InfraForge
Back to homeNIS2, Mandatory Now

Are you subject to NIS2? We ensure you're compliant.

The new European cybersecurity law affects thousands of Dutch SMEs. Fines up to €10 miljoen and personal liability for directors make postponing no longer an option.

Also applies to SMEs

From 50 employees or €10M turnover in 18 sectors, including IT, transport, food, manufacturing and healthcare.

Directors personally liable

Management can be held personally liable for negligence. Fines up to €10M or 2% of turnover.

24-hour reporting obligation

Cyber incidents must be reported to the regulator within 24 hours. No preparation = big risk.

NIS2

Which sectors fall under NIS2?

18 sectors are designated as essential or important. A selection:

ICT & digital services
Transport & logistics
Food & agriculture
Manufacturing & industry
Healthcare & medical
Energy, water & waste management
Our approach

From scan to compliant in 4 steps

No loose advisory reports, a structured trajectory with implementation and continuous management.

1. NIS2 Scan

We map your current security, processes and risks and assess them against NIS2 requirements.

2. Gap Analysis

A clear report: where do you already comply, what needs improvement, and which actions have the highest priority.

3. Implementation

We implement EDR/XDR, MFA, backups, policy and reporting procedures, tailored to your organization.

4. Continuous Management

24/7 monitoring, awareness training, incident response and annual re-assessment to stay compliant.

What InfraForge handles for you

The complete NIS2 checklist, covered by our MSP package.

Risk analysis & information security policy
Incident response & reporting procedures (24h)
Multi-factor authentication & access management
Backup, recovery and business continuity
Supply chain security & vendor management
Awareness training for employees
Encryption of data at rest and in transit
Vulnerability and patch management
Logging, monitoring and SIEM
Executive responsibility & governance

Frequently Asked Questions

Do I fall under NIS2?

From 50 employees OR €10 million turnover in one of the 18 designated sectors you fall under NIS2. Even as a supplier to a NIS2-obligated organization you may be indirectly required to comply.

What are the fines for non-compliance?

For essential entities up to €10 million or 2% of global annual turnover. For important entities up to €7 million or 1.4%. Additionally, management can be held personally liable.

When do I need to be compliant?

The Dutch Cybersecurity Act (implementation of NIS2) takes effect mid-2025. Regulators can enforce immediately after enactment, waiting is not an option.

How long does a NIS2 trajectory take?

An initial scan and gap analysis typically completes within 2-4 weeks. Full implementation depends on your starting position and averages 2-6 months.

Prevent fines up to €10 million, become NIS2-ready

Plan a no-obligation intake and discover within 30 minutes where your organization stands, and which steps you need to take today.