NIS2 is in effect: can you demonstrate your organization is cyber resilient?

In recent years, NIS2 has mainly been about awareness, impact analyses and preparations. The phase has now begun in which organizations must not only make plans, but above all demonstrate that they’re actually implementing them. The question is no longer: ‘Do we need to do something with NIS2?’ but: ‘Can we demonstrate that we are managing our cyber risks?’.

NIS2 marks a fundamental change in the way organizations deal with cybersecurity. It’s no longer solely an IT matter, but a management responsibility that directly affects risk management, business continuity, supplier management and compliance.

In the Netherlands, an estimated 8,000 to 10,000 organizations are directly subject to the Cybersecurity Act (Cyberbeveiligingswet), the Dutch implementation of NIS2, which came into force on 15 August 2026. The indirect impact is even greater: an estimated 50,000 to 60,000 suppliers, including many small and medium sized businesses, will face stricter cybersecurity requirements from customers and clients through supply chain due diligence obligations.

From compliance to resilience

Many organizations still primarily approach NIS2 as a legal requirement. Although compliance is important, its real value lies in structurally strengthening digital resilience and making cyber risks manageable. This is not only about technology, but also about governance, processes, people and the supply chain in which organizations operate. Organizations that successfully implement NIS2 treat cybersecurity as a strategic business risk that is directly connected to business continuity, reputation and trust in the market.

Management at the helm

One of the most important changes under NIS2 is the explicit responsibility of management. Whereas cybersecurity was often delegated to IT or security in the past, NIS2 requires active and demonstrable involvement from executive and management teams. Leaders must understand cyber risks, oversee measures and participate in decision making on digital resilience. This shifts cybersecurity from an operational IT issue to a responsibility at the management level. The topic should be a structural part of management meetings, risk assessments and strategic decision making.

The supply chain becomes the new challenge

For many organizations, the greatest challenge is not only within their own walls, but also in the supply chain. NIS2 requires risks at suppliers, partners and service providers to be actively managed. A vulnerability at a supplier can have just as much impact as an incident within the organization itself. Organizations that are not directly subject to NIS2 are also finding that customers increasingly ask for evidence of cybersecurity. Demonstrable information security is therefore becoming a prerequisite for many suppliers to continue doing business. Certifications, assessments and independent audits are playing an increasingly important role in this.

What can you do in practice?

Now that NIS2 has entered the implementation phase, the focus is on being able to demonstrate compliance. At a minimum, organizations should work on:

  • An up to date risk analysis
  • A formal cybersecurity policy
  • Incident management and reporting procedures
  • Business continuity and disaster recovery
  • Supplier and supply chain risk management
  • Clear roles, responsibilities and governance
  • Awareness and training for employees, management and executives

In addition, it’s important to periodically assess whether the measures taken are actually effective. Readiness assessments, gap analyses and independent audits help identify shortcomings and implement targeted improvements.

How Kiwa can support you

Kiwa supports organizations in assessing and demonstrating their cyber resilience, including through:

For organizations that already have ISO 27001 certification, the good news is that many of the foundations are already in place. These include risk management, policies, controls and continual improvement. This can make the transition to NIS2 significantly faster and more manageable. At the same time, NIS2 goes beyond ISO 27001 in certain areas, such as management responsibility, incident reporting requirements and supply chain responsibility. ISO 27001 is therefore not the endpoint, but it’s an excellent starting point for demonstrable NIS2 compliance.

A competitive advantage for the future

Organizations that invest in NIS2 now are not only complying with laws and regulations. They are also strengthening the trust of customers, partners, shareholders and regulators. In tenders and supply chains, demonstrable cyber resilience is increasingly becoming a selection criterion. Cybersecurity is therefore shifting from a cost item to a differentiator. NIS2 is not a project with an end date, but a continuous process of risk management and improvement. Organizations that invest today in governance, supplier management and cyber resilience are not only building compliance, but also trust, continuity and competitiveness. The question is therefore not whether cybersecurity is important, but whether you can demonstrate that your organization has control over it.

Contact

Learn more?

Would you like to know more about this topic? Call us at +31 (0)88 998 33 70 or fill out the contact form. Our experts will be happy to help you!

Go to contact form