy: transposed early through Legislative Decree 138/2024, in force since October 2024. The national cybersecurity agency ACN supervises registration and compliance.
- Germany: the NIS2UmsuCG entered into force on December 6, 2025. Around 29,500 companies fall under the law and had to register with the BSI.
- Poland: the amended National Cybersecurity System Act (KSC) entered into force on April 3, 2026 and covers roughly 42,000 companies, with a registration deadline in October 2026.
- The Netherlands: the Cyberbeveiligingswet was adopted in July 2026 and enters into force on August 15, 2026, without a transition period.
- France: still in the legislative process. The Loi Résilience is expected to pass in 2026, but ANSSI already encourages organizations to register and prepare.
- Spain: the draft law on cybersecurity coordination and governance is still going through parliament, so the directive is not yet fully transposed.
The takeaway: no matter where you are in the EU, the training and risk management obligations of NIS2 either already apply to you or will very soon.
NIS2 vs ISO 27001: what is the difference?
NIS2 is legislation, while ISO 27001 is a voluntary international standard for information security. An ISO 27001 certificate is not legally required and does not automatically make you NIS2 compliant. There is plenty of overlap though: organizations that follow ISO 27001 already cover a large part of what NIS2 asks for, such as risk management, incident procedures and security awareness training.
Preventing damage from cybercrime: what can you do?
Even without a cyber law like NIS2, it is important to take cybercrime seriously. You protect your business with, for example:
- Security by design
Start every meeting with (digital) security. What measures do you take to prevent abuse and what are the risks and vulnerabilities? By thinking about this as standard, you set up (new) systems more secure by default. - Secure connection
Use a secure connection for your company. Prevent others from unwanted viewing or even stealing data. The secure connection is available worldwide, at any time from any location. - Train employees in cybersecurity
Those who do not know what the risks are cannot possibly protect themselves against them. Train employees and make sure they recognize vulnerabilities and don’t fall into traps when cybercriminals set them up.
How EyeOn uses Guardey to comply with NIS2
Companies that need to comply with NIS2 are required to offer security awareness training to their employees. This obligation explicitly includes the board: under article 20 of the directive, management must follow cyber security training too.

Our customer Gezamenlijke Brandweer Amsterdam (a Dutch fire department) is an essential organization and therefor needs to adhere to the NIS2 regulation. To ensure their employees are prepared to recognize cyber threats, they use Guardey to offer security awareness training. Every week, their team plays a short 3-hour challenge that helps them to slowly build up cyber security knowledge.
Make it easy with Guardey
We understand at Guardey that you may have a lot on your mind. How do you comply with NIS2, what are the vulnerabilities at your company and how do you prevent a hack, data breach or other cybercrime?
That’s why we like to make it easy for you. With Guardey, you choose a complete cyber security solution all at once. We are plug & play, for both a secure connection, against malicious software and to train your employees professionally (but fun!).
So do you want to improve your company’s cyber security and comply with the new NIS2 directive? Discover our solution or ask us your questions. We’ll be happy to explain how you can be protected with Guardey in a very accessible, simple and affordable way.
Want to dive deeper into NIS2?
Our NIS2 guide explains the requirements step by step: who falls under the directive, what you need to arrange and how to get your team ready.
Read the NIS2 guide