NIS2

NIS2 (EU 2022/2555): EU cybersecurity directive for essential and important entities, with 24-hour incident reporting and management liability.

NIS2 (Directive (EU) 2022/2555) is the European directive on cybersecurity of networks and information systems (NIS) for essential and important entities across many sectors. It entered into force in January 2023, with a transposition deadline for member states of 17 October 2024 and application of the national transposing measures from 18 October 2024. NIS2 widens the scope of the original NIS directive to many more sectors listed in its Annexes I and II. Annex I includes sectors such as energy, transport, banking, financial market infrastructures, health, drinking water, digital infrastructure and public administration. Annex II includes sectors such as postal and courier services, waste management, chemicals, food production and manufacturing. The directive introduces stricter risk management and incident reporting duties (early warning within 24 hours) plus personal accountability for management. Entities in Annex I sectors that are large are classed as essential entities; entities in Annex I sectors that are medium-sized, and entities in Annex II sectors that are medium-sized or large, are classed as important entities. These size categories follow the EU SME definitions in Commission Recommendation 2003/361/EC. Small and micro entities are generally out of scope, except in specific cases such as sole providers in a member state, public administration bodies, providers of public electronic communications networks or publicly available electronic communications services, providers of top-level domain names and DNS services, and trust service providers - all of which remain in scope regardless of size under Article 2(2). Among trust service providers, Article 3(1)(b) classes qualified trust service providers - including QTSPs like Cleverbase - as essential entities regardless of size, while non-qualified trust service providers are in scope regardless of size as well, under Article 2(2)(a)(ii). Their class then follows the general rule: a large non-qualified provider is an essential entity under Article 3(1)(a), and every other one - medium-sized, small or micro - is an important entity under Article 3(2). Being small is therefore no way out of NIS2 for a trust service provider; it only changes which of the two classes you land in. See the trust service and QTSP entries for how eIDAS defines these two terms. Article 21 sets out minimum risk management measures that in-scope entities must implement, including supply chain security, multi-factor authentication, encryption, business continuity planning and backups. Implementing Regulation (EU) 2024/2690 further specifies these Article 21 requirements in more technical detail, for a defined set of entity types: DNS service providers, TLD name registries, cloud computing, data centre and content delivery network providers, managed service and managed security service providers, online marketplaces, search engines, social networking platforms and trust service providers. Under Article 3(4), member states must require in-scope entities to submit identifying information to the competent authority; the exact registration process depends on how each member state implements this.

EU member states had to transpose NIS2 into national law by 17 October 2024, after which it replaces the original NIS directive. The Netherlands missed that deadline: the Wbni (Wet beveiliging netwerk- en informatiesystemen), which implemented the original NIS directive, remains in force until the Cyberbeveiligingswet takes effect. The Eerste Kamer voted on the Cyberbeveiligingswet on 6-7 July 2026, and entry into force is expected on 15 August 2026, with the RDI designated as supervisor for digital infrastructure. Because the transposition is delayed, entities newly brought into scope by NIS2 in principle do not yet have directly binding obligations under Dutch law; entities already covered by the Wbni continue to be bound by its existing rules in the meantime. For Cleverbase, NIS2 obligations stack on top of the eIDAS and ETSI security requirements it already meets as a QTSP. For QTSPs specifically, eIDAS Article 19, which used to set trust service provider security and incident-reporting duties, was deleted by NIS2 Article 42 with effect from 18 October 2024; the equivalent duties now sit in eIDAS Article 24 (added by Regulation (EU) 2024/1183), which applies directly as an EU regulation and does not depend on the Cyberbeveiligingswet's entry into force. In practice, Cleverbase continues to apply the ETSI-based security and incident-reporting practices that both regimes are built on.

Frequently asked questions

Back to glossary