Online success starts with your own domain name

  • .be € 8,00   € 11,50
  • .nl € 10,00   € 11,50
  • .com € 15,00
  • .eu € 10,00   € 11,50

On October 18, 2024, the NIS2 legislation will come into effect. This legislation will set a new standard for cybersecurity that many entrepreneurs will need to comply with.

What is NIS2?

NIS2 (short for 'Network and Information Security Directive') is a European directive that sets stricter requirements for network and information security. Through this directive, Europe aims to encourage its member states and service providers to better protect themselves against increasing cyber threats.

In October 2024, NIS2 will officially come into force in Belgium. The impact of this is significant. Governments, critical service providers (such as energy suppliers), and large companies must comply with the new legislation. But even smaller businesses and suppliers need to take stricter standards for their digital infrastructure into account.

Essential and important companies

Organizations to which NIS2 applies are divided into 2 categories: essential companies and important companies. The classification of an organization depends on 2 criteria: the size of the organization and the sector it operates in.


1. The sectors to which NIS2 applies

Very Critical Sectors (Essential)

  • Energy
  • Transport
  • Banks
  • Financial market infrastructure
  • Healthcare
  • Drinking water
  • Wastewater
  • Digital infrastructure (e.g. DNS and cloud services)*
  • ICT services management
  • Government
  • Space exploration

Other Critical Sectors (Important)

  • Postal and courier services
  • Waste management
  • Manufacturing, production, and distribution of chemicals
  • Production, processing, and distribution of foodstuffs
  • Manufacturing
  • Digital providers
  • Research

 

* The distinction between very critical and other critical sectors is broad. Organizations in some sectors, such as digital infrastructure, are considered essential entities regardless of the size of the organization.


2. The size of the organization

An organization is large if it:

  • Has at least 250 employees; or
  • Has an annual turnover of more than 50 million euros.

An organization is medium-sized if it:

  • Has at least 50 employees; or
  • Has an annual turnover of more than 10 million euros.

Essential or important?

Based on the above criteria, organizations are categorized into essential and important entities.

An organization is essential if it:

  • Is a large organization providing services in a very critical sector.

An organization is important if it:

  • Is a medium-sized organization providing services in a very critical sector; or
  • Is a large or medium-sized organization providing services in another critical sector.

Why the distinction?

The distinction between essential and important organizations is mainly made for control and sanctions. Essential organizations are proactively and strictly monitored, while important organizations are only monitored after incidents or when there is evidence they are not complying with the regulations.

NIS2 in 3 pillars

Both essential and important organizations must comply with various measures. These obligations can be summarized in 3 pillars.

1. Organization Registration

Organizations that fall under the NIS2 policy must register with the Cybersecurity Centre Belgium (CCB). This can be done via the Safeonweb@Work registration platform.

The registration must be completed by March 18, 2025. However, organizations that register domain names, provide hosting and cloud services, or specialize in security services must do this by December 18, 2024. Online service providers in general are therefore required to register with the CCB this year.

2. Risk assessment and control measures

Organizations must thoroughly prepare for potential risks and take measures to protect themselves. An organization must therefore develop a policy tailored to its specific situation. This includes the following:

  • A risk analysis: to identify what is crucial for normal operations and which threats may put the operations under pressure. This analysis must be regularly evaluated.
  • A continuity plan: in which the organization gathers all measures to guarantee the operation of services, even in the case of incidents.
  • Security measures: a standard set of measures and actions to help prevent cyber incidents.

3. Reporting obligation

NIS2 also requires that important and essential organizations must report significant incidents. Any event that affects the service delivery (and that of partners and suppliers), or causes harm to individuals, must be reported to the CCB.

Each organization must provide an initial warning of such an incident within 24 hours. A detailed report about the specific incident must be submitted within 72 hours.

What does nomeo do?

As a provider of domain names and DNS services, nomeo falls into the category of essential entities. This means that nomeo, as an organization, is subject to strict security measures and will be regularly audited for compliance.

Since nomeo holds an ISO 27001 certificate, we already meet an international standard for information security. We have established processes for:

  • Protecting all data
  • Drastically reducing the risk of cyber incidents
  • Ensuring continuity in case of an incident
  • Increasing the resilience of our organization

In addition to the ISO 27001 framework, we are doing everything we can to comply with all measures that NIS2 imposes on essential entities.

What is the impact on our customers, partners, and resellers?

While waiting for the final Belgian legislation, it is still unclear exactly how great the impact of NIS2 will be. What is certain is that digital service providers must tighten their resilience against cyber incidents.

Impact on our customers

Customers who register a (European) domain name with nomeo can expect an (additional) identity check. One of the main points of NIS2 is a strong data policy. The name, email address, and phone number you provide when registering a domain name will likely need to be verified.

How this verification will take place is not yet known. It will probably be similar to how international domain name (gTLD) registrations are verified today, where the domain name holder must confirm their data via email before the domain name is activated.

Impact on our partners and resellers

The impact on our partners and resellers is also difficult to assess. Providers of DNS and cloud services are subject to NIS2 because they are an essential entity. Partners and resellers who only offer domain names are categorized as important and will therefore be assessed less strictly.

We will continue to closely monitor developments within NIS2. As soon as the final legal text is available, we will provide sufficient information to our customers, partners, and resellers to ensure that all services continue as they should.

Want to learn more about NIS2? Or whether your organization falls under it and what steps you need to take? You can always reach nomeo at +32 (0)9 395 23 90 or via support@nomeo.be

Need help?
Don't hesitate to contact us.

nomeo support team
X