The Netherlands took longer than most member states to transpose NIS2. It has now done so. Organisations in scope have carried their obligations from the first day. There was no transition period.
For boards, the significant change is not technical. It is that the duties land on you. Management bodies are required to approve the risk-management measures, to oversee their implementation, and to follow training on the subject. Being poorly informed is no longer an explanation.
The long legislative delay meant many organisations planned against draft texts, and a good number are still working through the gap. That is a normal position, and it is a recoverable one.
What is not recoverable is a board that cannot say where it stands. "We are working on it" only holds up when it is attached to a specific, owned, dated plan. Our work is to get you to that answer.
Two questions. Not a legal determination: a starting point for the conversation.
NIS2 lists specific "essential" and "important" sectors: pick the closest match.
NIS2 generally applies to medium and large enterprises.
Registered with the national authority, details kept current.
Risk-management measures proportionate to your exposure.
Short notification timelines: the decision path must exist first.
Approval, oversight and training obligations on the management body.
Requirements travelling down the chain, even out of direct scope.
Are you in scope, how far off are you, and what is the shortest defensible route from here. If you're not in scope, we'll tell you that, and you'll have spent thirty minutes finding out.