" /> NIS2 Requirements Explained: Articles 21 & 23 | ITSECOPS
Veiledning

What are the NIS2 requirements for companies?

Oppdatert · aug 2026 By ITSECOPS Gratis · Ingen påmelding

NIS2 requires in-scope companies to register with their national authority, implement ten risk-management measures (Article 21) — including incident handling, backups, supply-chain security and MFA — report significant incidents within 24 hours, and make management personally accountable, with fines up to €10 million or 2% of global turnover.

The four pillars

  • Registration with the national regulator (NCSC in the Netherlands, BSI in Germany, CCB in Belgium, CFCS in Denmark).
  • Duty of care — Article 21’s ten measures: risk analysis and security policies; incident handling; business continuity, backups and crisis management; supply-chain security; secure development and vulnerability handling; effectiveness testing; cyber hygiene and training; cryptography; access control and asset management; MFA and secured communications.
  • Incident reporting — Article 23: early warning within 24 hours, full notification within 72 hours, final report within one month. In practice this requires 24/7 detection and response.
  • Governance: management bodies approve and oversee the measures, complete cybersecurity training, and can be held personally liable.

Who is in scope?

Essential and important entities in 18 sectors, generally from 50 employees or €10 million turnover — assessed per legal entity. Smaller suppliers are pulled in indirectly through their customers’ supply-chain obligations.

Country specifics differ: see our native-language guides for the Netherlands, Germany, Belgium and Denmark, or book a free gap review.

Trenger du hjelp til å ta dette i bruk i din bedriftsmiljø?

Vi gjør compliance-guider om til implementerte kontroller. Snakk med en ingeniør.

Bestill en konsultasjon