OTRISK
Regulations · EU Directive 2022/2555

NIS2, read as an operations problem.

NIS2 sets one cybersecurity baseline for essential and important entities in 18 sectors. It is a directive: the duties that bind you live in national law. In the Netherlands that is the Cyberbeveiligingswet, in force 15 August 2026. The directive decides the floor: risk management, reporting, and management accountability.

IN FORCE
16 Jan 2023
TRANSPOSITION DUE
17 Oct 2024
NIS1 REPEALED
18 Oct 2024
NL IMPLEMENTATION
Cbw · 15 Aug 2026

What it demands

Art. 21 · Risk management
Measures matched to risk
"Appropriate and proportionate" technical, operational and organisational measures, all-hazards, explicitly including supply-chain security. Appropriate to what? Your risks, which is why a demonstrable risk assessment comes first.
Art. 23 · Reporting
Significant incidents, staged
An early warning within 24 hours, an incident notification within 72, a final report within a month, all to your national CSIRT.
Art. 20 · Accountability
Management on the hook
Management bodies approve the measures, oversee implementation and can be held liable. Training is a duty, not a suggestion.

Who must care

Essential or important is decided by sector and size in your national law: large companies in the high-criticality sectors are essential; medium-sized ones are typically important; some types qualify regardless of size. The fine floors are real: up to €10 million or 2% of worldwide turnover for essential entities, €7 million or 1.4% for important ones. Member states may go higher.

Whether you are in scope is a national-law question. In the Netherlands: check the Cbw and register at mijn.ncsc.nl, mandatory per 15 August 2026.

Where OT comes in

The directive never says PLC, zone or safety system. It says "appropriate". For an installation, appropriate is decided by a per-system risk assessment. IEC 62443-3-2 is how OT does that demonstrably.

NIS2 (EU)National lawRisk-management dutyIEC 62443-3-2 assessmentSigned IRA & CRS
Trace it in the map →

How OTRISK helps

The duty becomes a workflow. The risk analysis runs as the standard’s own steps, ZCR 1–7, each gated by independent review.
Accountability becomes checkable. Owners, deadlines, verdicts and a permanent process log: what Art. 20 looks like in practice.
The proof regenerates. The IRA and CRS your board, auditor or supervisor asks for, generated from live data.

Questions we hear

Does NIS2 require IEC 62443?

No. It requires measures you can defend as appropriate. For OT, a IEC 62443-3-2 assessment makes "appropriate" demonstrable. That is why we built on it.

We operate in several member states.

The directive is the floor; each country transposed its own version. One evidence base mapped to the directive’s articles serves all of them; presentation differs per regulator.

Are we essential or important?

Sector plus size decides it, in your national law. In the Netherlands: the Cyberbeveiligingswet, with registration at mijn.ncsc.nl from 15 August 2026.

We already do ISO 27001.

A good foundation: it governs the management system. NIS2’s "appropriate measures" for an installation still need the OT-level risk assessment underneath.

SOURCES · FACTS VERIFIED 30 JUL 2026
EUR-Lex · Directive (EU) 2022/2555European Commission · NIS2 Directive policy pageRijksoverheid · Cbw & Wwke van kracht per 15 augustus 2026

From standard to signed-off.

Bring one installation in mind. In thirty minutes we show you which parts of OTRISK fit your situation and how the way of working looks. You leave with concrete next steps and pricing.

Read the Dutch implementation →Field note: the Cyberbeveiligingswet countdown →