NIS2 readiness for European healthtech
NIS2 raises cybersecurity requirements across essential European sectors, including healthcare, medical-device manufacturing, cloud services and managed ICT services. It is implemented through national laws, so applicability, registration and supervision depend on each legal entity’s activities, size and jurisdiction. Asteron determines whether your company is directly regulated, affected through the healthcare supply chain or outside formal scope, then translates the applicable requirements into governance, controls, evidence and an incident-reporting process your team can operate.
- Applicability and entity status assessed
- Ten risk-management areas mapped
- 24-hour and 72-hour reporting prepared
- Board and supplier responsibilities defined
What is NIS2?
The NIS2 Directive establishes a common European baseline for cybersecurity risk management, incident reporting, management accountability and supervision. It applies through national legislation rather than as a single identical operating law across every EU country.
Both essential and important entities must implement proportionate technical, operational and organisational measures. National authorities determine registration, reporting channels, supervision and enforcement.
NIS2 is therefore not a checklist that can be completed once for the whole EU. A company operating across several countries may need a common control baseline combined with jurisdiction-specific obligations.
Does NIS2 apply to your healthtech company?
Handling health data or selling to a hospital does not by itself make every software company a NIS2 entity. Conversely, a company cannot assume it is excluded merely because it describes itself as a technology vendor.
The assessment must consider legal entities, employee and financial thresholds, sector classification, services provided, establishment, customer relationships and any designation based on public-health or systemic importance.
Essential and important entities
Both categories are subject to the core risk-management and incident-reporting duties. “Important” does not mean optional or low risk. Final classification follows the relevant national law and authority interpretation.
The ten NIS2 risk-management areas
A defensible NIS2 programme connects these areas to identified risks, accountable owners and operating evidence. Generic policies are insufficient if supplier reviews, access decisions, vulnerability handling, testing and incident escalation do not happen in practice.
- 1. Policies for risk analysis and information-system security
- 2. Incident handling
- 3. Business continuity, backup, disaster recovery and crisis management
- 4. Supply-chain and service-provider security
- 5. Secure acquisition, development and maintenance, including vulnerability handling and disclosure
- 6. Assessment of whether security measures remain effective
- 7. Cyber hygiene and cybersecurity training
- 8. Cryptography and encryption
- 9. Human-resources security, access control and asset management
- 10. Multi-factor authentication, secure communications and appropriate emergency communication systems
Incident reporting
Reports must use the relevant national authority or CSIRT channel. Contractual notification deadlines may be shorter and should be integrated into the same decision process.
- Step 1
Within 24 hours
Submit an early warning after becoming aware of a significant incident. It should indicate whether unlawful or malicious activity is suspected and whether cross-border impact is possible.
- Step 2
Within 72 hours
Provide the incident notification with an initial assessment of severity, impact and available indicators of compromise.
- Step 3
During the response
Supply intermediate information when requested and maintain evidence supporting containment, impact assessment and regulatory decisions.
- Step 4
Within one month
Submit the final report. If the incident is still ongoing, provide a progress report and complete the final report after handling concludes.
Board responsibility and governance
Management bodies must approve and oversee cybersecurity risk-management measures. Members are also expected to receive sufficient training to understand the organisation’s cyber risks and their consequences.
A workable governance model should define:
- - The management body that approves material risk decisions
- - The senior owner accountable for the NIS2 programme
- - Control owners responsible for day-to-day operation
- - Escalation thresholds for incidents and overdue remediation
- - Regular reporting on risk, suppliers, vulnerabilities and resilience
- - Evidence of management review and training
Responsibility for NIS2 obligations cannot be outsourced to Asteron or another security provider.
Supply-chain security
NIS2 requires organisations to consider vulnerabilities and security practices across direct suppliers and service providers.
For healthtech companies, this commonly includes cloud infrastructure, development partners, managed services, identity providers, clinical integrations, hosting providers and vendors that can affect product or service continuity.
Supplier assurance should be risk-based. It should connect procurement, due diligence, contractual requirements, ongoing monitoring, incident notification and exit planning instead of relying solely on questionnaires.
NIS2 in the Netherlands and Germany
Cyberbeveiligingswet
The Cyberbeveiligingswet implements NIS2 and enters into force on 15 August 2026. In-scope organisations face registration, duty-of-care, incident-reporting and management-accountability requirements.
Cyberbeveiligingswet Readiness →NIS2 implementation legislation
Germany’s NIS2 implementation legislation entered into force on 6 December 2025. In-scope companies use the BSI Portal for the applicable registration and incident-reporting processes.
An EU-level readiness baseline can be reused, but registration, entity categories, authorities, terminology and procedures must follow national law.
How Asteron delivers the project
Applicability assessment
Identify legal entities, sectors, size thresholds, jurisdictions and direct or indirect exposure.
Requirement mapping
Translate EU and national requirements into an agreed control baseline.
Risk and governance baseline
Define risks, responsibilities, board oversight and reporting.
Control implementation
Establish proportionate security, resilience, supplier and vulnerability processes.
Incident-reporting readiness
Align detection, escalation, regulatory decisions and national reporting channels.
Readiness validation
Review evidence, test a representative scenario and create the remaining-action roadmap.
Deliverables
Scope and governance
- - NIS2 applicability and jurisdiction assessment
- - Preliminary essential or important entity classification
- - Legal-entity and service-scope map
- - Requirement and control matrix
- - Cybersecurity risk baseline
- - Board responsibility and reporting model
- - Prioritised remediation roadmap
Operational readiness
- - NIS2 policy and evidence set
- - Supplier-security workflow
- - Vulnerability-management requirements
- - Business-continuity and crisis-management alignment
- - Incident classification and reporting runbook
- - 24-hour and 72-hour notification workflow
- - Management briefing and readiness evidence pack
NIS2 readiness pricing
Reuse established governance, risk, supplier, incident and evidence processes and add the applicable NIS2 requirements.
Establish the NIS2 readiness baseline without relying on an existing Asteron-managed compliance system.
These prices cover one legal entity, one principal jurisdiction and one agreed service scope. Multi-entity, multi-country or unusually complex environments are scoped separately. Prices exclude VAT where applicable.
What remains separate
- - Formal legal opinions or final statutory classification
- - Registration or filings made in the client’s name
- - Representation before regulators or CSIRTs
- - Technical remediation and software development
- - Penetration testing
- - Continuous vulnerability management
- - Incident-response retainers or live incident handling
- - ISO or NEN certification audits
- - Additional countries, entities or products outside the agreed scope
Responsibilities
Asteron
- - Assess likely applicability and jurisdiction
- - Map requirements to practical controls
- - Prepare governance, supplier and incident workflows
- - Review evidence and remaining gaps
- - Support readiness and management understanding
Your organisation
- - Confirm legal entities, activities, size and markets
- - Approve risks, policies and responsibilities
- - Implement and operate technical controls
- - Maintain supplier and incident information
- - Obtain legal advice where classification is uncertain
- - Make formal filings and regulatory decisions
Frequently asked questions
Does NIS2 apply to every healthtech company?
No. Applicability depends on the sector, the type of services provided, size thresholds and each Member State’s implementation of the directive. Some healthtech companies fall directly within scope, while others are affected primarily through customer or supply-chain obligations rather than as regulated entities themselves.
Are medical-device and IVD manufacturers covered?
They can be. Manufacturers of medical devices and in vitro diagnostic devices fall within the manufacturing categories used by NIS2, and certain critical medical devices receive additional treatment. Final classification follows the applicable national law and the entity’s activities, size and jurisdiction.
What is the difference between essential and important entities?
Essential entities are usually larger organisations in sectors of high criticality, plus specifically designated entities, and are subject to more proactive supervision and higher maximum fines. Important entities are commonly medium-sized organisations in high-criticality sectors or qualifying organisations in other critical sectors, supervised largely after evidence of non-compliance or an incident. Both must meet the core risk-management and reporting duties.
Can a small company still fall within scope?
Yes. NIS2 uses size thresholds as a general rule, but Member States and the directive itself allow specific designations regardless of size, including for entities whose services are systemically important, sole providers or otherwise critical. A small company should not assume it is out of scope without checking national criteria.
Does selling software to hospitals make us directly regulated?
Not automatically. Being a supplier to a hospital does not by itself make a software vendor a NIS2 entity. However, hospitals and other regulated customers must apply supply-chain security requirements, so vendors are commonly asked to demonstrate proportionate cybersecurity practices even when they are not directly regulated themselves.
Is ISO 27001 sufficient for NIS2?
No. ISO 27001 provides reusable security governance and evidence that supports NIS2 preparation, but it does not automatically establish NIS2 compliance. National authorities supervise NIS2 obligations under the applicable national law, including specific requirements on incident reporting, management responsibility and registration that are not part of an ISO 27001 audit.
What are the NIS2 incident-reporting deadlines?
For significant incidents, an early warning is required within 24 hours of awareness, an incident notification within 72 hours, intermediate information on request during the response and a final report within one month. Reporting uses the applicable national authority or CSIRT channel, and contractual notification deadlines may be shorter.
What responsibilities does the board have?
Management bodies must approve and oversee the cybersecurity risk-management measures and are expected to receive sufficient training to understand the organisation’s cyber risks and their consequences. Responsibility for NIS2 obligations cannot be outsourced to a security provider.
How does NIS2 differ between the Netherlands and Germany?
The Netherlands implements NIS2 through the Cyberbeveiligingswet, which enters into force on 15 August 2026 and uses the NCSC and sectoral authorities. Germany’s NIS2 implementation legislation entered into force on 6 December 2025, with in-scope companies using the BSI Portal for registration and incident reporting. Entity categories, authorities, terminology and procedures follow each national law.
Is there an official NIS2 certification?
No. There is no EU-wide NIS2 certificate or certification-body audit. National authorities supervise compliance under their implementing legislation. NIS2 readiness is an operational programme, not a legal assurance or certification.
How should a multi-country company prepare?
A common EU-level control baseline can be reused across establishments, but each legal entity, jurisdiction and applicable national law must be assessed separately for registration, entity categorisation, reporting channels and supervision. Group governance should coordinate consistent controls while respecting national variations.
How much does NIS2 readiness cost?
A scoped NIS2 readiness engagement is €6,900 when reusing an existing Asteron Compliance Core and €9,900 as a first Asteron engagement. Prices cover one legal entity, one principal jurisdiction and one agreed service scope, and exclude VAT where applicable. Multi-entity, multi-country or unusually complex environments are scoped separately.
Turn NIS2 obligations into an operating security programme
Determine where the law applies, establish accountable controls and prepare your organisation to manage suppliers, incidents and regulatory evidence across European markets.
Official references: European Commission NIS2 overview, Directive (EU) 2022/2555, Dutch Cyberbeveiligingswet, German BSI NIS2 registration guidance.
Last reviewed: July 2026
