What does NIS2 mean for your organization?

NIS2 might sound like a technical cybersecurity story, but it’s first and foremost a legal obligation. The European directive determines whether, how, and to which concrete obligations around cyber risk management, incident reporting, and board-level duty of care your organization must comply.

Find everything you need to know about NIS2 from a legal perspective, right here.

What is
NIS2?

NIS2 is the European cybersecurity law that replaces the NIS Directive from 2016.

The original directive only applied to critical sectors, such as energy, water, …. It soon became clear that this wasn’t enough, and with larger incidents and attacks, the law needed to be revised. As a result, NIS2 now applies to a much broader group of organizations than before, with extra focus on the security of the supply chain and authentication mechanisms.

What does this law concretely involve? Essentially three things:

  1. managing cyber risks through concrete measures,
  2. reporting incidents within strict deadlines,
  3. and an active duty of care for your board in this area.

Find out below whether your organization belongs to that broader group.

Does NIS2 apply to your organization?

NIS2 applies to a wide range of sectors. Your organization may fall under the law if you are active in:

  • Energy
  • Transport
  • Banking
  • Financial market infrastructure
  • Healthcare
  • Drinking water and wastewater
  • Digital infrastructure (cloud, data centers, DNS services, telecom)
  • Management of ICT services (e.g. managed service providers)
  • Public administration
  • Space
  • Postal and courier services
  • Waste management
  • Chemicals
  • Food production
  • Certain manufacturing industries (such as medical devices, electronics, or machinery)
  • Digital platforms (online marketplaces, search engines, social networks)
  • Research institutions
Show all Show less

 

 

In addition to your sector, the size of your organization also plays a role. Small and micro-enterprises generally fall outside NIS2, unless they fulfill a critical role.

And if you’re not active in any of these sectors yourself, but you supply to an organization that is? That client may contractually require you to meet certain security standards, since they themselves are obligated to secure their supply chain.

When determining whether you fall under NIS2, three things are often overlooked:

  1. Parent and subsidiary companies: their figures count when calculating the size of your organization.
  2. Applicable law: even when it’s clear you’re in scope, that doesn’t yet tell you which country’s NIS2 law applies. That’s determined by the location of your main establishment.
  3. Chain responsibility: if you fall under NIS2 yourself, you’re also responsible for the security of your suppliers, with consequences for existing contracts and cooperation agreements.

Our legal expert Bernd explains this for you in the video below:

Lisa Botteldoorn

Not sure whether your organization needs to comply with NIS2?

Our legal experts can guide you.

When is the next deadline?

A brief timeline:

  • 18 October 2024: NIS2 took effect in Belgium, with obligations applying since then.
  • 18 April 2026: essential entities were required to complete a first conformity assessment.
  • 18 April 2027: essential entities must advance to the next level: from an initial, limited verification to full certification.

Want to know whether your organization is subject to NIS2 and what your legal obligations are?

What does this mean specifically for your organization?  

What are the consequences of failing to comply with the NIS2 law?

Many organizations still aren’t fully NIS2-compliant, so you’re definitely not the only one if you still have steps to take.

 

The consequences, however, are far from minor. Fines can run up to €10 million or 2% of global annual turnover (whichever is higher). For important entities, that’s up to €7 million or 1.4%. On top of that, the supervisory authority can temporarily suspend services, publicly disclose a breach, and even hold directors personally liable if they neglect their oversight duties in this area. In extreme cases, they can even be temporarily removed from their management position.

 

Bernd is happy to walk you through this:

Is your legal position on NIS2 clear?

Before investing in technical measures, you need to know where you stand legally. Do you fall under NIS2? And if so, are you an essential or important entity? Getting this wrong can lead to delays, duplicate costs, or, in the worst case, sanctions.

Our solution for this is the Digital Law Scan. The scan maps out whether and how NIS2 applies to your organization, and positions your current legal status against the statutory obligations. 

If you know where you stand but need support preparing your organization to meet all these obligations, you can also turn to Cingulum, our subsidiary specialized in cybersecurity programs.

Meet our CRANIUM specialists.

Marie Manhaeve

Marie Manhaeve

Digital Law Consultant

Bernd Fiten

Head of Digital Law

Bram Goetry

Bram Goetry

Senior Digital Law Consultant

Get your organization scanned.

Request your Digital Law Scan today and find out where you stand on NIS2.

Start the conversation here


We care about your privacy. Unless you sign op to join our community, we will use this data solely to answer your request. For more information on how we process and care for your data, you can read our privacy statement.
  • Solutions
  • Expertise
  • Knowledge
  • Careers
  • About