What technical measures are required under NIS2?

6 August 2026 | John van Lopik

Under NIS2, organizations in designated sectors are required to implement concrete technical security measures. Think risk assessments, encryption, access control, incident detection, and securing the physical network infrastructure. These obligations apply to both essential and important entities and will be fully in force in the Netherlands in 2026 through the Cybersecurity Act. In this article, we answer the most frequently asked questions about NIS2 obligations, technical requirements, and how your organization can achieve compliance.

Which sectors fall under NIS2 obligations?

NIS2 applies to organizations in sectors designated as essential or important. Essential sectors include energy, transport, healthcare, drinking water, digital infrastructure, and financial markets. Important sectors include postal and courier services, waste management, food production, chemicals, and digital providers such as search engines and cloud platforms.

The distinction between essential and important determines the intensity of supervision, but not the content of the obligations. Both categories must implement the same technical measures. The thresholds are based on organizational size: medium-sized enterprises with more than 50 employees or an annual turnover exceeding 10 million euros fall within the scope of the directive, provided they operate in one of the designated sectors.

Important to note: organizations that do not directly operate in a designated sector may still fall indirectly under NIS2 if they provide critical services to entities that do. Suppliers and managed service providers in the supply chain are explicitly included in the risk management obligations.

What are the mandatory technical security measures under NIS2?

NIS2 does not prescribe specific products, but requires organizations to take appropriate and proportionate technical measures based on a risk assessment. The directive identifies a number of concrete areas where action is required. These are the key NIS2 technical measures every organization must address:

  • Risk assessment and security policy: Document risks to network and information systems and establish a formal policy.
  • Access control and authentication: Restrict access based on the principle of least privilege and enforce strong authentication.
  • Encryption: Protect data in transit and at rest through appropriate encryption solutions.
  • Incident detection and monitoring: Ensure continuous monitoring of networks and systems to identify anomalies in a timely manner.
  • Business continuity and backup: Guarantee recovery capability in the event of incidents, including backup management and emergency procedures.
  • Supply chain security: Assess the security posture of suppliers and service providers.
  • Patch management and vulnerability management: Keep systems up to date and respond quickly to known vulnerabilities.

The emphasis is on demonstrability. It is not enough to implement measures — you must also be able to prove that they are effective and regularly tested.

How does NIS2 differ from the original NIS directive?

NIS2 is considerably broader and stricter than the original NIS directive from 2016. The main differences are an expanded scope, stricter security requirements, higher fines, and explicit liability for executives.

While the first NIS directive was limited to a small group of essential service providers and digital service providers, NIS2 significantly widens the scope. Dozens of new sectors have been added, and the definition of who falls under the directive has been tightened based on objective thresholds rather than national assessments.

Another fundamental difference is managerial accountability. Under NIS2, executives can be held personally liable if they fail to adequately oversee compliance with NIS2 cybersecurity requirements. This makes NIS2 compliance a boardroom issue, not just an IT matter. Fines can reach up to 10 million euros or 2 percent of global annual turnover for essential entities.

Ready for the next step?

Explore our solutions or get in touch with one of our experts directly.

What does NIS2 require for network infrastructure and physical security?

NIS2 network security encompasses both logical and physical measures. Organizations must protect their network infrastructure against unauthorized access, eavesdropping, and physical sabotage. This means that security measures do not stop at the firewall and must also cover the physical layer of the network.

Logical network security

At the logical level, NIS2 requires network segmentation, monitoring of network traffic, and detection of anomalous behavior. Encryption of data traffic over critical connections is an explicit requirement, especially when sensitive information is transmitted over public or shared networks. Protecting sensitive data starts with choosing the right encryption protocols at the network level.

Physical network security

The physical security of network infrastructure is an area that organizations frequently underestimate. NIS2 requires that physical access to critical network equipment and cabling be restricted and controlled. For fiber optic networks, this also means monitoring the integrity of the physical connection. Real-time fiber optic monitoring makes it possible to detect physical breaches or disruptions immediately, contributing to both security and continuity.

When must an organization report an incident under NIS2?

Under NIS2, a tiered reporting schedule applies to significant incidents. An incident is considered significant if it causes a serious operational disruption, results in considerable financial damage, or affects other organizations or individuals. The reporting obligation consists of three steps with fixed deadlines.

  1. Early warning within 24 hours: As soon as you become aware that a significant incident has occurred, you must submit an initial notification to the competent authority (in the Netherlands, the NCSC or the sector-specific supervisory authority).
  2. Incident report within 72 hours: A more detailed report with an initial assessment of severity, impact, and possible cause.
  3. Final report within one month: A complete report including root cause analysis, measures taken, and lessons learned.

Effective monitoring and network management are essential for detecting incidents in time and having the required information available quickly for reporting purposes. Organizations without continuous monitoring in place risk missing the 24-hour deadline, which in itself constitutes a violation.

How do you get started with NIS2 compliance for your network infrastructure?

Start with a baseline assessment: map out which systems, networks, and data fall within the scope of NIS2, and evaluate your current security measures against the requirements of the directive. Based on that gap analysis, develop a prioritization plan aligned with your organization’s risk level.

A practical step-by-step approach:

  • Determine whether your organization falls under NIS2 and in which category (essential or important).
  • Conduct a risk assessment for your network and information systems.
  • Identify gaps in access control, encryption, monitoring, and physical security.
  • Develop an incident response plan and test it regularly.
  • Document all measures in a demonstrable way for regulators.
  • Actively involve leadership in overseeing NIS2 compliance obligations.

Do not overlook the supply chain. NIS2 requires you to assess the security posture of your suppliers as well. Establish minimum security requirements for parties that have access to your network or systems.

How we help with NIS2 compliance for your network infrastructure

NIS2 compliance requires more than a checklist. It demands a technically grounded approach tailored to the specific risk profiles of your organization and sector. We support organizations at every stage of this process, from risk assessment to the implementation of concrete security measures at the network level.

What we offer:

  • Vendor-independent advice based on your network environment, with solutions from partners such as Nokia, Cisco, Huawei, and HPE Aruba.
  • Layer 1 and Layer 2 encryption for protecting data in transit, including over fiber optic connections.
  • Real-time monitoring and surveillance of physical and logical network infrastructure for timely incident detection.
  • Out-of-band management for secure administration of critical network equipment, even during emergencies.
  • Supply chain guidance and support in establishing security requirements for suppliers.

Our engineers have years of hands-on experience with critical network infrastructure in sectors such as healthcare, transport, and data centers. We translate NIS2 technical measures into solutions that fit your specific situation, without unnecessary complexity. Want to know where your organization stands today and what steps are needed? Contact us for a no-obligation consultation.

Ready for the next step?

Explore our solutions or get in touch with one of our experts directly.

Related Articles

Smart Connections for Your Organization

Would you like to learn more about what we can do for your IT organization? Our experts would be happy to help!