NovaTerrae NovaTerrae

NIS2 Compliance and Business Processes

The NIS2 Directive (EU 2022/2555) entered into force across EU member states in October 2024. For many organizations, it is the most significant piece of cybersecurity legislation since GDPR — and unlike GDPR, its impact extends deep into operational processes rather than purely into data handling practices.

Understanding what NIS2 requires, which organizations are in scope, and what the practical process implications are is essential for compliance officers, IT managers and operations leaders. This article provides a practical overview.

What Is NIS2?

NIS2 stands for Network and Information Security Directive 2. It replaced the original 2016 NIS Directive with a significantly expanded scope, stronger enforcement and higher penalties (up to €10 million or 2% of global turnover for essential entities).

The directive operates at the EU level, but each member state transposes it into national law. In the Netherlands, NIS2 was implemented through the Cyberbeveiligingswet. Organizations must comply with the national implementing legislation in each member state where they operate.

Who Falls Under NIS2?

NIS2 distinguishes between essential entities and important entities. Size thresholds apply: organizations with 50+ employees or €10M+ in annual revenue in covered sectors are typically in scope.

Essential entities include organizations in:

  • Energy (electricity, oil, gas, hydrogen)
  • Transport (road, rail, air, maritime)
  • Banking and financial market infrastructure
  • Healthcare
  • Drinking water and wastewater
  • Digital infrastructure (internet exchange points, DNS, cloud computing)
  • Public administration

Important entities include:

  • Postal and courier services
  • Waste management
  • Chemicals manufacturing and distribution
  • Food production and distribution
  • Manufacturing of medical devices, machinery, motor vehicles and electronics
  • Digital providers (search engines, online marketplaces, social networks)

Critically, NIS2 also introduces supply chain obligations. If your organization is a supplier to an in-scope entity, that entity may pass down security requirements to you contractually — even if you do not fall under NIS2 directly.

What NIS2 Requires: The Process Perspective

Article 21 of NIS2 sets out the required risk management measures. Translated into operational process terms, these include:

  • Access control and identity management: Only authorized users should be able to execute sensitive process steps. Changes to access rights must be logged and reviewable.
  • Incident detection and response: Organizations must be able to detect security incidents — including anomalous process behavior — and report significant incidents to the national authority within 24 hours (early warning) and 72 hours (detailed notification).
  • Business continuity: Processes must be designed for resilience. Organizations need backup procedures, disaster recovery plans and tested restoration capabilities.
  • Supply chain security: The security practices of suppliers and service providers must be assessed and monitored.
  • Cryptography and encryption: Sensitive data — including process data — must be protected in transit and at rest.
  • Governance and accountability: Management bodies are personally accountable for NIS2 compliance. This is new compared to NIS1 and creates direct board-level exposure.

ERP Systems and NIS2: The Gap Most Organizations Overlook

ERP systems like Business Central sit at the heart of most operational processes — purchasing, sales, inventory, finance. They are therefore a primary target for NIS2 scrutiny.

The challenge is that standard ERP configurations do not always provide the level of process event logging, anomaly detection and access control visibility that NIS2 requires. Common gaps include:

  • No tamper-evident log of who changed which process data and when
  • No automated alerting when a user performs an action outside their normal pattern
  • No monitoring of whether sensitive process steps (credit limit overrides, manual postings, payment approvals) are being executed with appropriate authorization
  • No centralized visibility into which processes are running, which are delayed and which are completing outside their expected control boundaries

Business Central does not log all security-relevant process events by default. Organizations subject to NIS2 typically need to extend their ERP with dedicated process security and audit trail capabilities to close these gaps and provide the evidence required by supervisory authorities.

Building a NIS2-Ready Process Architecture

A NIS2-ready process architecture has four layers:

  1. Logging: Every security-relevant process event is captured in an immutable log — who did what, on which record, at what time.
  2. Detection: Automated monitoring identifies deviations from expected process behavior — unauthorized access, unusual transaction volumes, bypassed controls.
  3. Response: Alerts are routed to the appropriate owner with context and suggested action. Escalation paths are defined and tested.
  4. Reporting: The organization can produce a clear, evidenced account of process security controls and any incidents to auditors or supervisory authorities.

Practical First Steps

For organizations beginning their NIS2 journey, the following sequence is commonly recommended:

  1. Determine whether your organization is an essential or important entity under national implementing legislation.
  2. Map the critical processes — the ones whose disruption would cause the greatest operational or financial harm.
  3. Assess the current security controls for those processes: what is logged, what is monitored, what is not.
  4. Identify the gaps and prioritize remediation by risk and regulatory exposure.
  5. Implement technical and organizational measures to close the priority gaps.
  6. Establish an incident response procedure and test it.
  7. Document everything — NIS2 compliance is as much about demonstrable governance as about technical controls.

Related Concepts

Want to apply this in Business Central?

Request a free Quick Scan — we analyse your specific processes and respond within 24 hours.

GDPR compliant · No spam · Privacy statement

Process Security natively in Business Central

Close the NIS2 gap in your ERP: process event logging, access control monitoring and anomaly detection — built directly into Business Central.

Business Process Security →