+31 88 8040 777
  Legal obligation, Q3 2025

NIS2 / Cyber Security Act: are you ready for the deadline?

The NIS2 directive has been transposed into Dutch law. Tens of thousands of organisations fall under it directly or indirectly, but only a small fraction are aware of it. ZETA helps you determine whether you are covered and which measures you are legally required to take.

Fines up to €10M
or 2% of global turnover
Reporting duty
within 24 hours
35 sectors
now obligated
50,000+
SMEs indirectly

Do I fall under NIS2 / the Cyber Security Act?

Not only large companies, but also medium-sized organisations and their suppliers are covered

Essential sectors (directly obligated)

Medium-sized and large organisations in these sectors are covered directly:

Energy
Transport
Banking
Drinking water
Healthcare
Digital infrastructure
ICT management (MSPs)
Wastewater
Public authorities
Space
Chemical industry
Food production

Indirectly obligated: suppliers

Do you supply organisations in the essential sectors? Then you are indirectly required to take adequate measures:

Software and IT suppliers to healthcare institutions
Hosting and cloud service providers to government
Transport logistics for essential sectors
Any supplier named in the contract of a NIS2-obligated organisation
Estimate: 10,000 companies directly obligated, 50,000 to 70,000 SMEs indirectly.

What do you need to arrange at a minimum?

The duty of care: eight mandatory measures

1. Risk analysis

Mapping out cyber risks, critical systems and vulnerabilities. ZETA carries out a thorough risk analysis and documents it in line with NIS2.

2. Incident policy

A formal Incident Response Plan (IRP), including reporting procedures, escalation lines and recovery processes. Mandatory testing at least twice a year.

3. Reporting duty (24 hours)

In the event of a significant incident, you must report it to the supervisor (NCSC/ACM) within 24 hours. ZETA supports the reporting and documentation.

4. Monitoring & logging

Continuous monitoring of your systems with audit trails. ZETA's MDR service fully meets the NIS2 monitoring obligation.

5. Supply chain security (suppliers)

Due diligence on your suppliers. Setting contractual requirements. ZETA helps with a supplier risk analysis and standard contract clauses.

6. Access security (MFA/IAM)

Strong authentication, least privilege, separated admin accounts. ZETA implements this in your Microsoft environment and network.

7. Encryption & data integrity

Data encrypted in transit and at rest. Backups tested and isolated. ZETA handles the technical implementation and verification.

8. Awareness & training

Mandatory security awareness training for all employees. Including phishing simulations and reporting for the supervisor.

How ZETA helps you become NIS2-compliant

NIS2 Quick Scan (gap analysis)

In a single day we determine which measures you already have and what is still missing. You receive a prioritised list with a time indication.

Implementation plan & roadmap

We draw up a realistic implementation plan, phased and tailored to your organisation and budget.

Technical implementation

MDR monitoring, M365 hardening, network security, encryption and access policy: ZETA takes care of the technology.

Documentation for the supervisor

Policy documents, risk registers, incident logs and evidence of measures: everything in order for any inspection.

What are the risks of non-compliance?

Fines up to €10 million
Or 2% of global annual turnover, whichever is higher.
Personal liability of directors
Management can be held personally liable in cases of demonstrable negligence.
Ban on holding a management position
A temporary ban on management duties for repeated or serious violations.
Reputational damage & loss of contracts
Clients and contracting authorities demand NIS2 compliance from suppliers.

Do not wait until the supervisor knocks

ZETA helps you become NIS2-compliant quickly and practically, without overkill and tailored to the size of your organisation.

Request a NIS2 Quick Scan View all compliance services

Request a NIS2 quick scan

Leave your details and we will contact you within 1 business day.