Home > NIS2 Directive
EU Directive (EU) 2022/2555 · In force since 16 January 2023

EU NIS2 Directive

Europe's cybersecurity law does not stop at software. NIS2 makes management bodies accountable for risk measures that explicitly include access control, asset management and the physical environment of network and information systems.

Transposition deadline 17 Oct 2024 NL: Cyberbeveiligingswet in force 15 Aug 2026 EU transposition: live tracker below
Where NIS2 stands

From directive to enforcement, the clock so far

NIS2 replaced the first NIS directive in January 2023. Transposition is nearly complete across the EU, and in the Netherlands the obligations became national law in August 2026.

Today
  1. 16 Jan 2023Directive in force across the EU
  2. 17 Oct 2024National transposition deadline; most member states missed it
  3. 17 Apr 2025Member states list their essential and important entities
  4. Jul / Aug 2026NL referred to the EU Court of Justice (8 Jul); Cyberbeveiligingswet in force 15 Aug
  5. 2027 →Registration, supervision, audits and enforcement

In the Netherlands, registration for in-scope organisations is mandatory from 15 August 2026; duty-of-care and incident-notification obligations follow under sector supervision.

What it requires

Six obligations that decide your NIS2 posture

NIS2 defines security of network and information systems to include their physical environment. These are the articles that matter most for organisations running critical operations.

ART. 20

Governance and accountability

Management bodies must approve cybersecurity risk measures, oversee their implementation and can be held personally liable. Training for boards is mandatory.

ART. 21(2)(a–c)

Risk management and continuity

Policies on risk analysis, incident handling, business continuity, backup and crisis management, proportionate to the risk and all-hazards in scope.

ART. 21(2)(d)

Supply chain security

Security in supplier relationships, including service providers and contractors with access, digital or physical, to your systems and sites.

ART. 21(2)(i)

Access control and asset management

Human resources security, access control policies and asset management. The clause that pulls physical keys, cabinets and access points into cybersecurity scope.

ART. 21(2)(j)

Authentication

Multi-factor or continuous authentication and secured communications wherever appropriate, for people as well as systems.

ART. 23

Incident reporting

Early warning within 24 hours, incident notification within 72 hours and a final report within one month, to the CSIRT or competent authority.

Who is in scope

Essential and important entities across 18 sectors

NIS2 applies automatically to medium-sized and larger organisations in the sectors of Annex I and II, with member states able to designate smaller entities that are critical regardless of size.

In the Netherlands the Cyberbeveiligingswet is expected to cover roughly 8,000 organisations.

EnergyTransportHealthPublic administrationManufacturingDrinking & waste waterDigital infrastructureICT service managementBanking & financial marketsSpacePostal & courierChemicalsFoodWaste managementResearch+ digital providers and more in Annex II
Where the directive meets physical access

NIS2 asks for control. Physical access is where it breaks.

Most NIS2 programmes govern digital identity well and stop at the server-room door. Identity-governed physical access extends the same lifecycle, policy and audit model to keys, cabinets and sites.

ART. 21(2)(i)

Access control policies and asset management, including the physical environment of systems.

Every key, locker and cabinet is a governed asset bound to an identity, with request, approval, issue and return controlled by policy.

ART. 21(2)(d)

Security in supplier relationships and service provider access.

Contractors and field engineers receive time-boxed physical access tied to their identity lifecycle. Off-boarded means revoked, the same day.

ART. 20

Management bodies accountable for measures and their implementation.

Board-ready evidence: who could open what, when, approved by whom, exportable per audit period.

ART. 23

Incident timelines of 24 hours, 72 hours and one month.

One audit trail across digital and physical access, so incident reconstruction is a query, not an investigation.

ART. 21(2)(c)

Business continuity and crisis management.

Emergency and break-glass access is governed, logged and certifiable, instead of a key box that runs on trust.

See how the platform works →

Live from EUR-Lex

Live: NIS2 transposition across the EU

The NIS2 Directive (EU 2022/2555) requires every member state to transpose it into national law. We track the implementing measures notified to EUR-Lex in real time, so you always know where each country stands.

Loading implementation data...
In the Netherlands

Cyberbeveiligingswet (Cbw)

The Netherlands transposed NIS2 through the Cyberbeveiligingswet, approved by the Senate on 7 July 2026 and in force since 15 August 2026, weeks after the European Commission referred the Netherlands to the EU Court of Justice for late transposition. Registration for in-scope organisations is mandatory from day one; duty-of-care and incident-notification obligations follow under sector supervision.

In force
15 August 2026
Applies to
± 8,000 organisations
Registration
Mandatory from 15 Aug 2026
Replaces
Wbni (2018)
Keep reading

Latest on NIS2

All coverage →

Make NIS2 evidence a by-product, not a project

See how identity-governed physical access produces the access-control and asset-management evidence NIS2 asks for, from the same lifecycle that already governs your digital world.

Book a demo Build your business case