NIS2 is now law across most of the EU — in the Netherlands since 15 August 2026, with no transition period. Answer four questions to see whether you are an essential entity, an important entity or out of scope, what that means in fines and duties, and get a step-by-step readiness roadmap you can tick off.
Does NIS2 apply to you?
Why this matters right now
The Netherlands switched NIS2 on with the Cyberbeveiligingswet on 15 August 2026 — with no transition period. Germany, Belgium and Denmark are already in force, and several registration windows have closed. If the checker says you are in scope, the obligations are running today, not at some future deadline. See how a Rotterdam logistics group got NIS2-ready before the Dutch deadline, or jump to your country guide: Nederland · Deutschland · België · Danmark · Norge · EU overview.
FAQ
Who does NIS2 apply to?
Organisations in Annex I (energy, transport, banking, health, water, digital infrastructure, ICT service management, public administration, space) and Annex II sectors (post, waste, chemicals, food, manufacturing, digital providers, research) with 50+ employees or €10M+ turnover — plus some providers regardless of size, and non-EU companies serving the EU.
What is the difference between essential and important entities?
Essential entities are large Annex I organisations: proactive supervision and fines up to €10M or 2% of worldwide turnover. Important entities face reactive supervision and up to €7M or 1.4%. The security measures are the same ten either way.
My company is below the thresholds — can I ignore NIS2?
Not necessarily. If you supply in-scope customers, Article 21 supply-chain security pushes the same requirements into your contracts — meeting them is increasingly the price of keeping those customers.