thinQit|Nisha
|
NIS2 is law in the Netherlands since 15 August 2026, through the Cyberbeveiligingswet.
Roughly half of the 8,000 to 10,000 organisations in scope missed the registration deadline for the entiteitenregister.
Six pillars of NIS2 readiness
From does NIS2 apply to you, to readiness you can prove.
Does NIS2 apply to you?
Free scope check
Answer a few questions in chat and Nisha maps your organisation against the Bijlage 1 and 2 sectors and the size thresholds of the Cyberbeveiligingswet. A clear outcome, no obligations.
- Free check in chat
- Bijlage 1 and 2 sector mapping
- Size and turnover thresholds applied
- Essential or important classification
Readiness cockpit
One percentage, always current
One live readiness percentage across the NIS2 duties of care: risk management, incident process, supply chain, business continuity and governance. You always know where you stand.
- Live readiness percentage
- Breakdown per domain
- Gap list with next actions
- Progress you can show the board
Evidence vault
Proof, not promises
Nisha collects policies, decisions and technical settings in one vault, and checks Microsoft 365 and Google Workspace for MFA, logging and access hygiene.
- Central evidence vault
- Microsoft 365 configuration checks
- Google Workspace configuration checks
- Evidence linked to each duty of care
Incident meldplicht assistant
24 hours, 72 hours, 1 month
When an incident hits, Nisha starts the clocks: an early warning within 24 hours, an incident notification within 72 hours and a final report within 1 month, prepared for MijnNCSC.
- Early warning within 24 hours
- Incident notification within 72 hours
- Final report within 1 month
- Reports prepared for MijnNCSC
Monthly compliance report
Board ready, every month
Every month Nisha delivers a compliance report: readiness movement, open gaps, incidents and the evidence added. Written so the board can carry its training and oversight duty.
- Monthly readiness report
- Open gaps and planned actions
- Log of incidents and reports
- Supports the board training duty
NIS2 Ready verklaring
Honest by design
At 100 percent readiness Nisha issues a NIS2 Ready verklaring: a voluntary readiness statement backed by your evidence vault. There is no official NIS2 certificate and only the supervisor determines legal compliance.
- Issued at 100 percent readiness
- Voluntary readiness statement
- Backed by your evidence vault
- Never certificate claims
Pricing
One flat price. The whole compliance rhythm.
No trial, no setup fee. Cancel monthly.
- Scope check and full onboarding included
- Readiness cockpit and evidence vault
- Microsoft 365 and Google Workspace checks
- Incident assistant with the meldplicht clocks
- Monthly compliance report for the board
NIS2 FAQ
NIS2 in the Netherlands, answered
Direct answers about the Cyberbeveiligingswet and how Nisha gets organisations NIS2 ready.
Is NIS2 mandatory in the Netherlands?
Yes. NIS2 applies in the Netherlands through the Cyberbeveiligingswet, in force since 15 August 2026. Organisations in scope must register in the entiteitenregister via mijn.ncsc.nl and meet the duty of care and the incident reporting duty.
Who falls under NIS2?
Organisations in the sectors of Bijlage 1 and 2 of the law with 50 or more FTE, or with more than EUR 10 million in annual turnover and balance sheet total. Some categories, such as parts of digital infrastructure and government, fall in scope at any size.
What are the fines under NIS2?
Supervisors can impose fines up to EUR 10 million or 2 percent of worldwide annual turnover for essential entities, and up to EUR 7 million or 1.4 percent for important entities. Board members also carry a personal duty of training and oversight.
Is there an official NIS2 certificate?
No. NIS2 has no official certificate and no party can issue one. Nisha issues a voluntary NIS2 Ready verklaring at 100 percent readiness, a readiness statement backed by collected evidence. Only the supervisor determines whether an organisation legally complies.
What is the NIS2 meldplicht?
Significant incidents must be reported via MijnNCSC: an early warning within 24 hours, an incident notification within 72 hours and a final report within 1 month. Nisha prepares each step and tracks the clocks for you.
Explore related thinQit pages
NIS2 is not coming.
It is already law.
Get ready with Nisha.
The Cyberbeveiligingswet has been in force since 15 August 2026. Start with a free scope check, watch your readiness percentage climb, and build the evidence before the supervisor asks for it.