What is NIS2? The EU directive explained, including physical security
NIS2 is the European Union’s cybersecurity directive. Every member state turns it into national law, and it now applies to thousands of organisations across Europe. Below: what it requires, who it covers, and what it means for the part almost nobody thinks about, your cameras, alarms and who can get into your buildings and footage.
- EU directive 2022/2555
- National law in every EU member state
- Covers physical access too
Short answer
What is NIS2?
NIS2 is EU Directive 2022/2555. It requires organisations in critical sectors to secure their network and information systems, report serious incidents quickly and make their management accountable. It replaced the original NIS Directive and covers far more sectors and organisations.
Because it is a directive, each member state implements it in its own law. The core is the same everywhere, but the names, supervisors and details differ. In the Netherlands, for example, it became the Cyberbeveiligingswet, in force since 15 August 2026, with the concrete requirements set out in a separate decree.
Scope
Who does NIS2 apply to?
Two things decide it: your sector and your size. In most countries you have to establish this yourself; nobody sends you a letter.
Sector
The directive lists eighteen sectors. Highly critical ones such as energy, transport, banking, health, drinking water, digital infrastructure, public administration and space. And other critical ones such as postal services, waste management, chemicals, food, manufacturing, digital providers and research.
Size
As a rule, medium-sized and large organisations: 50 employees or more, or annual turnover and balance sheet above 10 million euros. Some organisations fall under it regardless of size, and member states can designate smaller ones that provide an essential service.
There are two categories, essential and important. They share the same obligations, but supervision differs: essential entities are supervised proactively, important entities mainly after the fact.
Requirements
What are the NIS2 requirements?
| Obligation | What it means |
|---|---|
| Registration | Register with your national authority, so supervisors and CSIRTs can reach you. |
| Risk management | Appropriate measures based on a risk assessment. Article 21 lists, among others, incident handling, business continuity, supply chain security, cryptography, human resources security, access control policies, asset management and multi-factor authentication where appropriate. |
| Incident reporting | A significant incident is reported with an early warning within 24 hours, a notification within 72 hours and a final report within one month. |
| Management | The management body approves the measures, oversees their implementation and follows cybersecurity training. Managers can be held accountable. |
Fines
What are the NIS2 fines?
For essential entities up to at least 10 million euros or 2 percent of worldwide annual turnover, for important entities up to at least 7 million euros or 1.4 percent, whichever is higher. Member states set the exact maximum.
In practice a supervisor rarely starts with a fine. First comes an instruction or an order. But if you then cannot show what you have in place, you are on weak ground. Being able to demonstrate it runs through the whole directive.
UK
Does NIS2 apply in the UK?
Not directly. NIS2 is EU law and was adopted after Brexit. The UK has its own NIS Regulations 2018 and is updating them through the Cyber Security and Resilience Bill, presented to Parliament in November 2025. It follows the same line of thinking, with a UK-specific approach.
UK organisations can still feel NIS2. If you have operations in the EU, or customers there who fall under it, they will ask you about it through their supply chain requirements.
The forgotten part
What does NIS2 mean for physical security and CCTV?
More than most people think. The directive doesn’t mention cameras. But it requires access control policies and asset management, and it aims to protect network and information systems and their physical environment.
Your security systems are part of that. Cameras on your network are devices you have to manage. Cameras watching your server room are part of your physical access policy. And the recorder login is simply an account you must be able to revoke.
That is where it goes wrong in practice. Eleven people know the same recorder login, the alarm code hasn’t changed in years, and nobody knows who still has the intercom app on their phone. IT has locked down the network, but the recorder in the cupboard at site three is on no list at all.
- One account per person. No shared logins.
- Revoke access when people leave. See the offboarding checklist for security systems.
- Show who did what. See the audit trail of your camera system.
- An up-to-date list of devices. Which cameras, recorders and firmware run at every site.
How we bring that under control across all your sites is on access management for cameras, alarms and intercoms.
Honest
What we do, and what we don’t
We specialise in the part of NIS2 that concerns your security systems: cameras, alarms, intercoms and access, managed centrally and demonstrably. We look along, think along, come up with solutions and carry them out, and we deliver the permissions overview, audit trail, leaver procedure and documentation your auditor wants to see.
We don’t write the information security policy for your whole organisation and we are not an auditor. For the risk assessment of your whole business you work with your own adviser. We connect to that.
Questions about NIS2
When did NIS2 come into force?
The directive had to be transposed by member states by 17 October 2024. Many were late, so the date your national law applies differs per country. In the Netherlands it is 15 August 2026.
How do I know whether NIS2 applies to my organisation?
Check your sector and size against your national implementation. Many member states offer an official self-assessment. Fifty employees or more, or turnover and balance sheet above 10 million euros, in one of the listed sectors: then it is likely. When in doubt, ask your legal adviser or the national authority.
Is there a NIS2 certification?
Not for organisations and not for products. NIS2 puts the obligation on the organisation and asks you to be able to demonstrate your measures. A supplier selling a ‘NIS2-certified’ product is selling a label.
What is the difference between NIS2 and ISO 27001?
NIS2 is a legal obligation, ISO 27001 a voluntary standard you can be certified against. The measures overlap a lot. With ISO 27001 much of the work for NIS2 is done, but registration, incident reporting deadlines and the role of management come on top.
Does NIS2 require CCTV?
No. It requires a policy for physical access and that you apply it demonstrably. Which measures you choose follows from your own risk assessment.
How do your security systems measure up?
Take the three-minute access check, or tell us about your situation. We review your cameras, alarms and access control and tell you what still needs doing.

A quick word
Questions about your situation? Call Koen.
Takes the time, draws it out, and does not steer towards a number. I do not sell, I advise. Describe your situation and you will hear straight away what we would do — with no obligation.
Koen · Senior adviser