Skip to content

NIS2 Compliance

From regulation to recovery you can prove

NIS2 asks you to show that your business can keep running and recover. Mindtime covers the backup and disaster recovery part of Article 21, and gives you the evidence for your auditor.

Directive
(EU) 2022/2555
Netherlands
Cbw · since 15 Aug 2026
Germany
NIS2UmsuCG · since 6 Dec 2025
We cover
Art. 21(2)(c)

The regulation

Ten measures, one law

Article 21 lists ten areas every organisation in scope must cover, from risk analysis to multi-factor authentication.

In your organisation

Every control accounted for

Management has to approve the measures, oversee them, and can be held liable when they fall short.

Article 21(2)(c)

Backup and recovery, covered

Immutable backups, disaster recovery and tested restores: the business continuity layer, run for you.

Your evidence

Ready for the auditor

Restore tests, recovery drills and audit logs, documented automatically.

Get a free assessment

In short

What is NIS2?

NIS2, Directive (EU) 2022/2555, is the EU's cybersecurity law for essential and important organisations. It requires risk-management measures in ten areas, reporting of significant incidents starting within 24 hours, and makes management accountable for both.

Who it applies to
Medium-sized and larger organisations in the sectors of Annex I and II, plus some providers regardless of size
Key obligations
Article 21 security measures, Article 23 incident reporting, Article 20 management accountability
Fines
Up to at least €10 million or 2% of worldwide turnover for essential entities
What Mindtime covers
The backup and disaster recovery layer of Article 21(2)(c), with the evidence

Scope check

Does NIS2 apply to your business?

Three questions give you a first indication. Your national authority makes the final call, and in the Netherlands organisations in scope must register themselves.

Question 1

Do you work in one of these sectors?

High criticality (Annex I)

Energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management (including managed service providers), public administration, space

Other critical sectors (Annex II)

Postal and courier services, waste management, chemicals, food, manufacturing (including medical devices, electronics, machinery and vehicles), digital providers, research

Question 2

Are you a medium-sized enterprise or larger?

That means 50 or more employees, or more than €10 million in both annual turnover and balance sheet total.

Question 3

Are you a provider that's in scope regardless of size?

For example a public electronic communications provider, a trust service provider, a DNS service provider or top-level domain registry, or an organisation your government has designated.

Your first indication

Answer the questions to see whether NIS2 is likely to apply.

Article 21(2)

The ten measures, and who covers what

Article 21 requires "appropriate and proportionate" measures in ten areas. No single supplier covers all of them. This is where Mindtime fits.

  1. a

    Risk analysis and information system security policies

    Your organisation sets the policies and assesses the risks.

    You
  2. b

    Incident handling

    Detecting, handling and reporting incidents is your process.

    You
  3. c

    Business continuity, such as backup management and disaster recovery, and crisis management

    Mindtime covers backup management and disaster recovery, with the test evidence. Crisis management stays with you.

    Mindtime
  4. d

    Supply chain security

    Mindtime is an ISO 27001 and NEN 7510 audited supplier with a Data Processing Agreement, which helps your supplier assessment.

    We help
  5. e

    Security in acquisition, development and maintenance, including vulnerability handling

    Your systems, your patching and vulnerability process.

    You
  6. f

    Policies to assess the effectiveness of your measures

    Your organisation checks whether its measures work. Our restore tests are one input.

    You
  7. g

    Basic cyber hygiene practices and cybersecurity training

    Training for staff and, under Article 20, for management.

    You
  8. h

    Cryptography and, where appropriate, encryption

    Backup data is sent to our data centres AES-256 encrypted.

    We help
  9. i

    Human resources security, access control policies and asset management

    Who has access to what in your organisation.

    You
  10. j

    Multi-factor authentication and secured communications

    Admin actions in the Mindtime backup console require MFA. MFA across your own systems is yours.

    We help

Article 21(2)(c)

What NIS2 means for backup and recovery

The law asks for business continuity "such as backup management and disaster recovery". In practice auditors want to see three things: copies that survive an attack, recovery that works, and proof of both.

  1. 1

    Backups that survive

    Immutable copies following the 3-2-1-1-0 rule, stored only in Dutch and German data centres.

  2. 2

    Recovery that works

    Disaster recovery with standby infrastructure, and failover tested every quarter.

  3. 3

    Proof for the auditor

    Restore tests, audit logs and incident documentation, generated automatically.

Article 23

Report a significant incident in three steps

The clock starts when you become aware of a significant incident. Reporting is your obligation; our restore logs and recovery records give you the facts to report.

  1. 24 hours

    Early warning

    Whether the incident may be caused by unlawful or malicious acts, or could have a cross-border impact.

  2. 72 hours

    Incident notification

    An update with an initial assessment of the incident, its severity and impact.

  3. 1 month

    Final report

    No later than one month after the notification: a detailed description, the likely cause and the measures taken.

Articles 20 and 34

Penalties and management liability

Member States must be able to fine at least these amounts for breaches of Article 21 or 23. Whichever is higher applies.

  • Essential entities

    €10 million or 2%

    The maximum fine must be at least this amount or this share of total worldwide annual turnover, whichever is higher.

  • Important entities

    €7 million or 1.4%

    The maximum fine must be at least this amount or this share of total worldwide annual turnover, whichever is higher.

  • Management bodies · Article 20

    Approve, oversee, answer for it

    Management must approve the measures, oversee their implementation and can be held liable. Board members must also follow cybersecurity training.

Supply chain

Your suppliers count too

Article 21(2)(d) makes the security of your direct suppliers and service providers part of your own obligations.

Choosing a backup supplier

What to ask, and what we answer

  • Independently audited: ISO 27001 and NEN 7510
  • Data stored only in the Netherlands and Germany, under EU law
  • A Data Processing Agreement with every contract
  • Immutable backups and recovery tests you can show your auditor

For MSPs

NIS2 may apply to you directly

  • Managed service providers and managed security service providers are listed in Annex I, sectors of high criticality
  • Your clients in scope will assess you as their supplier
  • Mindtime gives you audited backup, recovery and evidence to offer every client
Become a partner

National laws

Where NIS2 stands in the Netherlands and Germany

NIS2 is a directive, so each country writes it into its own law. Status checked on 2 October 2026.

  • Netherlands · in force

    Cyberbeveiligingswet (Cbw)

    In force since 15 August 2026. Organisations in scope must register in the entity register, carry out a risk analysis and report incidents within 24 hours.

    NCSC on the Cbw
  • Germany · in force

    NIS2UmsuCG

    The NIS2 Implementation Act entered into force on 6 December 2025, without transition periods.

  • Mindtime

    Built for both

    Data centres in the Netherlands and Germany, and personal support in Dutch, German and English.

FAQ

Common questions

What is NIS2?

NIS2, Directive (EU) 2022/2555, is the EU's cybersecurity law for essential and important organisations. It requires risk-management measures in ten areas (Article 21), reporting of significant incidents starting within 24 hours (Article 23), and makes management bodies accountable (Article 20).

Does NIS2 apply to my business?

Generally yes if you work in a sector listed in Annex I or II of the directive and you are a medium-sized enterprise or larger: 50 or more employees, or more than €10 million in both annual turnover and balance sheet total. Some providers are in scope regardless of size. Take the scope check, and confirm with your national authority or adviser.

What does Article 21(2)(c) require?

Business continuity, such as backup management and disaster recovery, and crisis management. Mindtime covers the technical backup and disaster recovery layer and documents the evidence. Crisis management remains your responsibility.

How fast do I have to report an incident?

An early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report no later than one month after the notification.

What are the fines under NIS2?

For essential entities, maximum fines of at least €10 million or 2% of total worldwide annual turnover, whichever is higher. For important entities, at least €7 million or 1.4%. Management bodies can also be held liable.

When did NIS2 take effect in the Netherlands and Germany?

In the Netherlands the Cyberbeveiligingswet entered into force on 15 August 2026. In Germany the NIS2 Implementation Act (NIS2UmsuCG) entered into force on 6 December 2025.

Does using Mindtime make my organisation NIS2 compliant?

No single supplier can make you compliant. Mindtime covers the backup and disaster recovery part of Article 21(2)(c) and supports several other measures. Governance, risk analysis, incident reporting and the remaining measures stay with your organisation.