NIS2 guide · public sector

NIS2 for (semi-)government: the complete guide

For government, NIS2 is no longer a distant concern. The EU directive becomes the Dutch Cybersecurity Act and directly affects municipalities, provinces, water authorities and implementing agencies. This guide sets out what NIS2 is, who it applies to, which obligations it brings, how it builds on your existing BIO/ENSIA framework and — above all — what you can already do now without waiting for the final text.

In short
  • In the Netherlands NIS2 becomes the Cybersecurity Act (Cbw), directly affecting municipalities, provinces, water authorities and implementing agencies.
  • Four obligations: duty of care, reporting duty, registration and supervision — plus explicit board accountability.
  • Reporting deadlines are tight: 24 hours (early warning), 72 hours (notification), 1 month (final report).
  • Get the BIO demonstrably in order and you're largely NIS2-ready; the biggest additions are the reporting duty, supply-chain security and board accountability.
  • Don't wait for the law: start now with risk analysis, supply-chain and incident processes, and embed it in your BIO/ENSIA cycle.

What is NIS2 and why does it affect government?

NIS2 (Network and Information Security Directive 2) is the EU directive for network and information security that replaces and significantly expands the original NIS directive. It raises the security level across the EU and brings far more organisations under one regime.

The Netherlands transposes NIS2 into the Cybersecurity Act (Cbw), succeeding the Wbni. Where previously mainly critical providers were in scope, NIS2 explicitly brings government and many public service providers within its reach.

Who does NIS2 apply to? Essential and important entities

NIS2 distinguishes essential and important entities. For the public sector: municipalities, provinces, water authorities and implementing agencies are expected to fall under the law — the precise scope for decentralised government is set via the Cbw.

The difference lies mainly in supervision: essential entities face proactive supervision, important entities reactive (after an incident or signal). The underlying duty of care and reporting duty apply to both. So don't assume you're out of scope.

The four obligations at a glance

NIS2 rests on four pillars. The duty of care: appropriate technical and organisational measures to manage risk. The reporting duty: report significant incidents within tight deadlines. The registration duty: register your organisation with the competent authority. And supervision: the regulator can inspect, issue instructions and enforce.

New and significant is the explicit responsibility of the management body: the board must approve the measures, oversee implementation and can be held liable.

Duty of care: which measures does NIS2 expect?

The duty of care is risk-based. NIS2 names, among others: risk analysis and security policies, incident handling, business continuity (backups, recovery, crisis management), supply-chain security, secure acquisition and development including vulnerability handling, access control and asset management, cryptography and encryption, HR security, and basic cyber hygiene with training.

Importantly, it's not a checklist but demonstrably appropriate measures for your risks. That is exactly where the Dutch BIO framework already fits well.

Reporting duty: the deadlines you must meet

For a significant incident the deadlines are tight: an early warning within 24 hours, a full incident notification within 72 hours, and a final report within one month. Reporting goes to the competent authority/CSIRT.

That requires a rehearsed incident process: who decides something is 'significant', who reports, and how do you gather the right facts fast? A runbook and a tested reporting chain are not a luxury but a necessity.

Board accountability: this is new and serious

NIS2 places ultimate responsibility firmly with the management body. The board must approve the cybersecurity measures and oversee implementation, and can be held personally accountable for negligence. Board members must also follow training to assess risks.

Cybersecurity is therefore definitively a governance topic, not an IT affair. Make sure it's on the board's agenda, with clear roles and responsibilities.

NIS2 and your existing BIO/ENSIA framework

Good news for Dutch government: you don't start from zero. The BIO (government information-security baseline) already provides a broad set of measures, and ENSIA is the annual accountability report on it. Many NIS2 requirements — risk management, access control, continuity — are already in there.

NIS2's biggest additions are the reporting duty with deadlines, supply-chain security and board accountability. Get the BIO demonstrably in order and you're largely NIS2-ready; the rest is targeted building.

What you can do now — without waiting for the law

There's no need to wait for the exact Cbw text; the core is set. Start with a current risk analysis and map your key systems and data chains, including your suppliers. Set up or test your incident and reporting process (can you meet the 24/72-hour deadlines?). Anchor cybersecurity at board level with clear roles. And embed all of this in your existing BIO/ENSIA cycle rather than running a separate project.

That way you build demonstrable resilience step by step — and you're ready the moment the law takes effect, instead of starting only then.

The timeline: where do we stand?

NIS2 entered into force across the EU with a transposition deadline of 17 October 2024. The Netherlands did not meet it with the Cybersecurity Act; implementation is delayed and expected during 2025-2026. The exact date and the fine-grained scope for decentralised government are still being finalised.

The direction, however, is irreversible. Organisations that get the basics in order now turn the delayed date into extra preparation time — no reason to wait.

Frequently asked questions

What is NIS2?

NIS2 (Network and Information Security Directive 2) is the EU directive for network and information security that replaces and significantly expands the original NIS directive. The Netherlands transposes it into the Cybersecurity Act (Cbw), and it explicitly brings government within its scope.

Who does NIS2 apply to?

NIS2 distinguishes essential and important entities. For the public sector, municipalities, provinces, water authorities and implementing agencies are expected to fall under the law; the precise scope is set via the Cbw. Don't assume you are out of scope.

Which obligations does NIS2 bring?

Four: the duty of care (appropriate measures), the reporting duty (report incidents within tight deadlines), the registration duty (register with the competent authority) and supervision. New is the explicit responsibility and liability of the management body.

What does the NIS2 duty of care involve?

Risk-based measures: among others risk analysis and security policy, incident handling, business continuity, supply-chain security, access control, cryptography and cyber hygiene with training. It's not a checklist, but demonstrably appropriate measures for your risks.

What are the NIS2 reporting deadlines?

For a significant incident: an early warning within 24 hours, a full incident notification within 72 hours and a final report within one month, to the competent authority or CSIRT.

Are board members personally liable under NIS2?

Yes. The management body must approve the cybersecurity measures and oversee implementation, and can be held personally accountable for negligence. Board members must also follow training to assess risks.

What is the difference between NIS2 and the BIO?

The BIO is the Dutch measures framework for government information security; NIS2 is the EU directive layered on top. Many BIO measures already cover NIS2 — the biggest additions are the reporting duty with deadlines, supply-chain security and board accountability.

What can I already do to prepare for NIS2?

Don't wait for the final text. Start with a risk analysis, map your systems and data chains (including suppliers), set up or test your incident and reporting process, and anchor it in your existing BIO/ENSIA cycle.

When does the Dutch Cybersecurity Act (NIS2) take effect?

The EU deadline was 17 October 2024; the Netherlands missed it and implementation is delayed, expected during 2025-2026. Don't wait — the core obligations are already set.

Control over information security — together

Take the free scan or let us take a no-obligation look.

TdW
Tom de WaardFounder · Interim CMO & digital transformation partner

Founder of DWDA and interim CMO. For over thirty years — since 1993 — Tom has helped organisations from SME to multinational with digital strategy, marketing and transformation. As the face of an award-winning digital case at Nutricia (Danone) he won several public awards, including the Customer Data Award and the LOVIE Awards. As Marketing Director he built a distinctive sustainability positioning at FlexIT — from evidence to revenue model. In recent years he has focused strongly on the public sector: he helps (semi-)government organisations, such as Sabewa Zeeland, modernise and make use of today's systems and techniques — with information security and compliance as the fundamental starting points. Tom translates strategy into execution, with AI and governance as the common thread.

More about the team → Connect on LinkedIn