Governance and accountability
Management bodies must approve cybersecurity risk measures, oversee their implementation and can be held personally liable. Training for boards is mandatory.
Europe's cybersecurity law does not stop at software. NIS2 makes management bodies accountable for risk measures that explicitly include access control, asset management and the physical environment of network and information systems.
NIS2 replaced the first NIS directive in January 2023. Transposition is nearly complete across the EU, and in the Netherlands the obligations became national law in August 2026.
In the Netherlands, registration for in-scope organisations is mandatory from 15 August 2026; duty-of-care and incident-notification obligations follow under sector supervision.
NIS2 defines security of network and information systems to include their physical environment. These are the articles that matter most for organisations running critical operations.
Management bodies must approve cybersecurity risk measures, oversee their implementation and can be held personally liable. Training for boards is mandatory.
Policies on risk analysis, incident handling, business continuity, backup and crisis management, proportionate to the risk and all-hazards in scope.
Security in supplier relationships, including service providers and contractors with access, digital or physical, to your systems and sites.
Human resources security, access control policies and asset management. The clause that pulls physical keys, cabinets and access points into cybersecurity scope.
Multi-factor or continuous authentication and secured communications wherever appropriate, for people as well as systems.
Early warning within 24 hours, incident notification within 72 hours and a final report within one month, to the CSIRT or competent authority.
NIS2 applies automatically to medium-sized and larger organisations in the sectors of Annex I and II, with member states able to designate smaller entities that are critical regardless of size.
In the Netherlands the Cyberbeveiligingswet is expected to cover roughly 8,000 organisations.
Most NIS2 programmes govern digital identity well and stop at the server-room door. Identity-governed physical access extends the same lifecycle, policy and audit model to keys, cabinets and sites.
Access control policies and asset management, including the physical environment of systems.
Every key, locker and cabinet is a governed asset bound to an identity, with request, approval, issue and return controlled by policy.
Security in supplier relationships and service provider access.
Contractors and field engineers receive time-boxed physical access tied to their identity lifecycle. Off-boarded means revoked, the same day.
Management bodies accountable for measures and their implementation.
Board-ready evidence: who could open what, when, approved by whom, exportable per audit period.
Incident timelines of 24 hours, 72 hours and one month.
One audit trail across digital and physical access, so incident reconstruction is a query, not an investigation.
Business continuity and crisis management.
Emergency and break-glass access is governed, logged and certifiable, instead of a key box that runs on trust.
The Netherlands transposed NIS2 through the Cyberbeveiligingswet, approved by the Senate on 7 July 2026 and in force since 15 August 2026, weeks after the European Commission referred the Netherlands to the EU Court of Justice for late transposition. Registration for in-scope organisations is mandatory from day one; duty-of-care and incident-notification obligations follow under sector supervision.
See how identity-governed physical access produces the access-control and asset-management evidence NIS2 asks for, from the same lifecycle that already governs your digital world.