{"id":9135,"date":"2026-07-05T13:51:53","date_gmt":"2026-07-05T13:51:53","guid":{"rendered":"https:\/\/magicstone.nl\/en\/?page_id=9135"},"modified":"2026-07-08T07:59:37","modified_gmt":"2026-07-08T07:59:37","slug":"nis2-compliance-roadmap","status":"publish","type":"page","link":"https:\/\/magicstone.nl\/en\/nis2-compliance-roadmap\/","title":{"rendered":"Your NIS2 Roadmap"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"9135\" class=\"elementor elementor-9135\" data-elementor-post-type=\"page\">\n\t\t\t\t<section class=\"elementor-element elementor-element-1956858 e-con-full e-flex wpr-particle-no wpr-jarallax-no wpr-parallax-no wpr-sticky-section-no wpr-column-slider-no wpr-equal-height-no e-con e-parent\" data-id=\"1956858\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-1e4ae02 elementor-widget__width-inherit elementor-widget elementor-widget-html\" data-id=\"1e4ae02\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<!-- NIS2 Roadmap to Compliance | Magic Stone Cyber Security -->\r\n\r\n<section class=\"ms-service-page\">\r\n\r\n  <style>\r\n    .ms-service-page { width:100%; font-family:inherit; color:#1f2933; line-height:1.65; }\r\n    .ms-service-page * { box-sizing:border-box; }\r\n\r\n    .ms-hero { width:100%; background:linear-gradient(135deg,#0f172a 0%,#1f2937 100%); color:#fff; padding:70px 6%; margin-bottom:45px; }\r\n    .ms-hero h1 { max-width:1120px; font-size:42px; line-height:1.15; margin:0 auto 20px; color:#fff; }\r\n    .ms-hero p { max-width:1120px; font-size:19px; margin:0 auto 28px; color:#e5e7eb; }\r\n    .ms-hero .ms-btn-wrap { max-width:1120px; margin:0 auto; }\r\n\r\n    .ms-content { width:100%; max-width:1120px; margin:0 auto; padding:0 20px 55px; }\r\n    .ms-section { margin-bottom:48px; }\r\n    .ms-section h2 { font-size:30px; margin-bottom:18px; color:#111827; }\r\n\r\n    .ms-btn { display:inline-block; background:#57A200; color:#fff!important; padding:14px 26px; border-radius:8px; text-decoration:none; font-weight:700; margin-top:10px; }\r\n    .ms-btn:hover { background:#468500; color:#fff!important; }\r\n    .ms-btn-secondary { display:inline-block; background:transparent; color:#57A200!important; border:2px solid #57A200; padding:12px 24px; border-radius:8px; text-decoration:none; font-weight:700; margin-top:10px; margin-left:10px; }\r\n    .ms-btn-secondary:hover { background:#57A200; color:#fff!important; }\r\n\r\n    .ms-grid-2 { display:grid; grid-template-columns:repeat(2,1fr); gap:22px; margin-top:25px; }\r\n\r\n    .ms-roadmap { margin-top:30px; position:relative; }\r\n    .ms-roadmap-step { display:flex; gap:24px; align-items:flex-start; position:relative; }\r\n    .ms-roadmap-step:not(:last-child)::after {\r\n      content:'';\r\n      position:absolute;\r\n      left:27px;\r\n      top:56px;\r\n      bottom:-28px;\r\n      width:2px;\r\n      background:linear-gradient(to bottom, #57A200, #57A200aa);\r\n      z-index:0;\r\n    }\r\n    .ms-step-badge {\r\n      width:56px; height:56px; border-radius:50%;\r\n      background:#0f172a; border:2px solid #57A200;\r\n      color:#57A200; font-size:20px; font-weight:800;\r\n      display:flex; align-items:center; justify-content:center;\r\n      flex-shrink:0; font-family:inherit; position:relative; z-index:1;\r\n    }\r\n    .ms-step-card {\r\n      flex:1; background:#fff; border:1px solid #e5e7eb;\r\n      border-radius:14px; padding:22px 24px;\r\n      box-shadow:0 4px 16px rgba(0,0,0,.04);\r\n      margin-bottom:28px;\r\n    }\r\n    .ms-step-card h3 { margin:0 0 8px; font-size:20px; color:#111827; }\r\n    .ms-step-card p { margin:0; font-size:16px; color:#3d4a5c; line-height:1.65; }\r\n    .ms-step-tag { display:inline-block; background:#f3f8ef; color:#57A200; font-size:12px; font-weight:700; padding:3px 10px; border-radius:20px; margin-bottom:10px; letter-spacing:.5px; text-transform:uppercase; }\r\n\r\n    .ms-strip { background:#f3f8ef; border-left:5px solid #57A200; padding:28px; border-radius:14px; margin:40px 0; }\r\n    .ms-warning-strip { background:#fff7ed; border-left:5px solid #f97316; padding:28px; border-radius:14px; margin:40px 0; }\r\n\r\n    .ms-authority-strip {\r\n      background:#0f172a; border-radius:14px; padding:36px;\r\n      margin:40px 0; display:flex; gap:28px; align-items:flex-start;\r\n    }\r\n    .ms-authority-icon { font-size:36px; flex-shrink:0; margin-top:2px; }\r\n    .ms-authority-strip h3 { color:#fff; font-size:22px; margin:0 0 10px; }\r\n    .ms-authority-strip p { color:#94a3b8; font-size:16px; margin:0; line-height:1.65; }\r\n    .ms-authority-strip strong { color:#e5e7eb; }\r\n\r\n    .ms-tools { display:grid; grid-template-columns:repeat(2,1fr); gap:22px; margin-top:25px; }\r\n    .ms-tool-card {\r\n      background:#fff; border:1px solid #e5e7eb; border-radius:14px;\r\n      padding:28px; box-shadow:0 4px 16px rgba(0,0,0,.04);\r\n      display:flex; flex-direction:column; gap:14px;\r\n    }\r\n    .ms-tool-card .ms-tool-label { font-size:12px; font-weight:700; color:#57A200; text-transform:uppercase; letter-spacing:.5px; }\r\n    .ms-tool-card h3 { margin:0; font-size:21px; color:#111827; }\r\n    .ms-tool-card p { margin:0; font-size:15px; color:#3d4a5c; flex:1; }\r\n\r\n    .ms-fine-grid { display:grid; grid-template-columns:repeat(3,1fr); gap:20px; margin-top:22px; }\r\n    .ms-fine-block {\r\n      background:#fff; border:1px solid #e5e7eb; border-radius:14px;\r\n      padding:26px; box-shadow:0 4px 16px rgba(0,0,0,.04);\r\n      border-top:4px solid #e8192c;\r\n    }\r\n    .ms-fine-block.green { border-top-color:#f97316; }\r\n    .ms-fine-block.dark { border-top-color:#57A200; }\r\n    .ms-fine-block h3 { margin:0 0 6px; font-size:17px; color:#111827; }\r\n    .ms-fine-block .ms-fine-amount { font-size:32px; font-weight:800; color:#e8192c; margin:6px 0 10px; line-height:1.1; }\r\n    .ms-fine-block.green .ms-fine-amount { color:#f97316; }\r\n    .ms-fine-block.dark .ms-fine-amount { color:#111827; font-size:24px; }\r\n    .ms-fine-block p { margin:0; font-size:14px; color:#3d4a5c; line-height:1.55; }\r\n    .ms-fine-label { display:inline-block; font-size:11px; font-weight:700; text-transform:uppercase; letter-spacing:.5px; padding:2px 8px; border-radius:4px; margin-bottom:10px; background:#fef2f2; color:#e8192c; }\r\n    .ms-fine-label.orange { background:#fff7ed; color:#f97316; }\r\n    .ms-fine-label.neutral { background:#f3f4f6; color:#374151; }\r\n\r\n    \/* FAQ \u2014 open style, no accordion *\/\r\n    .ms-faq-list { margin-top:20px; }\r\n    .ms-faq-item { border-bottom:1px solid #e5e7eb; padding:24px 0; }\r\n    .ms-faq-item:first-child { border-top:1px solid #e5e7eb; }\r\n    .ms-faq-item h3 { font-size:20px; margin:0 0 10px; color:#111827; }\r\n    .ms-faq-item p { font-size:16px; color:#3d4a5c; margin:0; line-height:1.7; }\r\n    .ms-faq-item p a { color:#57A200; font-weight:700; text-decoration:none; }\r\n    .ms-faq-item p a:hover { text-decoration:underline; }\r\n\r\n    .ms-cta { background:#111827; color:#fff; border-radius:18px; padding:45px 35px; text-align:center; margin-top:50px; }\r\n    .ms-cta h2 { color:#fff; font-size:32px; margin-bottom:15px; }\r\n    .ms-cta p { color:#e5e7eb; max-width:780px; margin:0 auto 22px; font-size:18px; }\r\n\r\n    .ms-list { padding-left:22px; }\r\n    .ms-list li { margin-bottom:10px; }\r\n    .ms-links a { color:#57A200; font-weight:700; text-decoration:none; }\r\n    .ms-links a:hover { text-decoration:underline; }\r\n    .ms-highlight { color:#57A200; font-weight:700; }\r\n\r\n    .ms-check-list { list-style:none; padding:0; margin:12px 0 0; }\r\n    .ms-check-list li { display:flex; gap:9px; align-items:flex-start; padding:5px 0; font-size:15px; color:#374151; }\r\n    .ms-check-list li::before { content:\"\u2713\"; color:#57A200; font-weight:700; flex-shrink:0; margin-top:1px; }\r\n\r\n    #faq { scroll-margin-top:80px; }\r\n\r\n    @media(max-width:900px) {\r\n      .ms-grid-2, .ms-tools, .ms-fine-grid { grid-template-columns:1fr; }\r\n      .ms-hero { padding:50px 24px; }\r\n      .ms-hero h1 { font-size:32px; }\r\n      .ms-btn-secondary { margin-left:0; display:block; text-align:center; margin-top:10px; }\r\n      .ms-authority-strip { flex-direction:column; gap:14px; }\r\n      .ms-roadmap-step::after { left:27px; }\r\n    }\r\n  <\/style>\r\n\r\n  <!-- HERO -->\r\n  <div class=\"ms-hero\">\r\n    <h1>Your NIS2 Roadmap \u2014 From Where You Are to Where You Need to Be<\/h1>\r\n    <p>The directive is in force. But not being ready yet is not the same as being non-compliant. What regulators want to see is a documented NIS2 roadmap and evidence you're working it. We help smaller organisations build that plan \u2014 and execute it, step by step.<\/p>\r\n    <div class=\"ms-btn-wrap\">\r\n      <a href=\"https:\/\/tidycal.com\/raviv\/45-minute-meeting\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"ms-btn\">Book a Free NIS2 Call<\/a>\r\n      <a href=\"https:\/\/magicstone.nl\/en\/nis2-compliance-checklist\/\" class=\"ms-btn-secondary\">Compliance Checklist &rarr;<\/a>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"ms-content\">\r\n\r\n    <!-- SECTION 1: Normalise -->\r\n    <div class=\"ms-section\">\r\n      <h2>Most Organisations Haven't Started Yet. That's Not the Problem.<\/h2>\r\n      <p>The problem is doing nothing. Regulators know that full compliance takes time \u2014 especially for smaller organisations without dedicated security teams. What they do not accept is inaction: no assessment, no plan, no evidence of effort.<\/p>\r\n      <p>Organisations that can demonstrate a <span class=\"ms-highlight\">documented, active NIS2 compliance roadmap<\/span> are in a fundamentally different position than those who can't. A roadmap is not just a project plan. It is your first line of defence if an authority comes knocking.<\/p>\r\n    <\/div>\r\n\r\n    <!-- DEFINITION CALLOUT -->\r\n    <div style=\"background:#f8fafc; border:1px solid #e5e7eb; border-radius:14px; padding:26px 30px; margin:0 0 40px;\">\r\n      <p style=\"margin:0; font-size:17px; color:#1f2933; line-height:1.7;\"><strong>What is a NIS2 compliance roadmap?<\/strong> A NIS2 compliance roadmap is a formal, documented plan that maps your organisation's current security controls against the ten Article 21 requirements, identifies every gap, prioritises remediation actions, and assigns clear timelines and ownership. It is the document you show to a regulator as evidence that cybersecurity risk is being actively managed at board level \u2014 and it is the first thing an authority will ask for.<\/p>\r\n    <\/div>\r\n\r\n    <!-- AUTHORITY STRIP -->\r\n    <div class=\"ms-authority-strip\">\r\n      <div class=\"ms-authority-icon\">\ud83c\udfdb\ufe0f<\/div>\r\n      <div>\r\n        <h3>What Regulators Actually Look For<\/h3>\r\n        <p>Authorities don't just ask \"are you compliant?\" They ask: <strong>Can you show us your risk assessment? Do you have a documented remediation plan? Are you actively working towards compliance?<\/strong><br><br>\r\n        A formal gap assessment that produces a written roadmap is, in itself, compliance evidence. It shows that management has taken responsibility \u2014 which is exactly what Article 20 of the directive requires.<\/p>\r\n      <\/div>\r\n    <\/div>\r\n\r\n    <!-- SECTION 2: Roadmap steps -->\r\n    <div class=\"ms-section\">\r\n      <h2>The NIS2 Compliance Roadmap \u2014 Four Steps Forward<\/h2>\r\n      <p>You don't need to solve everything at once. You need to know where you stand and start moving. Here's how the journey works.<\/p>\r\n\r\n      <div class=\"ms-roadmap\">\r\n\r\n        <div class=\"ms-roadmap-step\">\r\n          <div class=\"ms-step-badge\">1<\/div>\r\n          <div class=\"ms-step-card\">\r\n            <div class=\"ms-step-tag\">Start Here<\/div>\r\n            <h3>Find Out If You're In Scope<\/h3>\r\n            <p>Not every SME falls under the directive \u2014 but many do, and some don't know it yet. Your sector, size, and role in critical supply chains all affect your obligations. Step one is getting a clear answer, so you're building on solid ground \u2014 not assumption.<\/p>\r\n          <\/div>\r\n        <\/div>\r\n\r\n        <div class=\"ms-roadmap-step\">\r\n          <div class=\"ms-step-badge\">2<\/div>\r\n          <div class=\"ms-step-card\">\r\n            <div class=\"ms-step-tag\">Weeks 1\u20134<\/div>\r\n            <h3>See Exactly Where You Stand<\/h3>\r\n            <p>A structured gap assessment measures your current controls against all ten Article 21 requirements. No guesswork. You get a clear picture of what's in place, what's missing, and what's at risk \u2014 in plain language your board can act on. This is also the document that demonstrates active NIS2 compliance effort to regulators.<\/p>\r\n          <\/div>\r\n        <\/div>\r\n\r\n        <div class=\"ms-roadmap-step\">\r\n          <div class=\"ms-step-badge\">3<\/div>\r\n          <div class=\"ms-step-card\">\r\n            <div class=\"ms-step-tag\">Months 1\u20133<\/div>\r\n            <h3>Close the Gaps, In the Right Order<\/h3>\r\n            <p>Not everything needs to happen at once. A prioritised remediation plan tells you what to fix first, what can wait, and what you already have covered. Progress \u2014 not perfection \u2014 is what compliance looks like in practice. We stay with you through implementation, not just the report.<\/p>\r\n          <\/div>\r\n        <\/div>\r\n\r\n        <div class=\"ms-roadmap-step\">\r\n          <div class=\"ms-step-badge\">4<\/div>\r\n          <div class=\"ms-step-card\">\r\n            <div class=\"ms-step-tag\">Ongoing<\/div>\r\n            <h3>Stay Compliant as Things Change<\/h3>\r\n            <p>This is not a one-time project. Your threat environment, your suppliers, and your systems all change. Ongoing monitoring keeps your NIS2 compliance posture current \u2014 and keeps you in a position to demonstrate that to authorities at any time.<\/p>\r\n          <\/div>\r\n        <\/div>\r\n\r\n      <\/div>\r\n    <\/div>\r\n\r\n    <!-- SECTION 3: Fine risk -->\r\n    <div class=\"ms-section\">\r\n      <h2>NIS2 Fines \u2014 What's at Stake If You Do Nothing<\/h2>\r\n      <p>NIS2 fines are not theoretical. Enforcement is active in the Netherlands since July 2025 \u2014 and the penalties go well beyond a financial hit.<\/p>\r\n\r\n      <div class=\"ms-fine-grid\">\r\n\r\n        <div class=\"ms-fine-block\">\r\n          <div class=\"ms-fine-label\">Essential Entities<\/div>\r\n          <h3>Energy, healthcare, transport, digital infrastructure<\/h3>\r\n          <div class=\"ms-fine-amount\">\u20ac10M or 2%<\/div>\r\n          <p>Fines up to \u20ac10 million or 2% of global annual turnover \u2014 whichever is higher. These are the NIS2 maximum penalties for the most critical sectors.<\/p>\r\n        <\/div>\r\n\r\n        <div class=\"ms-fine-block green\">\r\n          <div class=\"ms-fine-label orange\">Important Entities<\/div>\r\n          <h3>Most in-scope SMEs fall here<\/h3>\r\n          <div class=\"ms-fine-amount\">\u20ac7M or 1.4%<\/div>\r\n          <p>Fines up to \u20ac7 million or 1.4% of global annual turnover \u2014 whichever is higher. For a mid-sized business, this is an existential number.<\/p>\r\n        <\/div>\r\n\r\n        <div class=\"ms-fine-block dark\">\r\n          <div class=\"ms-fine-label neutral\">Beyond the Fine<\/div>\r\n          <h3>Personal liability for management<\/h3>\r\n          <div class=\"ms-fine-amount\">Article 20<\/div>\r\n          <p>Under Article 20, directors and senior management can be held personally accountable for cybersecurity failures. A documented roadmap protects the individual \u2014 not just the company.<\/p>\r\n        <\/div>\r\n\r\n      <\/div>\r\n\r\n      <div class=\"ms-warning-strip\" style=\"margin-bottom:0;\">\r\n        <strong>The cost of starting is a fraction of the cost of being found standing still.<\/strong><br><br>\r\n        A compliance assessment typically takes 2\u20134 weeks and immediately produces the documented roadmap that shifts your position with regulators \u2014 even before a single gap is closed.\r\n      <\/div>\r\n    <\/div>\r\n\r\n    <!-- SECTION 4: Our tools -->\r\n    <div class=\"ms-section\">\r\n      <h2>Two Ways We Help You Get There<\/h2>\r\n      <p>Whether you're just finding your feet on compliance or ready to bring in specialists \u2014 we have the right starting point for where you are now.<\/p>\r\n      <div class=\"ms-tools\">\r\n        <div class=\"ms-tool-card\">\r\n          <div class=\"ms-tool-label\">Self-Assessment<\/div>\r\n          <h3>\ud83d\udccb NIS2 Compliance Checklist<\/h3>\r\n          <p>Work through all ten Article 21 requirements at your own pace. Identify gaps, understand your obligations, and build a picture of where you stand \u2014 before talking to anyone.<\/p>\r\n          <ul class=\"ms-check-list\">\r\n            <li>All 10 compliance areas covered<\/li>\r\n            <li>Yes \/ Partial \/ No scoring<\/li>\r\n            <li>Includes downloadable 2026 workbook<\/li>\r\n            <li>Free \u2014 no registration required<\/li>\r\n          <\/ul>\r\n          <a href=\"https:\/\/magicstone.nl\/en\/nis2-compliance-checklist\/\" class=\"ms-btn-secondary\" style=\"margin-left:0; margin-top:16px; text-align:center;\">Use the Checklist &rarr;<\/a>\r\n        <\/div>\r\n        <div class=\"ms-tool-card\" style=\"border:2px solid #57A200;\">\r\n          <div class=\"ms-tool-label\">Expert-Led<\/div>\r\n          <h3>\ud83d\udd0d NIS2 Assessment<\/h3>\r\n          <p>A structured gap assessment delivered by Magic Stone and GRSee. You get a formal gap report, a prioritised remediation roadmap, and documented evidence your organisation is taking the directive seriously.<\/p>\r\n          <ul class=\"ms-check-list\">\r\n            <li>Formal gap analysis against Article 21<\/li>\r\n            <li>Prioritised remediation roadmap<\/li>\r\n            <li>Documented compliance evidence for authorities<\/li>\r\n            <li>Implementation support included<\/li>\r\n          <\/ul>\r\n          <a href=\"https:\/\/magicstone.nl\/en\/nis2-assessment\/\" class=\"ms-btn\" style=\"margin-top:16px; text-align:center; display:block;\">Start Your Assessment &rarr;<\/a>\r\n        <\/div>\r\n      <\/div>\r\n    <\/div>\r\n\r\n    <!-- STRIP -->\r\n    <div class=\"ms-strip\">\r\n      <strong>You don't need to have everything in place. You need to show you're getting there.<\/strong><br><br>\r\n      Magic Stone handles the technical controls \u2014 ransomware protection, email security, endpoint protection, backup, network security, supply chain risk management. GRSee leads the compliance assessment, governance framework, and readiness validation. Together, we give you both the regulatory standing and the operational security the directive requires.<br><br>\r\n      <span class=\"ms-links\"><a href=\"https:\/\/magicstone.nl\/en\/nis2-assessment\/\">See what an NIS2 Assessment involves &rarr;<\/a><\/span>\r\n    <\/div>\r\n\r\n    <!-- FAQ \u2014 open style -->\r\n    <div class=\"ms-section\" id=\"faq\">\r\n      <h2>Frequently Asked Questions<\/h2>\r\n      <div class=\"ms-faq-list\">\r\n\r\n        <div class=\"ms-faq-item\">\r\n          <h3>Is it too late to start NIS2 compliance?<\/h3>\r\n          <p>It's not too late to start \u2014 but every week of inaction increases your exposure. Starting a formal assessment now gives you a documented compliance posture immediately. Regulators treat organisations with an active, written roadmap very differently from those with no evidence of effort. The sooner you begin, the stronger your position.<\/p>\r\n        <\/div>\r\n\r\n        <div class=\"ms-faq-item\">\r\n          <h3>How long does it take for an SME to get compliant?<\/h3>\r\n          <p>The initial gap assessment takes 2\u20134 weeks. Closing the most critical gaps typically takes 2\u20133 months for an SME starting from a reasonable baseline. Some controls \u2014 MFA, email security, backup \u2014 can be implemented quickly. Others, like governance frameworks and supply chain risk management, take longer. We help you sequence it so the highest-risk issues close first.<\/p>\r\n        <\/div>\r\n\r\n        <div class=\"ms-faq-item\">\r\n          <h3>What does a NIS2 compliance roadmap look like?<\/h3>\r\n          <p>A NIS2 compliance roadmap is a formal, documented plan that maps your current controls against Article 21 requirements, identifies every gap, prioritises remediation actions, and assigns timelines and ownership. It is the document you show a regulator as evidence that cybersecurity is being actively managed at board level. Our assessment produces this deliverable \u2014 it is compliance evidence, not a PowerPoint summary.<\/p>\r\n        <\/div>\r\n\r\n        <div class=\"ms-faq-item\">\r\n          <h3>Do we need a consultant, or can we do this ourselves?<\/h3>\r\n          <p>You can start yourself \u2014 our <a href=\"https:\/\/magicstone.nl\/en\/nis2-compliance-checklist\/\">NIS2 Compliance Checklist<\/a> is built for exactly that. But for a formal gap report and documented evidence that satisfies regulatory scrutiny, you need a structured assessment. Self-assessments are good for orientation; a formal assessment is what holds up when an authority investigates.<\/p>\r\n        <\/div>\r\n\r\n        <div class=\"ms-faq-item\">\r\n          <h3>We already have ISO 27001 \u2014 does that help?<\/h3>\r\n          <p>Significantly. ISO 27001 overlaps heavily with the directive's requirements \u2014 particularly in governance, risk management, and technical controls. We map your existing certification against your obligations so you're not duplicating effort. Most certified organisations are much closer to full compliance than they realise. The gap is usually in incident reporting timelines, supply chain documentation, and sector-specific requirements.<\/p>\r\n        <\/div>\r\n\r\n        <div class=\"ms-faq-item\">\r\n          <h3>Are SMEs really being fined for non-compliance?<\/h3>\r\n          <p>Enforcement is active. In the Netherlands, the directive entered into force in July 2025 through the Cybersecurity Act. Authorities can audit, investigate, and fine at any time \u2014 not just following an incident. Essential entities face fines up to \u20ac10 million or 2% of global turnover. Important entities \u2014 where most SMEs fall \u2014 face fines up to \u20ac7 million or 1.4%. And under Article 20, management can be held personally liable. The question is not whether enforcement will happen \u2014 it's whether you're ready when it does.<\/p>\r\n        <\/div>\r\n\r\n      <\/div>\r\n    <\/div>\r\n\r\n    <!-- Related -->\r\n    <div class=\"ms-section ms-links\">\r\n      <h2>Related<\/h2>\r\n      <ul class=\"ms-list\">\r\n        <li><a href=\"https:\/\/magicstone.nl\/en\/what-is-nis2\/\">What is NIS2? \u2014 Plain Language Guide<\/a><\/li>\r\n        <li><a href=\"https:\/\/magicstone.nl\/en\/nis2-compliance-checklist\/\">NIS2 Compliance Checklist<\/a><\/li>\r\n        <li><a href=\"https:\/\/magicstone.nl\/en\/nis2-assessment\/\">NIS2 Assessment \u2014 Gap Analysis &amp; Compliance Roadmap<\/a><\/li>\r\n        <li><a href=\"https:\/\/magicstone.nl\/en\/nis2-third-party-risk-management\/\">NIS2 &amp; Third-Party Risk Management<\/a><\/li>\r\n        <li><a href=\"https:\/\/magicstone.nl\/en\/dora-compliance-made-simple\/\">DORA \u2014 Digital Operational Resilience Act<\/a><\/li>\r\n        <li><a href=\"https:\/\/magicstone.nl\/en\/services\/ransomware-protection\/\">Ransomware Protection<\/a><\/li>\r\n        <li><a href=\"https:\/\/magicstone.nl\/en\/services\/supply-chain-risk\/\">Supply Chain Risk Management<\/a><\/li>\r\n      <\/ul>\r\n    <\/div>\r\n\r\n    <!-- CTA -->\r\n    <div class=\"ms-cta\">\r\n      <h2>Ready to Find Your Footing?<\/h2>\r\n      <p>Book a 45-minute call with Magic Stone. We'll tell you whether you're in scope, where your biggest risks are, and what your compliance roadmap looks like. No jargon. No pressure. Just clarity.<\/p>\r\n      <a href=\"https:\/\/tidycal.com\/raviv\/45-minute-meeting\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"ms-btn\">Book Your Free NIS2 Call<\/a>\r\n    <\/div>\r\n\r\n  <\/div>\r\n<\/section>\r\n\r\n<script type=\"application\/ld+json\">\r\n{\r\n  \"@context\": \"https:\/\/schema.org\",\r\n  \"@type\": \"FAQPage\",\r\n  \"mainEntity\": [\r\n    {\"@type\":\"Question\",\"name\":\"Is it too late to start NIS2 compliance?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"It's not too late to start \u2014 but every week of inaction increases your exposure. Starting a formal assessment now gives you a documented compliance posture immediately. Regulators treat organisations with an active, written roadmap very differently from those with no evidence of effort.\"}},\r\n    {\"@type\":\"Question\",\"name\":\"How long does NIS2 compliance take for an SME?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"The initial gap assessment takes 2\u20134 weeks. Closing the most critical gaps typically takes 2\u20133 months for an SME starting from a reasonable baseline. We help you sequence it so the highest-risk issues close first.\"}},\r\n    {\"@type\":\"Question\",\"name\":\"What does a NIS2 compliance roadmap actually look like?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"A NIS2 compliance roadmap is a formal, documented plan that maps your current controls against Article 21 requirements, identifies every gap, prioritises remediation actions, and assigns timelines and ownership. It is the document you show a regulator as evidence that cybersecurity is being actively managed at board level.\"}},\r\n    {\"@type\":\"Question\",\"name\":\"Are SMEs really being fined for NIS2 non-compliance?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Enforcement is active. In the Netherlands, the directive entered into force in July 2025. Essential entities face fines up to \u20ac10 million or 2% of global turnover. Important entities face fines up to \u20ac7 million or 1.4%. Under Article 20, management can also be held personally liable.\"}},\r\n    {\"@type\":\"Question\",\"name\":\"We already have ISO 27001 \u2014 does that help with NIS2?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Significantly. ISO 27001 overlaps heavily with the directive's requirements. We map your existing certification against your obligations. Most certified organisations are much closer to full compliance than they realise \u2014 gaps are usually in incident reporting timelines, supply chain documentation, and sector-specific requirements.\"}}\r\n  ]\r\n}\r\n<\/script>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Your NIS2 Roadmap \u2014 From Where You Are to Where You Need to Be The directive is in force. But not being ready yet is not the same as being non-compliant. What regulators want to see is a documented NIS2 roadmap and evidence you&#8217;re working it. We help smaller organisations build that plan \u2014 and execute it, step by step. Book a Free NIS2 Call Compliance Checklist &rarr; Most Organisations Haven&#8217;t Started Yet. That&#8217;s Not the Problem. The problem is doing nothing. Regulators know that full compliance takes time \u2014 especially for smaller organisations without dedicated security teams. What they do not accept is inaction: no assessment, no plan, no evidence of effort. Organisations that can demonstrate a documented, active NIS2 compliance roadmap are in a fundamentally different position than those who can&#8217;t. A roadmap is not just a project plan. It is your first line of defence if an authority comes knocking. What is a NIS2 compliance roadmap? A NIS2 compliance roadmap is a formal, documented plan that maps your organisation&#8217;s current security controls against the ten Article 21 requirements, identifies every gap, prioritises remediation actions, and assigns clear timelines and ownership. It is the document you show to a regulator as evidence that cybersecurity risk is being actively managed at board level \u2014 and it is the first thing an authority will ask for. \ud83c\udfdb\ufe0f What Regulators Actually Look For Authorities don&#8217;t just ask &#8220;are you compliant?&#8221; They ask: Can you show us your risk assessment? Do you have a documented remediation plan? Are you actively working towards compliance? A formal gap assessment that produces a written roadmap is, in itself, compliance evidence. It shows that management has taken responsibility \u2014 which is exactly what Article 20 of the directive requires. The NIS2 Compliance Roadmap \u2014 Four Steps Forward You don&#8217;t need to solve everything at once. You need to know where you stand and start moving. Here&#8217;s how the journey works. 1 Start Here Find Out If You&#8217;re In Scope Not every SME falls under the directive \u2014 but many do, and some don&#8217;t know it yet. Your sector, size, and role in critical supply chains all affect your obligations. Step one is getting a clear answer, so you&#8217;re building on solid ground \u2014 not assumption. 2 Weeks 1\u20134 See Exactly Where You Stand A structured gap assessment measures your current controls against all ten Article 21 requirements. No guesswork. You get a clear picture of what&#8217;s in place, what&#8217;s missing, and what&#8217;s at risk \u2014 in plain language your board can act on. This is also the document that demonstrates active NIS2 compliance effort to regulators. 3 Months 1\u20133 Close the Gaps, In the Right Order Not everything needs to happen at once. A prioritised remediation plan tells you what to fix first, what can wait, and what you already have covered. Progress \u2014 not perfection \u2014 is what compliance looks like in practice. We stay with you through implementation, not just the report. 4 Ongoing Stay Compliant as Things Change This is not a one-time project. Your threat environment, your suppliers, and your systems all change. Ongoing monitoring keeps your NIS2 compliance posture current \u2014 and keeps you in a position to demonstrate that to authorities at any time. NIS2 Fines \u2014 What&#8217;s at Stake If You Do Nothing NIS2 fines are not theoretical. Enforcement is active in the Netherlands since July 2025 \u2014 and the penalties go well beyond a financial hit. Essential Entities Energy, healthcare, transport, digital infrastructure \u20ac10M or 2% Fines up to \u20ac10 million or 2% of global annual turnover \u2014 whichever is higher. These are the NIS2 maximum penalties for the most critical sectors. Important Entities Most in-scope SMEs fall here \u20ac7M or 1.4% Fines up to \u20ac7 million or 1.4% of global annual turnover \u2014 whichever is higher. For a mid-sized business, this is an existential number. Beyond the Fine Personal liability for management Article 20 Under Article 20, directors and senior management can be held personally accountable for cybersecurity failures. A documented roadmap protects the individual \u2014 not just the company. The cost of starting is a fraction of the cost of being found standing still. A compliance assessment typically takes 2\u20134 weeks and immediately produces the documented roadmap that shifts your position with regulators \u2014 even before a single gap is closed. Two Ways We Help You Get There Whether you&#8217;re just finding your feet on compliance or ready to bring in specialists \u2014 we have the right starting point for where you are now. Self-Assessment \ud83d\udccb NIS2 Compliance Checklist Work through all ten Article 21 requirements at your own pace. Identify gaps, understand your obligations, and build a picture of where you stand \u2014 before talking to anyone. All 10 compliance areas covered Yes \/ Partial \/ No scoring Includes downloadable 2026 workbook Free \u2014 no registration required Use the Checklist &rarr; Expert-Led \ud83d\udd0d NIS2 Assessment A structured gap assessment delivered by Magic Stone and GRSee. You get a formal gap report, a prioritised remediation roadmap, and documented evidence your organisation is taking the directive seriously. Formal gap analysis against Article 21 Prioritised remediation roadmap Documented compliance evidence for authorities Implementation support included Start Your Assessment &rarr; You don&#8217;t need to have everything in place. You need to show you&#8217;re getting there. Magic Stone handles the technical controls \u2014 ransomware protection, email security, endpoint protection, backup, network security, supply chain risk management. GRSee leads the compliance assessment, governance framework, and readiness validation. Together, we give you both the regulatory standing and the operational security the directive requires. See what an NIS2 Assessment involves &rarr; Frequently Asked Questions Is it too late to start NIS2 compliance? It&#8217;s not too late to start \u2014 but every week of inaction increases your exposure. Starting a formal assessment now gives you a documented compliance posture immediately. Regulators treat organisations with an active, written roadmap very differently from those with no evidence of effort. The sooner you begin, the stronger<\/p>\n","protected":false},"author":1,"featured_media":9156,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"elementor_header_footer","meta":{"_acf_changed":false,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"disabled","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"class_list":["post-9135","page","type-page","status-publish","has-post-thumbnail","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Your NIS2 Roadmap - Where You Need to Be | Magic Stone<\/title>\n<meta name=\"description\" content=\"Not NIS2 ready yet? A documented compliance roadmap protects your organisation from fines up to \u20ac10M. See the 4-step path and how Magic Stone helps you build it.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/magicstone.nl\/en\/nis2-compliance-roadmap\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Your NIS2 Roadmap \u2014 Not Compliant Yet? Start Here.\" \/>\n<meta property=\"og:description\" content=\"NIS2 enforcement is active. Fines up to \u20ac10M. But a documented roadmap changes your position with regulators immediately \u2014 even before you&#039;re fully compliant.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/magicstone.nl\/en\/nis2-compliance-roadmap\/\" \/>\n<meta property=\"og:site_name\" content=\"Magic Stone\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/MagicStoneNL\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-08T07:59:37+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/magicstone.nl\/en\/wp-content\/uploads\/2026\/07\/nis2_roadmap_social_1200x630-scaled.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1354\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Not NIS2 Compliant Yet? Start Here.\" \/>\n<meta name=\"twitter:description\" content=\"NIS2 fines reach \u20ac10M. But a documented roadmap changes your position with regulators immediately \u2014 even before you&#039;re fully compliant. See the 4-step path.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/magicstone.nl\/en\/wp-content\/uploads\/2026\/07\/nis2_roadmap_social_1200x630-scaled.webp\" \/>\n<meta name=\"twitter:site\" content=\"@magicstone72\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/magicstone.nl\\\/en\\\/nis2-compliance-roadmap\\\/\",\"url\":\"https:\\\/\\\/magicstone.nl\\\/en\\\/nis2-compliance-roadmap\\\/\",\"name\":\"Your NIS2 Roadmap - Where You Need to Be | Magic Stone\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/magicstone.nl\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/magicstone.nl\\\/en\\\/nis2-compliance-roadmap\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/magicstone.nl\\\/en\\\/nis2-compliance-roadmap\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/magicstone.nl\\\/en\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/nis2_roadmap_social_800x800-scaled.webp\",\"datePublished\":\"2026-07-05T13:51:53+00:00\",\"dateModified\":\"2026-07-08T07:59:37+00:00\",\"description\":\"Not NIS2 ready yet? A documented compliance roadmap protects your organisation from fines up to \u20ac10M. See the 4-step path and how Magic Stone helps you build it.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/magicstone.nl\\\/en\\\/nis2-compliance-roadmap\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/magicstone.nl\\\/en\\\/nis2-compliance-roadmap\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/magicstone.nl\\\/en\\\/nis2-compliance-roadmap\\\/#primaryimage\",\"url\":\"https:\\\/\\\/magicstone.nl\\\/en\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/nis2_roadmap_social_800x800-scaled.webp\",\"contentUrl\":\"https:\\\/\\\/magicstone.nl\\\/en\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/nis2_roadmap_social_800x800-scaled.webp\",\"width\":2560,\"height\":2560,\"caption\":\"NIS2 compliance roadmap in four steps \u2014 not compliant yet? Start here. Magic Stone Cyber Security\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/magicstone.nl\\\/en\\\/nis2-compliance-roadmap\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/magicstone.nl\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Your NIS2 Roadmap\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/magicstone.nl\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/magicstone.nl\\\/en\\\/\",\"name\":\"Magic Stone\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/magicstone.nl\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/magicstone.nl\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/magicstone.nl\\\/en\\\/#organization\",\"name\":\"Magic Stone\",\"url\":\"https:\\\/\\\/magicstone.nl\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/magicstone.nl\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/magicstone.nl\\\/en\\\/wp-content\\\/uploads\\\/2026\\\/04\\\/MS-logo-txt-1024x683.png\",\"contentUrl\":\"https:\\\/\\\/magicstone.nl\\\/en\\\/wp-content\\\/uploads\\\/2026\\\/04\\\/MS-logo-txt-1024x683.png\",\"width\":1024,\"height\":683,\"caption\":\"Magic Stone\"},\"image\":{\"@id\":\"https:\\\/\\\/magicstone.nl\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/MagicStoneNL\",\"https:\\\/\\\/x.com\\\/magicstone72\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/magicstonecyber\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Your NIS2 Roadmap - Where You Need to Be | Magic Stone","description":"Not NIS2 ready yet? A documented compliance roadmap protects your organisation from fines up to \u20ac10M. See the 4-step path and how Magic Stone helps you build it.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/magicstone.nl\/en\/nis2-compliance-roadmap\/","og_locale":"en_US","og_type":"article","og_title":"Your NIS2 Roadmap \u2014 Not Compliant Yet? Start Here.","og_description":"NIS2 enforcement is active. Fines up to \u20ac10M. But a documented roadmap changes your position with regulators immediately \u2014 even before you're fully compliant.","og_url":"https:\/\/magicstone.nl\/en\/nis2-compliance-roadmap\/","og_site_name":"Magic Stone","article_publisher":"https:\/\/www.facebook.com\/MagicStoneNL","article_modified_time":"2026-07-08T07:59:37+00:00","og_image":[{"width":2560,"height":1354,"url":"https:\/\/magicstone.nl\/en\/wp-content\/uploads\/2026\/07\/nis2_roadmap_social_1200x630-scaled.webp","type":"image\/webp"}],"twitter_card":"summary_large_image","twitter_title":"Not NIS2 Compliant Yet? Start Here.","twitter_description":"NIS2 fines reach \u20ac10M. But a documented roadmap changes your position with regulators immediately \u2014 even before you're fully compliant. See the 4-step path.","twitter_image":"https:\/\/magicstone.nl\/en\/wp-content\/uploads\/2026\/07\/nis2_roadmap_social_1200x630-scaled.webp","twitter_site":"@magicstone72","twitter_misc":{"Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/magicstone.nl\/en\/nis2-compliance-roadmap\/","url":"https:\/\/magicstone.nl\/en\/nis2-compliance-roadmap\/","name":"Your NIS2 Roadmap - Where You Need to Be | Magic Stone","isPartOf":{"@id":"https:\/\/magicstone.nl\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/magicstone.nl\/en\/nis2-compliance-roadmap\/#primaryimage"},"image":{"@id":"https:\/\/magicstone.nl\/en\/nis2-compliance-roadmap\/#primaryimage"},"thumbnailUrl":"https:\/\/magicstone.nl\/en\/wp-content\/uploads\/2026\/07\/nis2_roadmap_social_800x800-scaled.webp","datePublished":"2026-07-05T13:51:53+00:00","dateModified":"2026-07-08T07:59:37+00:00","description":"Not NIS2 ready yet? A documented compliance roadmap protects your organisation from fines up to \u20ac10M. See the 4-step path and how Magic Stone helps you build it.","breadcrumb":{"@id":"https:\/\/magicstone.nl\/en\/nis2-compliance-roadmap\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/magicstone.nl\/en\/nis2-compliance-roadmap\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/magicstone.nl\/en\/nis2-compliance-roadmap\/#primaryimage","url":"https:\/\/magicstone.nl\/en\/wp-content\/uploads\/2026\/07\/nis2_roadmap_social_800x800-scaled.webp","contentUrl":"https:\/\/magicstone.nl\/en\/wp-content\/uploads\/2026\/07\/nis2_roadmap_social_800x800-scaled.webp","width":2560,"height":2560,"caption":"NIS2 compliance roadmap in four steps \u2014 not compliant yet? Start here. Magic Stone Cyber Security"},{"@type":"BreadcrumbList","@id":"https:\/\/magicstone.nl\/en\/nis2-compliance-roadmap\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/magicstone.nl\/en\/"},{"@type":"ListItem","position":2,"name":"Your NIS2 Roadmap"}]},{"@type":"WebSite","@id":"https:\/\/magicstone.nl\/en\/#website","url":"https:\/\/magicstone.nl\/en\/","name":"Magic Stone","description":"","publisher":{"@id":"https:\/\/magicstone.nl\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/magicstone.nl\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/magicstone.nl\/en\/#organization","name":"Magic Stone","url":"https:\/\/magicstone.nl\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/magicstone.nl\/en\/#\/schema\/logo\/image\/","url":"https:\/\/magicstone.nl\/en\/wp-content\/uploads\/2026\/04\/MS-logo-txt-1024x683.png","contentUrl":"https:\/\/magicstone.nl\/en\/wp-content\/uploads\/2026\/04\/MS-logo-txt-1024x683.png","width":1024,"height":683,"caption":"Magic Stone"},"image":{"@id":"https:\/\/magicstone.nl\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/MagicStoneNL","https:\/\/x.com\/magicstone72","https:\/\/www.linkedin.com\/company\/magicstonecyber"]}]}},"_links":{"self":[{"href":"https:\/\/magicstone.nl\/en\/wp-json\/wp\/v2\/pages\/9135","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/magicstone.nl\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/magicstone.nl\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/magicstone.nl\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/magicstone.nl\/en\/wp-json\/wp\/v2\/comments?post=9135"}],"version-history":[{"count":5,"href":"https:\/\/magicstone.nl\/en\/wp-json\/wp\/v2\/pages\/9135\/revisions"}],"predecessor-version":[{"id":9261,"href":"https:\/\/magicstone.nl\/en\/wp-json\/wp\/v2\/pages\/9135\/revisions\/9261"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/magicstone.nl\/en\/wp-json\/wp\/v2\/media\/9156"}],"wp:attachment":[{"href":"https:\/\/magicstone.nl\/en\/wp-json\/wp\/v2\/media?parent=9135"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}