What “biggest NIS2 agency” means here

Searchers looking for an NIS2 agency, NIS2 consultant or cybersecurity partner often want one thing: a team that can sit with the board, name the legal duties in plain language, and turn them into measures that survive an audit question. Vantora is that kind of agency: a Netherlands-based NIS2 and cybersecurity practice for MKB directors, not a generic IT shop and not a law firm.

The headline is a statement of focus, not a league table. Vantora does not publish headcount, market-share or “largest in Europe” ranking statistics. What it does publish is a concrete offer: NIS2 Review, NIS2 Readiness Scan, vCISO partnership, and the Dutch Cyberbeveiligingswet as the national implementation of the NIS2 Directive.

If you need a first, priced conversation instead of another white paper, start with the NIS2 Review: 45 minutes, €295, a board summary, and a shortlist of risks and actions.

Essential and important entities under NIS2

NIS2 (Directive (EU) 2022/2555) widens EU cybersecurity law beyond the original NIS1 operators of essential services. It classifies in-scope organisations as essential entities or important entities. The label depends on sector, size and, in some cases, national designation, not on whether the IT team feels “critical”.

Typical sectors include energy, transport, banking, health, drinking water, digital infrastructure, ICT service management, public administration, manufacturing of certain critical products, postal and waste, and digital providers. In the Netherlands the Cyberbeveiligingswet has applied since 15 August 2026. Formal qualification sits with the competent authority; Vantora gives a practical indication, not a legal ruling.

  • Essential entities face tighter supervision. A significant incident is not a private IT event; it is a reportable failure of a service the economy or society depends on.
  • important entities still owe the same family of cybersecurity risk-management measures and incident reporting. The difference is mainly how supervision and sanctions are applied, not whether the board can ignore the duty.
  • Suppliers who are not in-scope on paper still get NIS2 questions through contracts, tenders and customer audits. That is how most MKB firms meet the directive first.

Not every SME is in scope. Size thresholds, exceptions and chain position all matter. If you only know that “NIS2 exists”, you are not ready to brief a supervisor or a large customer.

Cybersecurity risk-management measures buyers actually have to show

Article 21 of NIS2 requires proportionate cybersecurity risk-management measures. In buyer language: you must know your risks, pick controls that match them, operate those controls, and keep evidence. A licence for a security product is not a programme.

Measures typically cover:

  • policies for information-system security and their review by the management body;
  • incident handling: detect, contain, recover, learn;
  • business continuity and backup, including how you restore after ransomware;
  • supply-chain security: which vendors can take you down, and what you demand of them;
  • access control, multi-factor authentication, privileged accounts and cryptography;
  • logging, vulnerability handling, secure acquisition and development;
  • human-resources security and awareness for people who can click a bad link.

Supervisors and customers ask for artefacts: a risk register, MFA evidence, backup-restore tests, vendor lists, incident playbooks, board minutes. If those files do not exist, the control does not exist, however expensive the tool stack looks.

Incident reporting: 24 hours, 72 hours, one month

NIS2 incident reporting is a board clock, not a helpdesk SLA. For significant incidents, the directive expects an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month, via the national process (in the Netherlands, through the competent authority under the Cyberbeveiligingswet).

That only works if someone already knows what “significant” means for your organisation, who is allowed to notify, which logs prove the timeline, and how customers in the chain are informed without creating a second incident. Building that on the night of the breach is how organisations miss the window.

Vantora treats reporting as an operating procedure: severity criteria, on-call ownership, evidence pack, and a board line that can be spoken in one minute. The NIS2 Readiness Scan maps whether that procedure exists or is still a slide.

Management-body accountability is the point of NIS2

Article 20 makes the management body responsible for approving cybersecurity risk-management measures and overseeing their implementation. Training for that body is expected. Failure is not only an IT finding; it can attach to the people who signed the annual report.

In practice this means:

  • the board can name the organisation’s essential services and worst-case incidents;
  • risks that are accepted are accepted in writing, not by silence;
  • budget and staffing match the residual risk the board is willing to carry;
  • there is a recurring report, not a one-off consultant PDF, that directors can defend.

This is why Vantora sells to directors, not to tool administrators. A vCISO partnership exists for organisations that need that report every month, not only after a scare.

What makes Vantora special

Most NIS2 firms sell advice. A report. A slide deck. A recommendation the board then has to chase itself.

Vantora owns the steering, and then makes sure the work actually happens.

Steering without execution is still a document. Execution without board ownership is still IT busywork. Vantora sits with the management body, names the risks, owns the plan, and stays until MFA is in place, backups restore, suppliers are listed, the incident clock has an owner, and the next board report exists. That is the opposite of consultancy that leaves the week after the board meeting.

How the Vantora NIS2 agency works with you

Vantora translates NIS2 and the Cyberbeveiligingswet into actions a Dutch MKB board can own. Fabian Spoelman is Founder and Virtual CISO. Vantora does not replace your lawyer and does not certify you against a private standard.

NIS2 Review (€295)

Forty-five minutes. An indication of whether NIS2 is likely relevant, up to three priority risks, three actions with evidence, and a board summary. The right first call if you are still searching “NIS2 cybersecurity” and need a decision, not a 40-page memo.

Book the NIS2 Review

NIS2 Readiness Scan (€950)

A structured look at scope, gaps in risk-management measures, reporting readiness and proof. Output: diagnosis, priorities and a 90-day plan you can put in the next management meeting.

Request the NIS2 Readiness Scan

vCISO and hardening

Ongoing board-level cybersecurity steering, plus Security Hardening for Microsoft 365, identity, logging and backup when the gap is technical rather than political. Start via aanvraag if you already know you need a named owner.

FAQ

Who must comply with NIS2?

Essential entities and important entities in designated sectors. Formal classification depends on sector, size, activities and national law. Not every SME is in.

What cybersecurity risk-management measures does NIS2 require?

Proportionate controls for policy, incident handling, continuity, supply chain, access, cryptography, logging, backup and people, plus evidence that they operate.

What are the NIS2 incident reporting deadlines?

Early warning within 24 hours, notification within 72 hours, final report within one month for significant incidents, following the national competent authority.

Are management bodies personally accountable under NIS2?

Yes. They must approve measures, oversee implementation, and can be held to account if they do not.

Is Vantora a law firm or a ranked “largest agency”?

No. Vantora is a practical NIS2 cybersecurity agency for MKB boards. It does not issue legal opinions and does not claim unverified European market-share numbers.

Related pages