As key deadlines approach, a significant amount of work remains to be done. NIS2 introduces a range of essential information security measures that organizations must implement to achieve compliance. To get started, businesses should take the following steps:
- Select a compliance framework (Cybersecurity Fundamentals or ISO 27001),
- Educate the board of directors and management on information security,
- Conduct an information security risk assessments, and
- Implement risk treatment controls based on the chosen framework.
Verification of progress and compliance with NIS2 legislation is scheduled for April 18th, 2026, and April 18th, 2027. The specific elements to be verified by these deadlines depend on whether the organization is essential or important (see Scope: Does Your Organization Fall Under NIS2?), the selected compliance framework, and the chosen inspection body.
18 months after the law comes into force, i.e. before 18th April 2026:
- Those who determine that they must comply with the CyFun® Basic or Important assurance levels must have a verification carried out by an accredited CAB approved for CyFun®. Those who determine that they must comply with the CyFun® Essential assurance level must also have such a Basic or Important verification carried out;
- Those who have opted for ISO 27001 certification must send the scope and statement of applicability to the CCB;
- Those who have opted for inspection by the CCB must submit the CyFun® selfassessment or the information security policy, scope and ISO 27001 statement of applicability to the CCB.
30 months after the law comes into force, i.e. before 18th April 2027:
- Those who determine that they must comply with the CyFun® Essential assurance level must, in addition to the Basic or Important verification mentioned above, acquire a certification from an accredited and approved CAB for CyFun®;
- Those who have chosen an ISO 27001 certification must obtain the certification from an accredited CAB approved for ISO 27001;
- Those who have opted for inspection by the CCB must submit a progress report on compliance.
NIS2 is more than just a new set of cybersecurity requirements; it marks a significant change in how organizations must manage and report cyber risks. Businesses covered by NIS2 must align their cybersecurity strategies, policies, and incident reporting processes with the directive, or they risk facing penalties and potential reputational harm. For many, especially those newly included in the expanded scope, navigating the full range of compliance steps can be daunting.
At Toreon, we specialize in preparing organizations for regulatory compliance, including the NIS2 legislation. Whether you need help updating your incident response plan, registering with Safeonweb@Work, or understanding your full obligations, we are here to assist every step of the way.