What is NIS2 in plain English?
NIS2 is the European Union's updated cybersecurity directive for organizations that provide essential or important services. It replaced the original NIS Directive and expands the number of sectors expected to manage cybersecurity risk and report significant incidents.
The directive is implemented through national laws. In the Netherlands, that national law is the Cyberbeveiligingswet, which came into force on 15 August 2026. Other EU countries use their own implementation routes, authorities, forms, and sector guidance.
For SMBs, the practical message is simple: know whether you are in scope, know what your customers expect, and build a security workflow that can produce clear policies, owners, evidence, incident records, and management decisions.
Who may be affected?
NIS2 generally focuses on medium-sized and large entities in listed sectors, with special cases where smaller organizations can still be covered because of the service they provide or the risk they create. Dutch NCSC guidance explains that scope depends mainly on sector and organization size, and that some suppliers or connected companies may also feel the effect through the chain.
Even when an SMB is not directly regulated, it may still receive NIS2-related questions from customers, procurement teams, insurers, investors, or partners. That indirect pressure is often where smaller companies first notice NIS2.
- A customer asks for evidence of access control, backups, incident response, and supplier reviews.
- A procurement team asks whether you have an incident reporting process and a security owner.
- A larger customer asks how quickly you can notify them about incidents affecting their data or services.
- An insurer or auditor asks for written policies and evidence that controls operate in practice.
What areas does NIS2 expect organizations to address?
NIS2 is risk-based. It does not reduce security to one tool or one certificate. Article 21 includes a broad set of cybersecurity risk-management areas, and national guidance may provide more detail for each sector.
| Area | What this means in practice |
|---|---|
| Risk analysis | Know which systems, services, data, suppliers, and threats matter most. |
| Incident handling | Define intake, triage, ownership, escalation, evidence, reporting, RCA, and review. |
| Business continuity | Prepare backups, recovery plans, crisis coordination, and exercises. |
| Supply chain security | Assess direct suppliers and service providers that affect your services or data. |
| Vulnerability handling | Track weaknesses, patching, disclosure, and secure change management. |
| Control effectiveness | Review whether policies and controls actually work over time. |
| Cyber hygiene and training | Set expectations for safe behavior, awareness, and routine security practices. |
| Cryptography and encryption | Define when and how sensitive information is protected. |
| Access and asset management | Know what exists, who owns it, and who can access it. |
| Authentication and secure communications | Use appropriate MFA, secure communications, and emergency communication paths. |
How this topic cluster is organized
Use this guide as the starting point. Each supporting page answers one search intent clearly and links back here so the topic cluster stays coherent for visitors and search engines.
Start with scope
Read the SMB guide and the Netherlands Cyberbeveiligingswet page to understand direct and indirect impact.
Prepare reporting
Use the 24-hour reporting article and the incident response checklist to tighten incident records before time pressure starts.
Build control structure
Use the ISO 27001 comparison and supply-chain article to connect NIS2 expectations to practical policies, controls, owners, and evidence.
Use AI carefully
Use the AI article to see where IncidentAI can help with structure and summaries while keeping humans accountable.
Where aneo fits
Framework-Pro can help teams turn security requirements into tailored policy drafts, control mapping, implementation tasks, and evidence placeholders. It is useful when a team wants ISO 27001 or NIST CSF structure for NIS2 readiness work, while remembering that generated documents still need review, approval, and implementation.
IncidentAI can help teams capture incident intake, triage context, timelines, ownership, actions, management summaries, RCA notes, and audit trails. It does not decide legal reportability or replace management judgement, but it can make the factual incident record easier to maintain under pressure.
This guide is general information, not legal advice. NIS2 obligations depend on country, sector, service, size, and specific facts. Covered organizations should consult the relevant national authority and qualified advisers.
Quick FAQ
Does NIS2 apply to all SMBs?
No. NIS2 scope depends on sector, size, service type, and national implementation. Some SMBs may be directly covered, some may be indirectly affected through customers or suppliers, and some may not be in scope.
Is ISO 27001 required for NIS2?
NIS2 does not simply say every organization must be ISO 27001 certified. ISO 27001 can provide a useful management-system structure for risk, controls, policies, audits, and improvement, but legal obligations still come from NIS2 and national law.
What is the 24-hour NIS2 reporting rule?
NIS2 requires an early warning for significant incidents without undue delay and in any event within 24 hours after becoming aware of the incident. Further reporting normally follows at 72 hours and with a final report later.
Can AI make an organization NIS2 compliant?
No. AI can help structure tickets, summarize events, suggest next steps, draft RCA notes, map controls, and prepare management summaries. Humans remain responsible for decisions, legal assessment, reporting, approval, and implementation.
Official sources used
These pages were used for factual grounding. aneo summarizes them in original wording and does not provide legal advice.
