Preparing for NIS2: from compliance obligation to cyber resilience 

Cyber threats continue to increase, while legislation and regulations related to digital resilience are becoming increasingly stringent. With the introduction of the Cybersecurity Act (Cbw), the Dutch implementation of the NIS2 directive, organisations are faced with new requirements in the areas of governance, risk management, incident reporting, and supply chain security. 

For many organisations, this raises practical questions. Does my organisation fall under NIS2? Are our existing measures sufficient? Which risks should we address first? And how can we demonstrate compliance with the mandatory requirements? 
Effective preparation not only helps your organisation achieve compliance. It also creates opportunities to assign responsibilities more clearly, manage cyber risks more effectively, and strengthen digital resilience in a sustainable way. 

How do we help you? 

We help organisations translate NIS2 requirements into concrete, practical, and actionable steps. We start by determining whether and how NIS2 applies to your organisation. We then assess your current situation, including governance and risk management, incident processes, supplier management, and existing security measures.

Based on this assessment, we identify the most important areas for improvement and determine which actions should be prioritised. This results in a practical roadmap that enables your organisation to work systematically towards compliance and stronger cyber resilience. 

Our support does not stop with an assessment. Where required, we also assist with the design and implementation of measures, the strengthening of policies and processes, the establishment of governance structures, and the long-term embedding of cyber resilience throughout the organisation.

What do we offer?

  • NIS2 applicability analysis
  • NIS2 readiness assessment or gap analysis
  • Review of governance, risk management, and control measures
  • Roadmap with prioritised improvement actions
  • Support with policy development, processes, and incident management
  • Advice on supply chain risks and supplier management
  • Guidance on implementation and long-term embedding
  • Strategic support, such as CISO-as-a-Service 

What are the outcomes? 

Following our support, you will understand where your organisation stands in relation to the NIS2 requirements. You will gain insight into the key risks, areas for improvement, and priorities. This enables you to make informed decisions, clarify responsibilities across the organisation, and demonstrate the steps being taken towards compliance.

Our approach helps you see NIS2 not only as a legal obligation but also as an opportunity to strengthen cyber resilience in a sustainable way. In doing so, you gain greater control over digital risks, improve decision-making, and increase trust among customers, regulators, and supply chain partners. 

Benefits for your organisation

  • Clear insight into the impact of NIS2 on your organisation
  • Practical translation of legislation and regulations into concrete actions
  • Prioritisation of risks and improvement measures
  • Strengthened governance and management accountability
  • Better preparation for incident reporting and regulatory oversight
  • Greater control over cyber risks within the supply chain
  • A practical route towards sustainable cyber resilience 

Do you have a question?

Do you want to continue the conversation about the impact of the NIS2 directive on your organisation and how to strengthen your governance, risk management and digital resilience? Get in touch with us.

Why choose for Grant Thornton?

Grant Thornton Netherlands is a member of Grant Thornton International Ltd (GTIL), one of the world's largest networks (#7) of independent accounting and advisory firms, with 76,000 professionals in 156 markets. From eight Dutch offices, more than 700 professionals support our clients with advice and guidance in the fields of accountancy, tax, and (financial) advisory. We deliver world-class expertise in a way that seamlessly aligns with each client's unique situation. We operate from a solid foundation with a flexible and results-driven mindset.

Duurzaamheid in het mkb

Frequently asked questions

NIS2 is a European directive designed to strengthen cybersecurity and digital resilience across the European Union. The directive applies to organisations operating in essential and important sectors and sets requirements for areas including risk management, governance, incident reporting, and supply chain security. For organisations, NIS2 means that cybersecurity is no longer solely a technical matter and requires explicit attention from management. Management teams and boards must be able to demonstrate that appropriate measures have been implemented and that cyber risks are actively managed. The Dutch implementation of the NIS2 directive is set out in the Cybersecurity Act (Cbw). 

Whether NIS2 applies to your organisation depends in part on the sector in which you operate, the size of your organisation, and the services you provide. Organisations that do not fall directly under NIS2 may still be affected by the directive indirectly. For example, this may occur when they are suppliers to organisations that fall within the scope of NIS2.

In that situation, customers may impose stricter requirements relating to cybersecurity, reporting obligations, contractual agreements, or assurance. An applicability analysis helps provide clarity at an early stage on the impact of NIS2 on your organisation. 

Grant Thornton helps your organisation translate NIS2 requirements into practical and actionable measures. We first assess whether and how the directive applies. We then evaluate the current situation through a readiness assessment or gap analysis. 

Based on these findings, we provide insight into which measures are already in place, where improvements are required, and which actions should be prioritised. We can then support your organisation with governance, policies, processes, supply chain risk management, incident management, and implementation. This creates a practical route towards compliance and long-term cyber resilience. 

Yes. If your organisation falls under NIS2, compliance with the NIS2 directive remains mandatory. Existing standards and frameworks, such as ISO 27001, NEN 7510, DORA, or BIO, can be highly valuable because they already address many technical and organisational security measures. 

However, NIS2 introduces additional obligations, including requirements related to management accountability, reporting obligations, and supply chain risk management. A targeted gap analysis shows which components are already covered and where additional measures are required. This enables you to avoid duplication and build efficiently on existing compliance activities.