NexGenio
Home Academy Insights Contact

NIS2 is in force. Everything starts with scope.

Scope determination, Article 21 risk management measures, and the accountability the directive places directly on your management body. Established in a fixed-scope, fixed-price Baseline Check.

Essential entities Important entities Supply chain Board accountability Incident reporting
Book a scoping call
Scope

Essential, important, or neither

NIS2 sorts organisations into two tiers by sector and size. The tier decides how you are supervised, not whether the duties apply — the Article 21 measures are the same for both.

Tier one

Essential entities

Supervised proactively. Your regulator can inspect without waiting for something to go wrong.

  • Energy, transport, banking
  • Financial market infrastructure
  • Health, drinking water, wastewater
  • Digital infrastructure
  • ICT service management
  • Public administration, space
Tier two

Important entities

Supervised reactively, on evidence of a shortfall. The same duties, a lighter supervisory posture.

  • Postal and courier services
  • Waste management
  • Chemicals
  • Food production and distribution
  • Manufacturing of critical products
  • Digital providers, research
Worth checking

Reached through the chain

Article 21 makes supply chain security a duty of the entity in scope. That obligation travels to their suppliers as contract terms.

Many organisations first meet NIS2 as a questionnaire from a customer rather than a letter from a regulator, which is a workable place to start from.

Article 21

Ten measures, stated plainly

The directive names what a risk management framework must cover. It does not prescribe how, which is where proportionality and evidence do the work.

Article 20

What the board now owns

This is the change most organisations underestimate. NIS2 moves cybersecurity from a technical function to a governance duty with named owners.

Approve the measures

The management body approves the cybersecurity risk management measures and oversees their implementation. Delegating the work is expected. Delegating the accountability is not available.

Be trained for it

Members of the management body are required to follow training, so that they can identify risks and assess cybersecurity practices themselves rather than accept assurances.

Answer for it

Supervisory powers reach the management body directly. Penalties reach €10 million or 2% of worldwide turnover for essential entities, and €7 million or 1.4% for important entities.

We deliver board training as a distinct engagement, because the directive treats it as a distinct obligation. See NIS2 board training, or the academy for the certification track your implementation team follows.

Where to start

The NIS2 Baseline Check

A fixed scope at a fixed price. Not a full gap assessment and not a full penetration test — a positioning read that tells you where you stand and makes the right next step obvious.

NexGenio

The governance read

A 45 to 60 minute intake, then a written determination.

  • Whether you are in scope, and as which tier
  • Which Article 21 duties bite hardest for your operation
  • Where your management body's exposure actually sits
  • Registration and incident reporting obligations
Technical partner

The external read

Run in parallel by a certified specialist partner, never by us.

  • External view of your internet-facing estate
  • Findings ranked by exploitability, not by count
  • Delivered co-branded, under their certification

You receive one short report and one readout call. From there the path is yours to choose: a full gap assessment, a manual penetration test, continuous scanning, an OT assessment where you run a plant estate, or nothing at all if the baseline says you are in good shape.

How we work

Three independent reads, not one vendor

NexGenio orchestrates NIS2 programmes across a partner consortium. The separation is deliberate and it is the part clients tell us they value most.

1

We write the framework

Scope, governance, policy, risk method, evidence model. We do not sell you the tooling we then assess.

2

A partner tests IT

Internet-facing estate, applications, corporate network, phishing resilience. An independent firm under its own certification.

3

A different partner tests OT

Plant and industrial estates go to the certification bench, never to the same firm that tested IT. Different accreditations, different discipline.

4

Nobody marks their own work

Three independent reads is a materially stronger story at a board, and at a supervisor, than one vendor assuring itself.

Netherlands

The Cyberbeveiligingswet is live

The Dutch transposition of NIS2 entered into force on 15 August 2026, together with its implementing decree. Registration is a standing obligation from that date.

15 Aug 2026
Cyberbeveiligingswet in force, replacing the NIS1-based Wbni
8,000+
Organisations providing essential or important services now covered
MijnNCSC
Entity register. Registration is mandatory, and changes are reportable within 14 days
NCSC-NL & RDI
CSIRT and supervisor, alongside DNB and AFM for financial entities

Serving the Dutch market

NexGenio delivers NIS2 programmes to Dutch organisations, working with a Netherlands partner consortium for the technical and OT work. Advisory services are provided across the EU under freedom to provide services, so delivery runs from day one without waiting on a local establishment.

The strongest regional demand we see is where the discipline genuinely differs: financial and cloud operations around Amsterdam, port, maritime and petrochemical OT around Rotterdam and the Rijnmond, and high-tech manufacturing and supply chain around Eindhoven. Each needs a different technical partner, which is exactly what the consortium model is for.

Our advisory scope covers governance, risk and compliance. It does not extend to advice on specific financial products or instruments, which sits inside the Wft licensing perimeter and belongs with a licensed firm.

Questions

Frequently asked

How do I know whether we are an essential or an important entity?
It follows from your sector and your size. Sectors are listed in the directive's annexes, and the size test generally starts at the medium-enterprise threshold, meaning 50 or more staff or €10 million or more in turnover or balance sheet total. There are exceptions that pull smaller organisations in regardless of size, particularly in digital infrastructure and public administration. The tier changes how you are supervised rather than what you must do.
Does ISO 27001 make us NIS2 compliant?
It gets you a long way and it is the most efficient route for most organisations, because an ISO 27001 ISMS maps closely onto the Article 21 measures and produces the evidence a supervisor will ask for. It is not a substitute, though. NIS2 adds obligations that sit outside a standard ISMS scope, notably the registration duty, the incident reporting timelines, and the board's own accountability and training under Article 20.
What are the incident reporting deadlines?
A significant incident triggers an early warning within 24 hours of becoming aware of it, a fuller incident notification within 72 hours, and a final report within one month. The 24-hour clock is short enough that the decision path needs to exist in advance. Building that decision tree, so the right person can classify an incident quickly and without debate, is usually the highest-value early piece of work.
We only supply an in-scope company. Does NIS2 reach us?
Not as a direct legal obligation, unless you are independently in scope. In practice it reaches you commercially. Supply chain security is an explicit Article 21 duty for your customer, so the requirements arrive as contractual terms, security questionnaires and audit rights. Suppliers who can answer those quickly and consistently tend to find it becomes a competitive advantage rather than an overhead.
Do you need an office in our country to work with us?
No. Compliance advisory is a service provided under the EU freedom to provide services, so a local establishment is not required and engagements start immediately. Where work genuinely benefits from local presence, such as OT assessments on a plant or port estate, that is delivered by an accredited partner in-country.
What does the Baseline Check cost?
It is a fixed price against a fixed scope, quoted on the scoping call once we know the shape of your estate. We keep it a paid engagement deliberately. It is real work with a real deliverable, and pricing it properly is what keeps partner testing capacity available for the organisations that genuinely need it.

Start with where you actually stand

A short call establishes your scope, your tier, and which duties matter first. From there the Baseline Check gives you something you can take to your board.

Book a scoping call