Scope determination, Article 21 risk management measures, and the accountability the directive places directly on your management body. Established in a fixed-scope, fixed-price Baseline Check.
Book a scoping callNIS2 sorts organisations into two tiers by sector and size. The tier decides how you are supervised, not whether the duties apply — the Article 21 measures are the same for both.
Supervised proactively. Your regulator can inspect without waiting for something to go wrong.
Supervised reactively, on evidence of a shortfall. The same duties, a lighter supervisory posture.
Article 21 makes supply chain security a duty of the entity in scope. That obligation travels to their suppliers as contract terms.
Many organisations first meet NIS2 as a questionnaire from a customer rather than a letter from a regulator, which is a workable place to start from.
The directive names what a risk management framework must cover. It does not prescribe how, which is where proportionality and evidence do the work.
This is the change most organisations underestimate. NIS2 moves cybersecurity from a technical function to a governance duty with named owners.
The management body approves the cybersecurity risk management measures and oversees their implementation. Delegating the work is expected. Delegating the accountability is not available.
Members of the management body are required to follow training, so that they can identify risks and assess cybersecurity practices themselves rather than accept assurances.
Supervisory powers reach the management body directly. Penalties reach €10 million or 2% of worldwide turnover for essential entities, and €7 million or 1.4% for important entities.
We deliver board training as a distinct engagement, because the directive treats it as a distinct obligation. See NIS2 board training, or the academy for the certification track your implementation team follows.
A fixed scope at a fixed price. Not a full gap assessment and not a full penetration test — a positioning read that tells you where you stand and makes the right next step obvious.
A 45 to 60 minute intake, then a written determination.
Run in parallel by a certified specialist partner, never by us.
You receive one short report and one readout call. From there the path is yours to choose: a full gap assessment, a manual penetration test, continuous scanning, an OT assessment where you run a plant estate, or nothing at all if the baseline says you are in good shape.
NexGenio orchestrates NIS2 programmes across a partner consortium. The separation is deliberate and it is the part clients tell us they value most.
Scope, governance, policy, risk method, evidence model. We do not sell you the tooling we then assess.
Internet-facing estate, applications, corporate network, phishing resilience. An independent firm under its own certification.
Plant and industrial estates go to the certification bench, never to the same firm that tested IT. Different accreditations, different discipline.
Three independent reads is a materially stronger story at a board, and at a supervisor, than one vendor assuring itself.
The Dutch transposition of NIS2 entered into force on 15 August 2026, together with its implementing decree. Registration is a standing obligation from that date.
NexGenio delivers NIS2 programmes to Dutch organisations, working with a Netherlands partner consortium for the technical and OT work. Advisory services are provided across the EU under freedom to provide services, so delivery runs from day one without waiting on a local establishment.
The strongest regional demand we see is where the discipline genuinely differs: financial and cloud operations around Amsterdam, port, maritime and petrochemical OT around Rotterdam and the Rijnmond, and high-tech manufacturing and supply chain around Eindhoven. Each needs a different technical partner, which is exactly what the consortium model is for.
Our advisory scope covers governance, risk and compliance. It does not extend to advice on specific financial products or instruments, which sits inside the Wft licensing perimeter and belongs with a licensed firm.
A short call establishes your scope, your tier, and which duties matter first. From there the Baseline Check gives you something you can take to your board.
Book a scoping call