AsteronAsteron

    NIS2 readiness for European healthtech

    NIS2 raises cybersecurity requirements across essential European sectors, including healthcare, medical-device manufacturing, cloud services and managed ICT services. It is implemented through national laws, so applicability, registration and supervision depend on each legal entity’s activities, size and jurisdiction. Asteron determines whether your company is directly regulated, affected through the healthcare supply chain or outside formal scope, then translates the applicable requirements into governance, controls, evidence and an incident-reporting process your team can operate.

    View NIS2 pricing
    • Applicability and entity status assessed
    • Ten risk-management areas mapped
    • 24-hour and 72-hour reporting prepared
    • Board and supplier responsibilities defined

    What is NIS2?

    The NIS2 Directive establishes a common European baseline for cybersecurity risk management, incident reporting, management accountability and supervision. It applies through national legislation rather than as a single identical operating law across every EU country.

    Both essential and important entities must implement proportionate technical, operational and organisational measures. National authorities determine registration, reporting channels, supervision and enforcement.

    NIS2 is therefore not a checklist that can be completed once for the whole EU. A company operating across several countries may need a common control baseline combined with jurisdiction-specific obligations.

    Does NIS2 apply to your healthtech company?

    Handling health data or selling to a hospital does not by itself make every software company a NIS2 entity. Conversely, a company cannot assume it is excluded merely because it describes itself as a technology vendor.

    Hospital, clinic or qualifying healthcare provider
    Often directly covered when national scope and size thresholds are met
    Manufacturer of medical devices or IVDs
    May fall within the manufacturing categories; certain critical devices receive additional treatment
    Cloud, data-centre, managed-service or managed-security provider
    May be directly regulated based on the entity type and applicable thresholds
    Healthtech SaaS supplier to hospitals
    Not automatically in scope, but commonly affected through customer and supply-chain requirements
    Small healthtech startup
    Often outside the standard size threshold, but exceptions and national designations must still be checked
    Company operating in several EU countries
    Each legal entity, establishment and applicable national law must be assessed

    The assessment must consider legal entities, employee and financial thresholds, sector classification, services provided, establishment, customer relationships and any designation based on public-health or systemic importance.

    Essential and important entities

    Both categories are subject to the core risk-management and incident-reporting duties. “Important” does not mean optional or low risk. Final classification follows the relevant national law and authority interpretation.

    Usually larger organisations in sectors of high criticality, plus specifically designated entities
    Commonly medium-sized organisations in high-criticality sectors and qualifying organisations in other critical sectors
    Subject to more proactive supervision
    Commonly supervised after evidence of non-compliance or an incident
    Higher maximum fine thresholds under NIS2
    Lower - but still material - maximum fine thresholds

    The ten NIS2 risk-management areas

    A defensible NIS2 programme connects these areas to identified risks, accountable owners and operating evidence. Generic policies are insufficient if supplier reviews, access decisions, vulnerability handling, testing and incident escalation do not happen in practice.

    1. 1. Policies for risk analysis and information-system security
    2. 2. Incident handling
    3. 3. Business continuity, backup, disaster recovery and crisis management
    4. 4. Supply-chain and service-provider security
    5. 5. Secure acquisition, development and maintenance, including vulnerability handling and disclosure
    6. 6. Assessment of whether security measures remain effective
    7. 7. Cyber hygiene and cybersecurity training
    8. 8. Cryptography and encryption
    9. 9. Human-resources security, access control and asset management
    10. 10. Multi-factor authentication, secure communications and appropriate emergency communication systems

    Incident reporting

    Reports must use the relevant national authority or CSIRT channel. Contractual notification deadlines may be shorter and should be integrated into the same decision process.

    1. Step 1

      Within 24 hours

      Submit an early warning after becoming aware of a significant incident. It should indicate whether unlawful or malicious activity is suspected and whether cross-border impact is possible.

    2. Step 2

      Within 72 hours

      Provide the incident notification with an initial assessment of severity, impact and available indicators of compromise.

    3. Step 3

      During the response

      Supply intermediate information when requested and maintain evidence supporting containment, impact assessment and regulatory decisions.

    4. Step 4

      Within one month

      Submit the final report. If the incident is still ongoing, provide a progress report and complete the final report after handling concludes.

    Board responsibility and governance

    Management bodies must approve and oversee cybersecurity risk-management measures. Members are also expected to receive sufficient training to understand the organisation’s cyber risks and their consequences.

    A workable governance model should define:

    • - The management body that approves material risk decisions
    • - The senior owner accountable for the NIS2 programme
    • - Control owners responsible for day-to-day operation
    • - Escalation thresholds for incidents and overdue remediation
    • - Regular reporting on risk, suppliers, vulnerabilities and resilience
    • - Evidence of management review and training

    Responsibility for NIS2 obligations cannot be outsourced to Asteron or another security provider.

    Supply-chain security

    NIS2 requires organisations to consider vulnerabilities and security practices across direct suppliers and service providers.

    For healthtech companies, this commonly includes cloud infrastructure, development partners, managed services, identity providers, clinical integrations, hosting providers and vendors that can affect product or service continuity.

    Supplier assurance should be risk-based. It should connect procurement, due diligence, contractual requirements, ongoing monitoring, incident notification and exit planning instead of relying solely on questionnaires.

    NIS2 in the Netherlands and Germany

    🇳🇱 Netherlands

    Cyberbeveiligingswet

    The Cyberbeveiligingswet implements NIS2 and enters into force on 15 August 2026. In-scope organisations face registration, duty-of-care, incident-reporting and management-accountability requirements.

    Cyberbeveiligingswet Readiness →
    🇩🇪 Germany

    NIS2 implementation legislation

    Germany’s NIS2 implementation legislation entered into force on 6 December 2025. In-scope companies use the BSI Portal for the applicable registration and incident-reporting processes.

    An EU-level readiness baseline can be reused, but registration, entity categories, authorities, terminology and procedures must follow national law.

    How Asteron delivers the project

    1. Applicability assessment

      Identify legal entities, sectors, size thresholds, jurisdictions and direct or indirect exposure.

    2. Requirement mapping

      Translate EU and national requirements into an agreed control baseline.

    3. Risk and governance baseline

      Define risks, responsibilities, board oversight and reporting.

    4. Control implementation

      Establish proportionate security, resilience, supplier and vulnerability processes.

    5. Incident-reporting readiness

      Align detection, escalation, regulatory decisions and national reporting channels.

    6. Readiness validation

      Review evidence, test a representative scenario and create the remaining-action roadmap.

    Deliverables

    Scope and governance

    • - NIS2 applicability and jurisdiction assessment
    • - Preliminary essential or important entity classification
    • - Legal-entity and service-scope map
    • - Requirement and control matrix
    • - Cybersecurity risk baseline
    • - Board responsibility and reporting model
    • - Prioritised remediation roadmap

    Operational readiness

    • - NIS2 policy and evidence set
    • - Supplier-security workflow
    • - Vulnerability-management requirements
    • - Business-continuity and crisis-management alignment
    • - Incident classification and reporting runbook
    • - 24-hour and 72-hour notification workflow
    • - Management briefing and readiness evidence pack

    NIS2 readiness pricing

    With an existing Asteron Compliance Core
    €6,900

    Reuse established governance, risk, supplier, incident and evidence processes and add the applicable NIS2 requirements.

    As your first Asteron engagement
    €9,900

    Establish the NIS2 readiness baseline without relying on an existing Asteron-managed compliance system.

    These prices cover one legal entity, one principal jurisdiction and one agreed service scope. Multi-entity, multi-country or unusually complex environments are scoped separately. Prices exclude VAT where applicable.

    There is no EU-wide NIS2 certificate or certification-body audit included in this service. Authorities supervise compliance through the applicable national law. Asteron delivers operational readiness; it does not guarantee a regulator’s legal determination.
    View full pricing

    What remains separate

    • - Formal legal opinions or final statutory classification
    • - Registration or filings made in the client’s name
    • - Representation before regulators or CSIRTs
    • - Technical remediation and software development
    • - Penetration testing
    • - Continuous vulnerability management
    • - Incident-response retainers or live incident handling
    • - ISO or NEN certification audits
    • - Additional countries, entities or products outside the agreed scope

    Responsibilities

    Asteron

    • - Assess likely applicability and jurisdiction
    • - Map requirements to practical controls
    • - Prepare governance, supplier and incident workflows
    • - Review evidence and remaining gaps
    • - Support readiness and management understanding

    Your organisation

    • - Confirm legal entities, activities, size and markets
    • - Approve risks, policies and responsibilities
    • - Implement and operate technical controls
    • - Maintain supplier and incident information
    • - Obtain legal advice where classification is uncertain
    • - Make formal filings and regulatory decisions

    Frequently asked questions

    Does NIS2 apply to every healthtech company?

    No. Applicability depends on the sector, the type of services provided, size thresholds and each Member State’s implementation of the directive. Some healthtech companies fall directly within scope, while others are affected primarily through customer or supply-chain obligations rather than as regulated entities themselves.

    Are medical-device and IVD manufacturers covered?

    They can be. Manufacturers of medical devices and in vitro diagnostic devices fall within the manufacturing categories used by NIS2, and certain critical medical devices receive additional treatment. Final classification follows the applicable national law and the entity’s activities, size and jurisdiction.

    What is the difference between essential and important entities?

    Essential entities are usually larger organisations in sectors of high criticality, plus specifically designated entities, and are subject to more proactive supervision and higher maximum fines. Important entities are commonly medium-sized organisations in high-criticality sectors or qualifying organisations in other critical sectors, supervised largely after evidence of non-compliance or an incident. Both must meet the core risk-management and reporting duties.

    Can a small company still fall within scope?

    Yes. NIS2 uses size thresholds as a general rule, but Member States and the directive itself allow specific designations regardless of size, including for entities whose services are systemically important, sole providers or otherwise critical. A small company should not assume it is out of scope without checking national criteria.

    Does selling software to hospitals make us directly regulated?

    Not automatically. Being a supplier to a hospital does not by itself make a software vendor a NIS2 entity. However, hospitals and other regulated customers must apply supply-chain security requirements, so vendors are commonly asked to demonstrate proportionate cybersecurity practices even when they are not directly regulated themselves.

    Is ISO 27001 sufficient for NIS2?

    No. ISO 27001 provides reusable security governance and evidence that supports NIS2 preparation, but it does not automatically establish NIS2 compliance. National authorities supervise NIS2 obligations under the applicable national law, including specific requirements on incident reporting, management responsibility and registration that are not part of an ISO 27001 audit.

    What are the NIS2 incident-reporting deadlines?

    For significant incidents, an early warning is required within 24 hours of awareness, an incident notification within 72 hours, intermediate information on request during the response and a final report within one month. Reporting uses the applicable national authority or CSIRT channel, and contractual notification deadlines may be shorter.

    What responsibilities does the board have?

    Management bodies must approve and oversee the cybersecurity risk-management measures and are expected to receive sufficient training to understand the organisation’s cyber risks and their consequences. Responsibility for NIS2 obligations cannot be outsourced to a security provider.

    How does NIS2 differ between the Netherlands and Germany?

    The Netherlands implements NIS2 through the Cyberbeveiligingswet, which enters into force on 15 August 2026 and uses the NCSC and sectoral authorities. Germany’s NIS2 implementation legislation entered into force on 6 December 2025, with in-scope companies using the BSI Portal for registration and incident reporting. Entity categories, authorities, terminology and procedures follow each national law.

    Is there an official NIS2 certification?

    No. There is no EU-wide NIS2 certificate or certification-body audit. National authorities supervise compliance under their implementing legislation. NIS2 readiness is an operational programme, not a legal assurance or certification.

    How should a multi-country company prepare?

    A common EU-level control baseline can be reused across establishments, but each legal entity, jurisdiction and applicable national law must be assessed separately for registration, entity categorisation, reporting channels and supervision. Group governance should coordinate consistent controls while respecting national variations.

    How much does NIS2 readiness cost?

    A scoped NIS2 readiness engagement is €6,900 when reusing an existing Asteron Compliance Core and €9,900 as a first Asteron engagement. Prices cover one legal entity, one principal jurisdiction and one agreed service scope, and exclude VAT where applicable. Multi-entity, multi-country or unusually complex environments are scoped separately.

    Turn NIS2 obligations into an operating security programme

    Determine where the law applies, establish accountable controls and prepare your organisation to manage suppliers, incidents and regulatory evidence across European markets.

    View pricing