
NIS2 is not a project, it is a way of working
The European NIS2 directive sets requirements for how organisations arrange their digital resilience, and puts responsibility for it with the board. This page says what that asks of your IT in practice, and where our part ends.
What this is about
One European directive, two categories of organisation, and a reporting duty counted in hours.
Does it apply to you?
That depends on your sector and your size, and the national implementation differs per country. We do not determine it for you — this is what you need in order to ask the question properly.
- Sector and size togetherThe directive names sectors and attaches a size floor to them. Both have to hold: a small company in a named sector usually falls outside it, and so does a large company in a sector that is not named.
- Essential or importantThe two categories carry comparable obligations but different supervision: a regulator can approach an essential entity on its own initiative, and an important one only when there is cause.
- Even when it does not apply to youIf you supply an organisation that does fall under it, the requirements reach you through the contract anyway. That is not a side effect but the explicit purpose of the supply chain provisions.
- Registering with the regulatorAn organisation that falls under it registers itself with the national regulator. That is an act of the organisation, not of its IT supplier.
What the directive asks of your measures
The text names topics rather than products. These are the topics our work comes down to.
Knowing what you have and what it is worth
A risk assessment starts with a current list of systems, connections and suppliers. Without that list every measure is a guess, and afterwards there is no explaining why you did or did not do something.
Access, and the evidence of it
Who can reach what, with which rights, and with a second factor. Multi-factor authentication is named in the directive, and the log showing that it is switched on matters as much as the setting itself.
Carrying on when something breaks
Backups that have been restored and not merely made, failover that has been rehearsed, and a network where an infection does not arrive everywhere at once. Continuity is a requirement, not a by-product.
Handling an incident and reporting it
The clock starts the moment you know: an early warning within 24 hours, a substantive report within 72 hours and a final report within a month. You only make that with a process you have rehearsed.
The board, in the room
The directive puts approval of the measures with the board and asks that directors be trained on them. It is explicitly not a subject you can leave to the IT department.
What we do, and what we do not
There are firms selling "NIS2 compliance" as a product. We cannot deliver that and neither can anyone else: compliance is a judgement about your organisation, not a service you buy. This is the division we do stand behind.
- What we doThe technology and the record: access management and multi-factor authentication, network segmentation, patching, monitoring and logging, backup and recovery that has actually been tested, and rehearsing the incident process so the 24-hour clock is achievable. In the Netherlands and Belgium we do the on-site work with our own people.
- What we recordWhat was put in place, when, and on which systems. That is the material an auditor or a regulator asks for, and it is precisely the part that no longer exists if you have to reconstruct it afterwards.
- What we do not doDecide whether the law applies to you, register you with the regulator, or file a report on your behalf. Those are acts of the organisation itself, with legal consequences. We supply the facts such a report needs, and quickly.
- No certificateThere is no NIS2 mark to obtain. Anyone selling one is selling something else. Our ISO 9001 and ISO/IEC 27001 certification says something about how we work, not about how you meet the directive.
This is not legal advice. What stands here is the translation into technology and working practice; whether and how the directive applies to your organisation should come from your lawyer or from the national regulator. Not sure where you stand? Call +31 85 060 9347 or email info@itproposal.com.
Further reading
What this connects to.
Want to know where you stand?
Tell us what runs and what is already arranged. We walk through the topics above with you and say which ones are missing on your side — without attaching a compliance verdict to it.
Practical IT knowledge in your inbox
New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.