Did you know this about cyber incidents?

Soon, you will be required to report cyber incidents within 24 hours. Executives will be personally liable for their organization’s cyber risks. This is not a distant future, but a reality that is rapidly approaching. The Cybersecurity Act (Cbw), through which the Netherlands is implementing the European NIS2 Directive, is expected to take effect in the second quarter of 2026. Waiting until then is not an option. The requirements are extensive and affect every part of an organization: from policy and IT to suppliers and incident response. Those who start now will avoid stress and fines later.

What is NIS2 and why does it affect you?

NIS2 is the strengthened European cybersecurity directive. The Netherlands is implementing these rules through the Cybersecurity Act. Whereas the old NIS Directive primarily concerned operators of essential services, NIS2 significantly expands the scope. It often applies to medium-sized and large companies (at least 50 employees and more than 10 million euros in revenue), but smaller organizations may also fall under the Cybersecurity Act if they play a significant role in a critical chain. The new legislation applies to:

  • Critical infrastructure: such as energy, healthcare, transportation, and digital infrastructure
  • Key entities: such as IT service providers, waste management companies, postal and courier services, and food production companies
  • Suppliers to these organizations, when they could affect business continuity or security

In other words: even if your organization isn’t directly subject to the law, a customer can require you to take the same measures. Cybersecurity thus becomes not only a legal obligation, but also a business requirement.

The core of NIS2: demonstrable cyber resilience

NIS2NIS2 is not about checking off a checklist, but about demonstrably risk-based operations. The law requires organizations to establish a comprehensive cybersecurity policy that goes beyond technology alone. This includes policies for risk management, incident response, and supply chain security, as well as clear processes for business continuity and crisis management. In addition, NIS2 requires periodic evaluations and continuous improvement, so that measures not only exist but also remain effective. Incidents must be reported quickly and comprehensively: an initial report within 24 hours, an update within 72 hours, and a final report with an analysis of the cause within one month. Executives are given explicit responsibility. They must understand the cyber risks their organization faces, assess whether measures are effective, and undergo regular training. This is new and represents a major cultural shift for many organizations, as cybersecurity is no longer just an IT issue but a strategic priority for the entire company. This is new and represents a major cultural shift for many organizations, as cybersecurity is no longer just an IT issue but a strategic priority for the entire company.

The Cbw (NIS2) Control Framework: Your Practical Starting Point

How do you actually implement NIS2? The Cbw (NIS2) Control Framework provides guidance. This model helps you get a handle on the new requirements step by step. You start by defining the scope: which parts of your organization are subject to the law? Next, you assess the desired maturity level and conduct a self-assessment. This helps you identify gaps and determine what corrective actions are needed.

The framework uses five maturity levels, based on the NBA-LIO/NOREA Maturity Model. This model was developed by Dutch professional organizations for accountants and IT auditors and helps you assess the level of internal control and risk management. Level 3 means that you can demonstrate that processes exist and are functioning. Level 4 goes a step further and aligns with the requirements of the Cybersecurity Act, such as periodic evaluations and continuous improvement.

The framework clarifies what NIS2 requires of you and helps you set priorities. It provides a solid foundation for discussions with management, IT, auditors, and suppliers, and ensures that you can demonstrate to regulators that you have your cyber risks under control. With this model, you not only work in a structured and goal-oriented way on compliance and cyber resilience, but you also take a strategic step toward becoming an organization that is ready for the future. It is not a simple checklist, but a practical tool that provides direction and instills confidence.

Why start now?

The NIS2 requirements are extensive and affect virtually all processes within your organization. It’s not just about IT and technology, but also about policy, suppliers, crisis management, and governance. This is not a project you can complete in a few weeks. Establishing a mature cybersecurity policy requires time, collaboration, and a cultural shift. The longer you wait, the greater the chance that you’ll eventually have to implement it under pressure. That not only costs more money but also increases the risk of errors and reputational damage.

Regulators will soon have greater powers to enforce compliance and impose fines. These fines can be substantial, but the reputational damage is often even greater than the financial impact. In addition, customers and partners will impose stricter requirements on their suppliers. If you cannot demonstrate compliance with NIS2, you risk losing contracts or being excluded from the supply chain. Meanwhile, cyber threats are on the rise. Consider ransomware attacks, data breaches, and disruptions to business processes that affect not only IT but also the continuity of your organization.

Organizations that start now will have a head start later on. They can proceed in phases, train employees, and optimize processes without feeling rushed. Plus, you’ll demonstrate that you have risks under control and that you’re a reliable partner. Start today so you’re not playing catch-up, but are ready for the future.

How can SERIS help you with NIS2?

NIS2 requires more than just technical measures. It calls for a comprehensive approach that brings together policy, processes, and human behavior. That is exactly where SERIS makes a difference. We are not an IT company, but we understand how physical security and organizational measures play a crucial role in your cyber resilience.

When an incident occurs, it is essential that access control, visitor procedures, and emergency plans work seamlessly. These elements are not isolated details, but links in a chain that NIS2 explicitly addresses. SERIS helps you strengthen those links. We start with awareness: what does NIS2 mean for your daily operations? We share insights, examples, and best practices from the industry, so that you not only know the rules but also understand how to apply them within your organization.

Next, we’ll take a look at your processes. What about access control, contingency plans, and the integration of physical and digital incident response procedures? We’ll help you align your policies with your practices. And because human behavior is often the weakest link, we provide training and scenario-based exercises to prepare your teams for critical situations. This way, security isn’t just a concept on paper, but an integral part of your culture.

Our expertise lies in strengthening physical resilience. We do this by deploying security guards, implementing access control, conducting surveillance, and providing support for events and critical processes. And we go beyond that. We bring parties in the supply chain together, share intelligence and best practices, and ensure that you have a clear understanding of dependencies. NIS2 is all about collaboration and demonstrable accountability, and we’re here to help you with that.

Cyber resilience starts today

NIS2 isn’t a requirement you can put off; it’s an opportunity to make your organization stronger and future-proof. By getting started now, you demonstrate that you have risks under control and that you’re a reliable partner for customers and suppliers. With the Cbw (NIS2) Control Framework as your guide and SERIS as your partner, you’ll take concrete steps toward demonstrable security and business continuity.

Want to know where your organization stands and what steps need to be taken? Schedule a meeting with us today. Together, we’ll make sure your organization is ready for the new reality.

Get your security ready for the future

The impact of the staffing shortage in the security sector is being felt everywhere. You may recognize the concerns about staffing levels, employee turnover, or reliance on a single supplier. Especially in these times, it’s important to choose a partner that offers certainty not just today, but tomorrow as well. SERIS is here to help you find the right solution. We’ll show you how we build teams that stand the test of time, even when the market is under pressure. With our approach, you’re assured of continuity, quality, and a committed partnership.

Would you like to learn how your organization can benefit from our vision and approach? Contact us today to schedule a personalized consultation. Together, we’ll ensure that your security remains future-proof, regardless of the challenges in the tight labor market.

Share this article

Related articles

  • Corporate Security During the Holiday Season

    Business Security During the Holiday Season: The Risk Isn't Outside, but Inside

    A report that went unaddressed for three days Last year, sometime during week 30, our security guard reported a damaged ... read more

    9-minute readPublished on: July 7, 2026
  • safety

    The Role of Security in Safety: More Than Just Security

    What is the role of security in safety? Safety and security. In English, these are two words, ... read more

    10.2 min readPublished on: July 1, 2026
  • Outsource reception services

    Outsourcing Reception Services: How Your Organization’s First Impression Is Formed

    What does a receptionist do when someone arrives? It’s 8:58 a.m. when the first appointment of the day arrives at ... read more

    7.9-minute readPublished on: June 25, 2026