Applicability of the NIS2: A Practical Guide for the Netherlands

 September 8, 2026 | Blog | NL Law
1             Introduction

In our previous blog post, we introduced the NIS2 Directive (Directive (EU) 2022/2555) as the EU’s landmark legislation for strengthening cybersecurity across Europe. We outlined its key features, the differences from NIS1, and provided an overview of the transposition progress in Belgium, the Netherlands, and Luxembourg. Since then, all three Benelux countries have completed their transposition with the Netherlands being most recent; the Dutch Cybersecurity Act (Cyberbeveiligingswet, Cbw”) entered into force on 15 August 2026. Belgium and Luxembourg transposed the NIS2 Directive earlier, through the Belgium NIS2 law of 26 April 2024 (in force since 18 October 2024) and the Luxembourg NIS2 law of 5 May 2026 (in force since 10 May 2026).

With the Cbw now in force, this is the right moment to take a closer look at the Dutch implementation of NIS2. Whether an organisation falls within scope is not always immediately apparent and depends on several factors. This blog therefore sets out a practical three-step framework to help organisations assess whether the new cybersecurity regime applies to them. In this contribution, we focus on the Netherlands. Future editions of this blog series will also examine the Belgian and Luxembourg transposition laws and highlight key similarities and differences across the Benelux.

2             National transposition law: the Cyberbeveiligingswet

As said, the Netherlands adopted the Cyberbeveiligingswet (“Cbw”), which entered into force recently, on 15 August 2026. Entities that fall within scope by operation of law are subject to the Cbw’s rights and obligations from the date of entry into force, without any further designation or notification by the government.[1] The Cbw is supplemented by the Cybersecurity Decree (Cyberbeveiligingsbesluit) and sector-specific implementing regulations. These instruments specify requirements relating to registration, incident reporting and supervision. For example, the Cybersecurity Regulation for the Healthcare Sector (Cyberbeveiligingsregeling voor de Zorg (CbrZ)) includes sector-specific rules and designates the Dutch Healthcare and Youth Inspectorate as the competent supervisory authority. Similarly, the Regeling cyberbeveiliging EZK, issued by the Minister of Economic Affairs, further elaborates the duty of care and incident-reporting obligations for entities in the digital infrastructure, research, space, postal and courier, and manufacturing sectors.

Entities subject to the Cbw may interact with three types of public bodies: (i) the competent ministry responsible for the sector concerned, (ii) the designated Computer Security Incident Response Team (“CSIRT”), which provides operational cybersecurity support, and (iii) the competent supervisory authority responsible for monitoring compliance with the Cbw. While responsibility at the national level rests with the relevant ministry, supervisory and enforcement tasks are generally exercised by sector-specific regulators, including the Rijksinspectie Digitale Infrastructuur (RDI) for energy, digital infrastructure, ICT service management and most public sector entities, De Nederlandsche Bank (DNB) for banking, the Autoriteit Financiële Markten (AFM) for financial market infrastructure, and the Healthcare and Youth Inspectorate (IGJ) for healthcare and medical devices.

Operational cybersecurity support is provided through designated sectoral CSIRTs. In practice, the NCSC serves most sectors covered by the Cbw, while Z-CERT supports healthcare organisations and CERT-WM supports the water management sector. These CSIRTs provide incident response assistance, cybersecurity advisories, vulnerability information and threat-related alerts.

At the national level, the Minister of Justice and Security acts as the single point of contact under the Cbw and is responsible for cross-border and cross-sectoral coordination. In practice, these tasks are carried out by the NCSC, which also manages the national registration portal (MijnNCSC) through which entities within scope of the Cbw must register.

3             NIS2: THREE-STEP APPLICABILITY TEST

3.1          Assessment through step 1, 2 and 3

An entity falls within scope of the NIS2 (transpositions) if it satisfies three cumulative conditions:[2]

  • Sector test: the entity operates in a sector and as a type of entity listed in Annex I (highly critical sectors) or Annex II (other critical sectors) of NIS2;
  • Size test: the entity qualifies as at least a medium-sized enterprise under the EU rules for classifying enterprises by size, i.e. Commission Recommendation 2003/361/EC (the “Recommendation”);[3] and
  • Jurisdiction test: the entity provides its services or carries out its activities in the EU.

All three conditions must be met simultaneously. An entity that meets the sector test but falls below the size threshold is, in principle, out of scope – unless it qualifies as a size-independent category (see below). Conversely, a large entity that does not operate in a listed sector is out of scope.

3.2          Step 1: the sector test

The NIS2 applies only to entities operating in specifically listed sectors – but the list is broader than many organisations expect and also impacts the supply chain of such entities. In-scope entities are required to address cybersecurity risks throughout their supply chain and in their relationships with suppliers and service providers. As a result, entities that are themselves outside the formal scope of NIS2 may nevertheless be indirectly affected through contractual cybersecurity requirements, audit rights, incident notification obligations and other security measures imposed by regulated customers.

The first step is to establish whether the organisation operates in one of the sectors listed in Annex I or II. The NIS2 lists 11 highly critical sectors in Annex I: (i) energy, (ii) transport, (iii) banking, (iv) financial market infrastructure, (v) health, (vi) drinking water, (vii) waste water, (viii) digital infrastructure, (ix) ICT service management, (x) public administration and (xi) space. Seven sectors are listed as other critical sectors in Annex II NIS2: (i) postal and courier services, (ii) waste management, (iii) manufacturing, production and distribution of chemical substances, (iv) food production, (v) manufacturing, (vi) digital providers and (vii) research. These sectors and the interpretation questions they raise are addressed in a dedicated blog post.

Falling within a listed sector alone is not sufficient by definition; the entity must also qualify as a type of entity that provides services or carries out activities specifically listed for that sector in Annex I or II.[4] For example, the research sector in Annex II captures “research organisations”, defined as entities whose primary objective is to conduct applied research or experimental development with a view to exploiting the results for commercial purposes, but excluding educational institutions. In the health sector, Annex I lists specific entity types – such as healthcare providers, EU reference laboratories, and manufacturers of medicines, pharmaceuticals or public health emergency critical devices – rather than covering ‘healthcare’ generically.

An entity may operate across multiple sectors listed in NIS2. Importantly, if an entity qualifies as an essential entity under one sector (e.g. energy, Annex I) but as an important entity under another (e.g. waste management, Annex II), it is classified as an essential entity overall.

Finally, it should be noted that certain national implementation regimes provide for exceptions to the ordinary classification framework. In the Netherlands, for example, specific entities may be designated as essential entities under Article 9 Cbw, as discussed further below.

Managed services providers (IT)

Particular focus and attention is required when it comes to the category of ICT-services providers, since this category (i) may also capture intra-group service providers and (ii) has its own jurisdictional rules. Annex I NIS2 lists the ICT service management sector, which captures managed service providers, defined broadly as an entity that provides services related to the installation, management, operation or maintenance of ICT products, networks, infrastructure, applications, or any other network and information systems. Critically, this definition does not distinguish between services provided to third parties and services provided to other entities within the same group, meaning that a group entity that procures ICT services and makes them available to affiliates may classify as a managed service provider and, as such, as an essential entity subject to the most rigorous supervisory regime. We address the practical implications of this for group structures across the Benelux, including the resulting jurisdiction consequences, in our dedicated blog post on NIS2 sectors.

Even where suppliers do not themselves qualify as NIS2 entities, they may nevertheless be affected indirectly through the supply-chain obligations imposed on regulated entities. Managed service providers, cloud providers, software vendors and other ICT suppliers are increasingly required by their customers to comply with cybersecurity requirements, provide information regarding their own supply chains, cooperate in incident response procedures and accept contractual audit rights.

3.3          Step 2: the size test

Enterprise size: headcount and financial thresholds

Once an entity passes the sector test, it must be assessed whether it meets the size thresholds set out in the NIS2, read in conjunction with the SME Recommendation.[5] The assessment is based on two criteria: headcount and financial data. Headcount is expressed in Annual Work Units (“AWU”), meaning the number of persons who worked full-time within the enterprise during the entire reference year; part-time and seasonal workers count as fractions of an AWU.

An entity must generally be classified as at least a medium-sized enterprise to fall within scope. Small enterprises are enterprises that employ fewer than 50 persons and whose annual turnover or annual balance sheet total does not exceed EUR 10 million. Such entities are not in scope of the NIS2, subject to the size-independent categories and national designation mechanisms (see below). Medium-sized enterprises are defined as enterprises that employ fewer than 250 persons and either have an annual turnover that does not exceed EUR 50 million, or an annual balance sheet not exceeding EUR 43 million. Entities with 250 or more employees are classified as large enterprises and fall within scope regardless of their financial figures.

This classification is not necessarily reassessed every year the moment an entity’s figures move above or below a threshold. Under the SME Recommendation, an entity only gains or loses its SME classification if the relevant thresholds are crossed in two consecutive accounting periods.[6]

Aggregation of data

The size thresholds are not assessed based on the individual entity alone. Under the SME Recommendation, headcount, annual turnover, and balance sheet total must be calculated taking into account the data of any linked or partner enterprises. This distinction is important:

  • Linked enterprises are those where one enterprise (i) holds a majority of voting rights in another, (ii) can appoint or remove a majority of its board, (iii) exercises dominant influence under a contract or its articles of association, or (iv) alone controls a majority of another enterprise’s voting rights under an agreement with its other shareholders or members.[7] Indirect links through intermediary enterprises also count. Linked enterprises’ figures are added in full (100%).
  • Partner enterprises exist where one enterprise holds 25% or more of the capital or voting rights of another, without being linked.[8] Their figures are added pro rata to the (highest) percentage held, plus 100% of any enterprise linked to that partner and a pro rata share of any partner enterprise immediately up- or downstream of a linked enterprise.[9]

In practice, this means that a local entity with only 25 employees and limited turnover can still classify as a large enterprise under NIS2 if its parent company or other group entities push the aggregated figures above the thresholds. It is therefore recommended that organisations map their group ownership and control relationships before concluding that they fall outside the scope of the NIS2.

Size-independent categories

Certain entities fall within scope regardless of their size.[10] These size-independent categories include: (a) providers of public electronic communications networks or publicly available electronic communications services; (b) trust service providers; (c) top-level domain (TLD) name registries and DNS service providers; (d) domain name registration service providers; and (e) certain public administration entities. In these categories, even micro and small enterprises are captured.

Importantly, managed service providers and managed security service providers are not among the size-independent categories and must therefore satisfy the size thresholds to fall within scope.

In addition to the size-independent categories under NIS2, the Cbw contains additional provisions allowing certain entities to fall within scope regardless of their size. Article 9 Cbw empowers the competent minister to designate Annex I and Annex II entities as essential entities where they perform a particularly critical societal or economic function. In addition, Article 12 Cbw classifies certain providers of electronic communications networks, electronic communications services and trust services as important entities irrespective of their size.

3.4          Step 3: the jurisdiction test

If an entity satisfies both the sector test and the size test, the final question is which Member State’s legislation governs its obligations. The main rule is straightforward: an entity falls under the jurisdiction of the Member State in which it is established; the Cbw for the Netherlands, la loi NIS2 for Belgium, and the Luxembourg NIS2 law for Luxembourg. An entity established or providing services in more than one Member State falls under the separate, concurrent jurisdiction of each.[11]

An important exception applies to certain digital service providers, including managed service providers, and managed security service providers, among others.[12] For these entities, jurisdiction follows their main establishment in the EU (where cybersecurity risk-management decisions are primarily taken), not their place of incorporation. This is particularly relevant for intra-group managed service providers (see above); a group entity distributing ICT services across the Benelux may fall under the Cbw simply because those decisions are taken in the Netherlands.

Jurisdiction is assessed per entity, not per group: an entity established in Luxembourg remains subject to the Luxembourg NIS2 law even if its parent is governed by the Cbw.

4             Conclusion and next steps

Determining whether an organisation falls within scope of NIS2 is often less straightforward than it appears. Sector-specific definitions, group-wide size calculations, size-independent categories and jurisdiction rules can all affect the outcome. A careful scoping assessment is therefore the essential first step towards compliance. In our next blog, we take a closer look at the Annex I and II sectors and the practical interpretation issues that arise in determining whether an entity falls within scope. In following NIS2 blog posts, we will also explore the Belgian and Luxembourg implementing legislation and highlight key similarities and differences across the Benelux.

If you need advice on navigating the Cbw or other NIS2 implementing legislation in the Benelux, our team is here to help.

 

[1]              Articles 8 and 12 Cbw.

[2]              Article 2(1) NIS2.

[3]              Commission Recommendation of 6 May 2003 concerning the definition of micro, small and medium-sized enterprises.

[4]              Article 6(41) NIS2.

[5]              Article 2(1) NIS2; Commission Recommendation of 6 May 2003 concerning the definition of micro, small and medium-sized enterprises (“SME Recommendation”).

[6]              Article 4(2) of the Annex to the Recommendation.

[7]              Article 3(3) of the Annex to the Recommendation.

[8]              Article 3(2) of the Annex to the Recommendation.

[9]              Article 6 of the Annex to the Recommendation.

[10]            Article 2(2) and (4) NIS2.

[11]            Article 26(1)(a) NIS2.

[12]            Article 26(1)(b) NIS2.

1             Introduction

In our previous blog post, we introduced the NIS2 Directive (Directive (EU) 2022/2555) as the EU’s landmark legislation for strengthening cybersecurity across Europe. We outlined its key features, the differences from NIS1, and provided an overview of the transposition progress in Belgium, the Netherlands, and Luxembourg. Since then, all three Benelux countries have completed their transposition with the Netherlands being most recent; the Dutch Cybersecurity Act (Cyberbeveiligingswet, Cbw”) entered into force on 15 August 2026. Belgium and Luxembourg transposed the NIS2 Directive earlier, through the Belgium NIS2 law of 26 April 2024 (in force since 18 October 2024) and the Luxembourg NIS2 law of 5 May 2026 (in force since 10 May 2026).

With the Cbw now in force, this is the right moment to take a closer look at the Dutch implementation of NIS2. Whether an organisation falls within scope is not always immediately apparent and depends on several factors. This blog therefore sets out a practical three-step framework to help organisations assess whether the new cybersecurity regime applies to them. In this contribution, we focus on the Netherlands. Future editions of this blog series will also examine the Belgian and Luxembourg transposition laws and highlight key similarities and differences across the Benelux.

2             National transposition law: the Cyberbeveiligingswet

As said, the Netherlands adopted the Cyberbeveiligingswet (“Cbw”), which entered into force recently, on 15 August 2026. Entities that fall within scope by operation of law are subject to the Cbw’s rights and obligations from the date of entry into force, without any further designation or notification by the government.[1] The Cbw is supplemented by the Cybersecurity Decree (Cyberbeveiligingsbesluit) and sector-specific implementing regulations. These instruments specify requirements relating to registration, incident reporting and supervision. For example, the Cybersecurity Regulation for the Healthcare Sector (Cyberbeveiligingsregeling voor de Zorg (CbrZ)) includes sector-specific rules and designates the Dutch Healthcare and Youth Inspectorate as the competent supervisory authority. Similarly, the Regeling cyberbeveiliging EZK, issued by the Minister of Economic Affairs, further elaborates the duty of care and incident-reporting obligations for entities in the digital infrastructure, research, space, postal and courier, and manufacturing sectors.

Entities subject to the Cbw may interact with three types of public bodies: (i) the competent ministry responsible for the sector concerned, (ii) the designated Computer Security Incident Response Team (“CSIRT”), which provides operational cybersecurity support, and (iii) the competent supervisory authority responsible for monitoring compliance with the Cbw. While responsibility at the national level rests with the relevant ministry, supervisory and enforcement tasks are generally exercised by sector-specific regulators, including the Rijksinspectie Digitale Infrastructuur (RDI) for energy, digital infrastructure, ICT service management and most public sector entities, De Nederlandsche Bank (DNB) for banking, the Autoriteit Financiële Markten (AFM) for financial market infrastructure, and the Healthcare and Youth Inspectorate (IGJ) for healthcare and medical devices.

Operational cybersecurity support is provided through designated sectoral CSIRTs. In practice, the NCSC serves most sectors covered by the Cbw, while Z-CERT supports healthcare organisations and CERT-WM supports the water management sector. These CSIRTs provide incident response assistance, cybersecurity advisories, vulnerability information and threat-related alerts.

At the national level, the Minister of Justice and Security acts as the single point of contact under the Cbw and is responsible for cross-border and cross-sectoral coordination. In practice, these tasks are carried out by the NCSC, which also manages the national registration portal (MijnNCSC) through which entities within scope of the Cbw must register.

3             NIS2: THREE-STEP APPLICABILITY TEST

3.1          Assessment through step 1, 2 and 3

An entity falls within scope of the NIS2 (transpositions) if it satisfies three cumulative conditions:[2]

  • Sector test: the entity operates in a sector and as a type of entity listed in Annex I (highly critical sectors) or Annex II (other critical sectors) of NIS2;
  • Size test: the entity qualifies as at least a medium-sized enterprise under the EU rules for classifying enterprises by size, i.e. Commission Recommendation 2003/361/EC (the “Recommendation”);[3] and
  • Jurisdiction test: the entity provides its services or carries out its activities in the EU.

All three conditions must be met simultaneously. An entity that meets the sector test but falls below the size threshold is, in principle, out of scope – unless it qualifies as a size-independent category (see below). Conversely, a large entity that does not operate in a listed sector is out of scope.

3.2          Step 1: the sector test

The NIS2 applies only to entities operating in specifically listed sectors – but the list is broader than many organisations expect and also impacts the supply chain of such entities. In-scope entities are required to address cybersecurity risks throughout their supply chain and in their relationships with suppliers and service providers. As a result, entities that are themselves outside the formal scope of NIS2 may nevertheless be indirectly affected through contractual cybersecurity requirements, audit rights, incident notification obligations and other security measures imposed by regulated customers.

The first step is to establish whether the organisation operates in one of the sectors listed in Annex I or II. The NIS2 lists 11 highly critical sectors in Annex I: (i) energy, (ii) transport, (iii) banking, (iv) financial market infrastructure, (v) health, (vi) drinking water, (vii) waste water, (viii) digital infrastructure, (ix) ICT service management, (x) public administration and (xi) space. Seven sectors are listed as other critical sectors in Annex II NIS2: (i) postal and courier services, (ii) waste management, (iii) manufacturing, production and distribution of chemical substances, (iv) food production, (v) manufacturing, (vi) digital providers and (vii) research. These sectors and the interpretation questions they raise are addressed in a dedicated blog post.

Falling within a listed sector alone is not sufficient by definition; the entity must also qualify as a type of entity that provides services or carries out activities specifically listed for that sector in Annex I or II.[4] For example, the research sector in Annex II captures “research organisations”, defined as entities whose primary objective is to conduct applied research or experimental development with a view to exploiting the results for commercial purposes, but excluding educational institutions. In the health sector, Annex I lists specific entity types – such as healthcare providers, EU reference laboratories, and manufacturers of medicines, pharmaceuticals or public health emergency critical devices – rather than covering ‘healthcare’ generically.

An entity may operate across multiple sectors listed in NIS2. Importantly, if an entity qualifies as an essential entity under one sector (e.g. energy, Annex I) but as an important entity under another (e.g. waste management, Annex II), it is classified as an essential entity overall.

Finally, it should be noted that certain national implementation regimes provide for exceptions to the ordinary classification framework. In the Netherlands, for example, specific entities may be designated as essential entities under Article 9 Cbw, as discussed further below.

Managed services providers (IT)

Particular focus and attention is required when it comes to the category of ICT-services providers, since this category (i) may also capture intra-group service providers and (ii) has its own jurisdictional rules. Annex I NIS2 lists the ICT service management sector, which captures managed service providers, defined broadly as an entity that provides services related to the installation, management, operation or maintenance of ICT products, networks, infrastructure, applications, or any other network and information systems. Critically, this definition does not distinguish between services provided to third parties and services provided to other entities within the same group, meaning that a group entity that procures ICT services and makes them available to affiliates may classify as a managed service provider and, as such, as an essential entity subject to the most rigorous supervisory regime. We address the practical implications of this for group structures across the Benelux, including the resulting jurisdiction consequences, in our dedicated blog post on NIS2 sectors.

Even where suppliers do not themselves qualify as NIS2 entities, they may nevertheless be affected indirectly through the supply-chain obligations imposed on regulated entities. Managed service providers, cloud providers, software vendors and other ICT suppliers are increasingly required by their customers to comply with cybersecurity requirements, provide information regarding their own supply chains, cooperate in incident response procedures and accept contractual audit rights.

3.3          Step 2: the size test

Enterprise size: headcount and financial thresholds

Once an entity passes the sector test, it must be assessed whether it meets the size thresholds set out in the NIS2, read in conjunction with the SME Recommendation.[5] The assessment is based on two criteria: headcount and financial data. Headcount is expressed in Annual Work Units (“AWU”), meaning the number of persons who worked full-time within the enterprise during the entire reference year; part-time and seasonal workers count as fractions of an AWU.

An entity must generally be classified as at least a medium-sized enterprise to fall within scope. Small enterprises are enterprises that employ fewer than 50 persons and whose annual turnover or annual balance sheet total does not exceed EUR 10 million. Such entities are not in scope of the NIS2, subject to the size-independent categories and national designation mechanisms (see below). Medium-sized enterprises are defined as enterprises that employ fewer than 250 persons and either have an annual turnover that does not exceed EUR 50 million, or an annual balance sheet not exceeding EUR 43 million. Entities with 250 or more employees are classified as large enterprises and fall within scope regardless of their financial figures.

This classification is not necessarily reassessed every year the moment an entity’s figures move above or below a threshold. Under the SME Recommendation, an entity only gains or loses its SME classification if the relevant thresholds are crossed in two consecutive accounting periods.[6]

Aggregation of data

The size thresholds are not assessed based on the individual entity alone. Under the SME Recommendation, headcount, annual turnover, and balance sheet total must be calculated taking into account the data of any linked or partner enterprises. This distinction is important:

  • Linked enterprises are those where one enterprise (i) holds a majority of voting rights in another, (ii) can appoint or remove a majority of its board, (iii) exercises dominant influence under a contract or its articles of association, or (iv) alone controls a majority of another enterprise’s voting rights under an agreement with its other shareholders or members.[7] Indirect links through intermediary enterprises also count. Linked enterprises’ figures are added in full (100%).
  • Partner enterprises exist where one enterprise holds 25% or more of the capital or voting rights of another, without being linked.[8] Their figures are added pro rata to the (highest) percentage held, plus 100% of any enterprise linked to that partner and a pro rata share of any partner enterprise immediately up- or downstream of a linked enterprise.[9]

In practice, this means that a local entity with only 25 employees and limited turnover can still classify as a large enterprise under NIS2 if its parent company or other group entities push the aggregated figures above the thresholds. It is therefore recommended that organisations map their group ownership and control relationships before concluding that they fall outside the scope of the NIS2.

Size-independent categories

Certain entities fall within scope regardless of their size.[10] These size-independent categories include: (a) providers of public electronic communications networks or publicly available electronic communications services; (b) trust service providers; (c) top-level domain (TLD) name registries and DNS service providers; (d) domain name registration service providers; and (e) certain public administration entities. In these categories, even micro and small enterprises are captured.

Importantly, managed service providers and managed security service providers are not among the size-independent categories and must therefore satisfy the size thresholds to fall within scope.

In addition to the size-independent categories under NIS2, the Cbw contains additional provisions allowing certain entities to fall within scope regardless of their size. Article 9 Cbw empowers the competent minister to designate Annex I and Annex II entities as essential entities where they perform a particularly critical societal or economic function. In addition, Article 12 Cbw classifies certain providers of electronic communications networks, electronic communications services and trust services as important entities irrespective of their size.

3.4          Step 3: the jurisdiction test

If an entity satisfies both the sector test and the size test, the final question is which Member State’s legislation governs its obligations. The main rule is straightforward: an entity falls under the jurisdiction of the Member State in which it is established; the Cbw for the Netherlands, la loi NIS2 for Belgium, and the Luxembourg NIS2 law for Luxembourg. An entity established or providing services in more than one Member State falls under the separate, concurrent jurisdiction of each.[11]

An important exception applies to certain digital service providers, including managed service providers, and managed security service providers, among others.[12] For these entities, jurisdiction follows their main establishment in the EU (where cybersecurity risk-management decisions are primarily taken), not their place of incorporation. This is particularly relevant for intra-group managed service providers (see above); a group entity distributing ICT services across the Benelux may fall under the Cbw simply because those decisions are taken in the Netherlands.

Jurisdiction is assessed per entity, not per group: an entity established in Luxembourg remains subject to the Luxembourg NIS2 law even if its parent is governed by the Cbw.

4             Conclusion and next steps

Determining whether an organisation falls within scope of NIS2 is often less straightforward than it appears. Sector-specific definitions, group-wide size calculations, size-independent categories and jurisdiction rules can all affect the outcome. A careful scoping assessment is therefore the essential first step towards compliance. In our next blog, we take a closer look at the Annex I and II sectors and the practical interpretation issues that arise in determining whether an entity falls within scope. In following NIS2 blog posts, we will also explore the Belgian and Luxembourg implementing legislation and highlight key similarities and differences across the Benelux.

If you need advice on navigating the Cbw or other NIS2 implementing legislation in the Benelux, our team is here to help.

 

[1]              Articles 8 and 12 Cbw.

[2]              Article 2(1) NIS2.

[3]              Commission Recommendation of 6 May 2003 concerning the definition of micro, small and medium-sized enterprises.

[4]              Article 6(41) NIS2.

[5]              Article 2(1) NIS2; Commission Recommendation of 6 May 2003 concerning the definition of micro, small and medium-sized enterprises (“SME Recommendation”).

[6]              Article 4(2) of the Annex to the Recommendation.

[7]              Article 3(3) of the Annex to the Recommendation.

[8]              Article 3(2) of the Annex to the Recommendation.

[9]              Article 6 of the Annex to the Recommendation.

[10]            Article 2(2) and (4) NIS2.

[11]            Article 26(1)(a) NIS2.

[12]            Article 26(1)(b) NIS2.