NIS2 Compliance
From regulation to recovery you can prove
NIS2 asks you to show that your business can keep running and recover. Mindtime covers the backup and disaster recovery part of Article 21, and gives you the evidence for your auditor.
The regulation
Ten measures, one law
Article 21 lists ten areas every organisation in scope must cover, from risk analysis to multi-factor authentication.
In your organisation
Every control accounted for
Management has to approve the measures, oversee them, and can be held liable when they fall short.
Article 21(2)(c)
Backup and recovery, covered
Immutable backups, disaster recovery and tested restores: the business continuity layer, run for you.
Your evidence
Ready for the auditor
Restore tests, recovery drills and audit logs, documented automatically.
Get a free assessmentIn short
What is NIS2?
NIS2, Directive (EU) 2022/2555, is the EU's cybersecurity law for essential and important organisations. It requires risk-management measures in ten areas, reporting of significant incidents starting within 24 hours, and makes management accountable for both.
- Who it applies to
- Medium-sized and larger organisations in the sectors of Annex I and II, plus some providers regardless of size
- Key obligations
- Article 21 security measures, Article 23 incident reporting, Article 20 management accountability
- Fines
- Up to at least €10 million or 2% of worldwide turnover for essential entities
- What Mindtime covers
- The backup and disaster recovery layer of Article 21(2)(c), with the evidence
This page explains the law in plain language. It is information, not legal advice. Legal sources were checked on 2 October 2026.
Scope check
Does NIS2 apply to your business?
Three questions give you a first indication. Your national authority makes the final call, and in the Netherlands organisations in scope must register themselves.
Question 1
Do you work in one of these sectors?
High criticality (Annex I)
Energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management (including managed service providers), public administration, space
Other critical sectors (Annex II)
Postal and courier services, waste management, chemicals, food, manufacturing (including medical devices, electronics, machinery and vehicles), digital providers, research
Question 2
Are you a medium-sized enterprise or larger?
That means 50 or more employees, or more than €10 million in both annual turnover and balance sheet total.
Question 3
Are you a provider that's in scope regardless of size?
For example a public electronic communications provider, a trust service provider, a DNS service provider or top-level domain registry, or an organisation your government has designated.
Your first indication
Answer the questions to see whether NIS2 is likely to apply.
Article 21(2)
The ten measures, and who covers what
Article 21 requires "appropriate and proportionate" measures in ten areas. No single supplier covers all of them. This is where Mindtime fits.
- aYou
Risk analysis and information system security policies
Your organisation sets the policies and assesses the risks.
- bYou
Incident handling
Detecting, handling and reporting incidents is your process.
- cMindtime
Business continuity, such as backup management and disaster recovery, and crisis management
Mindtime covers backup management and disaster recovery, with the test evidence. Crisis management stays with you.
- dWe help
Supply chain security
Mindtime is an ISO 27001 and NEN 7510 audited supplier with a Data Processing Agreement, which helps your supplier assessment.
- eYou
Security in acquisition, development and maintenance, including vulnerability handling
Your systems, your patching and vulnerability process.
- fYou
Policies to assess the effectiveness of your measures
Your organisation checks whether its measures work. Our restore tests are one input.
- gYou
Basic cyber hygiene practices and cybersecurity training
Training for staff and, under Article 20, for management.
- hWe help
Cryptography and, where appropriate, encryption
Backup data is sent to our data centres AES-256 encrypted.
- iYou
Human resources security, access control policies and asset management
Who has access to what in your organisation.
- jWe help
Multi-factor authentication and secured communications
Admin actions in the Mindtime backup console require MFA. MFA across your own systems is yours.
Article 21(2)(c)
What NIS2 means for backup and recovery
The law asks for business continuity "such as backup management and disaster recovery". In practice auditors want to see three things: copies that survive an attack, recovery that works, and proof of both.
- 1
Backups that survive
Immutable copies following the 3-2-1-1-0 rule, stored only in Dutch and German data centres.
- 2
Recovery that works
Disaster recovery with standby infrastructure, and failover tested every quarter.
- 3
Proof for the auditor
Restore tests, audit logs and incident documentation, generated automatically.
Article 23
Report a significant incident in three steps
The clock starts when you become aware of a significant incident. Reporting is your obligation; our restore logs and recovery records give you the facts to report.
- 24 hours
Early warning
Whether the incident may be caused by unlawful or malicious acts, or could have a cross-border impact.
- 72 hours
Incident notification
An update with an initial assessment of the incident, its severity and impact.
- 1 month
Final report
No later than one month after the notification: a detailed description, the likely cause and the measures taken.
Articles 20 and 34
Penalties and management liability
Member States must be able to fine at least these amounts for breaches of Article 21 or 23. Whichever is higher applies.
Essential entities
€10 million or 2%
The maximum fine must be at least this amount or this share of total worldwide annual turnover, whichever is higher.
Important entities
€7 million or 1.4%
The maximum fine must be at least this amount or this share of total worldwide annual turnover, whichever is higher.
Management bodies · Article 20
Approve, oversee, answer for it
Management must approve the measures, oversee their implementation and can be held liable. Board members must also follow cybersecurity training.
Supply chain
Your suppliers count too
Article 21(2)(d) makes the security of your direct suppliers and service providers part of your own obligations.
Choosing a backup supplier
What to ask, and what we answer
- Independently audited: ISO 27001 and NEN 7510
- Data stored only in the Netherlands and Germany, under EU law
- A Data Processing Agreement with every contract
- Immutable backups and recovery tests you can show your auditor
For MSPs
NIS2 may apply to you directly
- Managed service providers and managed security service providers are listed in Annex I, sectors of high criticality
- Your clients in scope will assess you as their supplier
- Mindtime gives you audited backup, recovery and evidence to offer every client
National laws
Where NIS2 stands in the Netherlands and Germany
NIS2 is a directive, so each country writes it into its own law. Status checked on 2 October 2026.
Netherlands · in force
Cyberbeveiligingswet (Cbw)
In force since 15 August 2026. Organisations in scope must register in the entity register, carry out a risk analysis and report incidents within 24 hours.
NCSC on the CbwGermany · in force
NIS2UmsuCG
The NIS2 Implementation Act entered into force on 6 December 2025, without transition periods.
Mindtime
Built for both
Data centres in the Netherlands and Germany, and personal support in Dutch, German and English.
NIS2 guides
Go deeper
Practical guides on each part of NIS2, written for business owners rather than lawyers.
- 01NIS2 scope checklistSectors, size thresholds and the exceptions, step by step.
- 02Backup and DR requirementsWhat Article 21(2)(c) asks for, and how to prove it.
- 03Incident reporting timelineThe 24-hour, 72-hour and one-month steps explained.
- 04Penalties and liabilityFines, supervisory measures and what management is accountable for.
- 05Supply chain securityHow to assess your suppliers under Article 21(2)(d).
- 06The shared responsibility modelWhere Microsoft's part ends and yours begins, and what NIS2 expects on your side.
- 07NIS2 for MSPsYour own obligations, and what your clients will ask you.
- 08The Dutch and German lawsWhere the Cyberbeveiligingswet and the NIS2UmsuCG stand today.
- 09Data sovereigntyWhat it means, and why the location of your data matters.
- 10AI governance and NIS2Where AI tools meet your security obligations.
FAQ
Common questions
What is NIS2?
NIS2, Directive (EU) 2022/2555, is the EU's cybersecurity law for essential and important organisations. It requires risk-management measures in ten areas (Article 21), reporting of significant incidents starting within 24 hours (Article 23), and makes management bodies accountable (Article 20).
Does NIS2 apply to my business?
Generally yes if you work in a sector listed in Annex I or II of the directive and you are a medium-sized enterprise or larger: 50 or more employees, or more than €10 million in both annual turnover and balance sheet total. Some providers are in scope regardless of size. Take the scope check, and confirm with your national authority or adviser.
What does Article 21(2)(c) require?
Business continuity, such as backup management and disaster recovery, and crisis management. Mindtime covers the technical backup and disaster recovery layer and documents the evidence. Crisis management remains your responsibility.
How fast do I have to report an incident?
An early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report no later than one month after the notification.
What are the fines under NIS2?
For essential entities, maximum fines of at least €10 million or 2% of total worldwide annual turnover, whichever is higher. For important entities, at least €7 million or 1.4%. Management bodies can also be held liable.
When did NIS2 take effect in the Netherlands and Germany?
In the Netherlands the Cyberbeveiligingswet entered into force on 15 August 2026. In Germany the NIS2 Implementation Act (NIS2UmsuCG) entered into force on 6 December 2025.
Does using Mindtime make my organisation NIS2 compliant?
No single supplier can make you compliant. Mindtime covers the backup and disaster recovery part of Article 21(2)(c) and supports several other measures. Governance, risk analysis, incident reporting and the remaining measures stay with your organisation.
Keep reading