NIS2 compliance step-by-step plan
Is your organisation ready for the new NIS2 guidelines? Cyber threats are increasing and organisations depend more and more on systems, networks, software and digital infrastructure. With NIS2, Europe wants cybersecurity to become a high priority, not only for the IT department but also for directors.
Although NIS2 is not mandatory for every organisation, it provides valuable guidance for protecting critical business processes. This plan helps you find a practical approach and understand the main NIS2 obligations so you are prepared, whether or not the regulations apply to you.
The main steps are:
- Understand the scope and obligations of NIS2.
- Carry out a risk analysis.
- Implement appropriate security measures.
- Establish a systematic policy for business continuity and cybersecurity.
- Register with the NCSC.
- Continuously improve and monitor.
Step 1: Understand the scope and obligations of NIS2
NIS2 aims to strengthen the resilience of essential and important organisations. This concerns not only digital risks but also physical threats or other operational problems that could affect the availability, integrity or confidentiality of critical services. If your organisation falls under these guidelines, you must comply with duties of care, reporting and registration, and with supervision.
Use the NCSC's NIS2 self-assessment to check whether your organisation falls under these guidelines. Important: organisations fall under NIS2 only if classified as “essential” or “important”, based on their impact on society and the economy. Even if your organisation is not directly covered by NIS2, you may indirectly face NIS2 requirements as a supplier or service provider to an NIS2-regulated entity. These organisations must ensure the security of their supply chain and can therefore impose requirements on your security measures.
Even if you are not required to comply with NIS2, the guidelines are valuable for getting your business continuity and cybersecurity in order. This demonstrates responsible entrepreneurship and increases stakeholder confidence.
Step 2: Carry out a risk analysis
The first step towards NIS2 compliance is a detailed risk analysis. This provides insight into the specific threats your organisation could face and helps identify vulnerabilities in your business processes. This analysis covers not only digital threats such as cyberattacks, but also physical threats and operational risks.
Approach to a risk analysis:
- Protect what matters: identify the business processes critical to your organisation's continuity, in both digital systems and physical infrastructure.
- Map threats and vulnerabilities: gather current threat intelligence and map both digital and physical vulnerabilities.
- Assess your current defences: analyse the security and continuity measures already in place and check whether they provide sufficient protection against the threats identified.
It is important to emphasise that this risk analysis must be updated regularly, because NIS2 requires a cyclical risk management process that keeps adapting to new threats.
Step 3: Implement appropriate security measures
After your risk analysis, it is time to take the right security measures. These must ensure the continuity of your critical services and protect your business information and processes. This includes both digital security measures and managing physical risks.
Essential measures:
- Basic cybersecurity measures: ensure you have implemented basic measures such as secure configurations, network segmentation and software updates. Also consider measures such as multifactor authentication and encrypted communications.
- Physical security and the supply chain: identify suppliers and physical risks that could directly affect your critical business processes. Make clear security agreements and monitor them regularly.
- Incident response plan: establish a plan to respond quickly and effectively to both cyber incidents and other disruptions that could affect business operations. Incidents with significant consequences for operations must be reported promptly, usually within 24 hours. This must be properly documented in accordance with NIS2's reporting obligation.
Step 4: Establish a systematic policy for business continuity and cybersecurity
A consistent business continuity and cybersecurity policy ensures your organisation takes the right measures and regularly evaluates and adapts them to new physical and digital risks.
Practical advice:
- Use frameworks such as ISO 27001 and SOC 2:
- ISO 27001 provides a framework for risk management and continuous improvement of information security, and is ideal for meeting NIS2 obligations.
- SOC 2 is particularly useful for IT and cloud service providers. It helps ensure security, availability and confidentiality, which is crucial when supplying NIS2-regulated entities.
- Develop a threat intelligence programme:
Collect and analyse threat intelligence from reliable sources such as the NCSC and commercial reports. Use this information to improve your security measures continuously and address threats proactively. - Ensure continuous improvement and compliance:
Review the policy regularly and document everything to meet audit and compliance requirements. Frameworks such as ISO 27001 and SOC 2 support this process and help with compliance with the NIS2 guidelines.
Step 5: Register with the NCSC
Essential and important organisations must register with the National Cyber Security Centre (NCSC), https://www.ncsc.nl/over-ncsc/documenten/publicaties/2024/oktober/08/checklist-registreren. This registration is a legal obligation under NIS2 and helps map the resilience of critical infrastructure.
Step-by-step registration process: Gather the required details, such as your organisation's name, address, sector and current contact details, and register through Mijn.NCSC.nl.
Step 6: Continuous improvement and monitoring
Cybersecurity and business continuity are ongoing processes. It is important to map vulnerabilities continuously and evaluate your security and continuity measures. Regular checks and information gathering help identify and address new threats promptly, in both cybersecurity and operational risks.
Consider implementing a SIEM/SOC solution for real-time monitoring of your systems and processes, so you can detect suspicious activities and physical disruptions immediately.
Need help with NIS2?
At SECWATCH, we provide independent advice to guide your organisation in the right direction on NIS2. During an NIS2 Check-in Call, we discuss which measures are relevant to your business and how to develop the right mindset. We help you translate the complex requirements into practical actions that have a real impact.
