Does NIS2 apply to my company?
Two questions decide it: are you in a listed sector, and do you meet the threshold from Recommendation 2003/361/EC (more than 50 FTE and more than EUR 10M turnover or balance sheet). Below that you are only indirectly in scope, via your customers. The threshold determines whether you are an important or essential entity depending on sector.
Try this first
- 1Check the sector. Annexes I and II list energy, transport, water, banking, financial markets, health, government, digital infrastructure, ICT service management, space, food, chemicals, manufacturing of critical goods, digital providers, and research.
- 2Count headcount and revenue. Below 50 FTE and EUR 10M revenue you are out of direct scope, unless you are the only NL provider of that service.
- 3Do you serve a customer who is in scope? Then NIS2 reaches you indirectly through their supplier management, contractually.
- 4Use the official RDI NIS2 self-assessment to confirm whether you are an essential or important entity.
- 5Write down the result with date and source. Re-run when the law or your revenue changes.
When to bring us in
Unclear sector classification or you supply multiple essential entities at once? Then a legal review beats guessing.
See also
- What changes with the Dutch Cyber Security Act?The Cyberbeveiligingswet is the Dutch implementation of NIS2. Track NCSC for the exact effective date and the lower regulations.
- Am I personally liable as a director under NIS2?Yes. The board is accountable for approving and overseeing the cyber measures. Severe negligence can become personal.
- What is a processing register and how do I build one?A list per processing activity: what data, what purpose, how long, who shares it. Mandatory under GDPR Art. 30; the under-250-staff exemption falls away as soon as processing is structural or high-risk, which is essentially always the case for SMBs handling customer data.
None of the above fits?
Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.
Or skip the DIY entirely
Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.