A factual assessment for a medium-sized enterprise seeking certainty about the applicability of NIS2 and the Dutch Cybersecurity Act.
The organisation
A medium-sized international company designs and realizes physical presentation and communication concepts for business clients. Some projects integrate existing electronic products and digital functionalities.
The question
- Are our activities directly NIS2?
- Does processing electronics or digital functionality make us a manufacturer or digital service provider?
- What measures are wise when we are not directly covered by the law, but when customers or chain partners make demands?
Our approach
Kynexis Information Security conducted a targeted NIS2 scope assessment. This was not only a review of trade register data, but also of actual work.
Determination of actual business activities
It was examined whether the company produced electronic equipment, provided software as a standalone service, operated digital infrastructure, implemented structural ICT management, acted as MSP or MSSP or operated a digital platform.
Review of the NIS2 sectors
The actual activities were assessed against the production, digital infrastructure, management of ICT services, digital providers and special application grounds. The size criterion was also assessed.
Website and market positioning checked
Marketing terms such as digital applications, interactive concepts and apps were compared with the actual role distribution around software development, hosting, connectivity, data and technical management.
Summary
On the basis of the facts examined, the company did not directly qualify as NIS2 entity within the sector categories under investigation.
- no production of electronics or communication equipment;
- no digital infrastructure;
- no managed service provider;
- not a digital platform;
- no software or security service as an independent product.
NIS2 remains relevant via the chain
Organisations not directly covered by NIS2 may also be subject to security requirements of customers, clients and chain partners.
Kynexis Information Security therefore advised to record primary and critical business processes, identify digital dependencies, identify critical suppliers, document roles around software and data and periodically recalibrate the scope.
The result
- a documented picture of facts;
- a substantiated review of relevant NIS2 sectors;
- clarity on the size criterion;
- a distinction between own activities and outsourced services;
- a reasoned conclusion;
- a practical action list for chain risks and suppliers.
Why this approach worked
The assessment did not stick with industry codes, personnel numbers or general checklists. The organisation's actual role was leading.
Doubt about the Dutch Cybersecurity Act?
- NIS2 scope assessments
- Assessment of actual business activities
- Chain and supplier analyses
- Board-level risk analyses
- Preparation for customer requests and assurance


