" /> NIS2 Readiness: Rotterdam Logistics Case Study | ITSECOPS
Case study

NIS2 Readiness for a Rotterdam Logistics Group Before the Dutch Deadline

Updated · Aug 2026 By ITSECOPS Free · No signup

Case study · Logistics & Transport · Rotterdam, Netherlands

With the Dutch Cyberbeveiligingswet entering into force on 15 August 2026 — with no transition period — a Rotterdam logistics group needed NIS2 readiness done, not discussed. ITSECOPS ran the full programme: applicability, gap assessment against the ten Article 21 measures, incident-reporting workflow and board training — finished before the law switched on.

The client

A logistics and freight-forwarding group in the Rotterdam port ecosystem. Transport is an Annex I high-criticality sector under NIS2, and with well over 50 employees the group qualifies as an important entity under the Dutch implementation.

The challenge

The Cyberbeveiligingswet took effect on 15 August 2026 with immediate obligations: duty of care (zorgplicht), incident reporting (meldplicht) on a 24-hour / 72-hour / one-month cycle, registration, and personal accountability for management. The board first heard about NIS2 from a customer questionnaire — five months before the deadline.

What we did

  • Confirmed applicability and classification (important entity, transport, Annex I) and prepared the registration details required from day one.
  • Ran a gap assessment against the ten Article 21 minimum measures — risk analysis, incident handling, business continuity, supply-chain security, secure development and procurement, effectiveness testing, cyber hygiene and training, cryptography, HR and access security, and MFA/secured communications.
  • Built the incident-reporting workflow: severity definitions, decision tree for “significant incident”, pre-drafted 24h early-warning and 72h notification templates, and a one-month final-report checklist — then drilled it with a tabletop exercise.
  • Added NIS2 security clauses to carrier and IT-supplier contracts (the supply-chain measure most logistics firms miss).
  • Delivered the management-body training session the law expects boards to evidence, with minutes filed as proof.
  • Connected the estate to 24×7 monitoring so “detect and handle incidents” is a running capability, not a policy sentence.

Results

  • NIS2-ready before 15 August 2026 — no scramble when the law entered into force.
  • Board can evidence training and oversight; fine exposure (up to €7M / 1.4% of turnover for important entities) governed.
  • First customer security questionnaire after go-live answered from the gap-assessment evidence in one afternoon.

FAQ

Does NIS2 apply to logistics companies in the Netherlands?

Usually yes — transport is an Annex I sector, so logistics and freight firms with 50+ employees or €10M+ turnover are typically important entities under the Cyberbeveiligingswet, in force since 15 August 2026.

How long does NIS2 readiness take?

For a mid-sized company: 8–14 weeks from gap assessment to evidenced readiness, driven mostly by supplier-contract updates and remediation depth. Check where you stand with our free NIS2 applicability checker.

What happens if a Dutch company ignores NIS2?

Fines up to €10M or 2% of worldwide turnover for essential entities (€7M / 1.4% for important), plus registration and reporting breaches counted separately — and management can be held personally accountable.

BOOK A FREE NIS2 GAP REVIEW

Need help applying this to your environment?

We turn compliance guides into shipped controls. Talk to an engineer.

Book a consultation