X Center logo white
x center icon left 1
By Scoob Admin
|
At July 22, 2026

NIS2 and document management: why it’s not an IT job

Why organizations that treat the Cybersecurity Act as a job for the IT department will end up empty-handed in front of the regulator. What OpenText and SAP have to do with it. And what we at X-Center are seeing at various Belgian companies.
X Center Experts in OpenText and SAP document management 00014

Why organizations that treat the Cybersecurity Act as a job for the IT department will end up empty-handed in front of the regulator. What OpenText and SAP have to do with it. And what we at X-Center are seeing at various Belgian companies.

NIS2, the European directive on cybersecurity, has been translated into Dutch law as the Cybersecurity Act. From 15 August 2026, new obligations apply to more than 8,000 organizations and, through the supply chain, to tens of thousands of suppliers delivering to those organizations. The Dutch Senate approved the law on 7 July 2026.

Most executives react predictably: they pass the issue on to IT. And IT treats it as a technical project: firewalls, patches, detection, a pentest. All necessary. But anyone who declares NIS2 a purely technical project misses the core of the law, and runs a real risk as a result.

The law doesn’t ask whether you’re secure. It asks whether you can prove it.

Duty of care and reporting obligation: what NIS2 actually requires

The Cybersecurity Act revolves around two core obligations: a duty of care and a reporting obligation. The duty of care (Article 21 of the NIS2 directive) requires organizations to take appropriate technical and organizational measures against cyber risks, explicitly including risks in the supply chain. The reporting obligation requires you to report serious incidents to the regulator within 24 hours.

The crucial word is demonstrable. The law doesn’t just require you to take measures; it requires you to substantiate them to regulators who proactively come to inspect. That oversight goes considerably further than what organizations are used to under the GDPR. Inspections will happen. You must be able to show appropriate measures. And in the case of demonstrable negligence, including in the supply chain, there is personal director liability.

“Demonstrably in control” is not a technical property. It’s a documentation and governance issue. And that’s where it gets stuck.

Why NIS2 evidence often falls short

Ask any organization for its information security policy, the latest risk assessment, incident procedures, data processing agreements with suppliers, and proof that the policy was reviewed and approved this year. In practice, those documents are scattered across mailboxes, network drives, SharePoint sites, Teams channels, and the laptop of someone who left last year.

That’s exactly the picture every ECM professional recognizes: versions side by side, no retention rules, critical documents in shadow IT outside any governance policy, and audit preparation that drags on because the evidence is fragmented across countless systems.

Under the GDPR, you could sometimes get away with that. Under NIS2, with a 24-hour reporting deadline and inspectors who want to see the evidence, you no longer can.

NIS2 duty of care translated into document management terms

Translate Article 21 into concrete points, and it becomes clear how much of NIS2 is, in essence, an information governance challenge:

    • Policies and risk assessments that are managed, version-controlled, and demonstrably up to date, showing who approved what and when.
    • Incident registration with a watertight timeline and logged communication, so the 24-hour report can be substantiated.
    • Supply chain documentation: supplier contracts, security addenda, certifications and assurance reports that are findable and current, because you must be able to prove your suppliers work securely.
    • Retention and access control: who can access which information, how long you retain documents, and how you delete what may be removed in an audit-proof way.
    • Business continuity: back-up, recovery and crisis plans that aren’t sitting in a drawer but are managed as living documents

This isn’t a firewall checklist. This is the daily reality of an enterprise content management platform.

OpenText and SAP: infrastructure for NIS2 compliance already in place

Here lies the opportunity many organizations overlook. Anyone already working with a mature OpenText™ Content Management (Extended ECM) system, Core Content Management, Archive Center, integrated with SAP S/4HANA or Microsoft 365, largely already has the building blocks for NIS2 demonstrability in place.

A platform like OpenText™ Content Management links unstructured content (documents, emails, contracts) directly to structured business processes in SAP and applies governance rules across a document’s entire lifecycle. Automatic classification based on process metadata. Centrally managed retention and deletion rules. Conversion to long-term formats such as PDF/A and transfer to a certified archive. Audit-proof, logged read-and-sign workflows for compliance documents.

Those are exactly the mechanisms that let you not only fulfill the duty of care, but also prove it. A controlled-document solution you deployed yesterday for ISO quality management manages your NIS2 policy file today. And an archive you set up to meet retention periods delivers the evidence at an inspection tomorrow.

For these organizations, the task is therefore often not “build something new”, but “explicitly set up and label what’s already there for NIS2”.

NIS2 at Belgian companies: what we see as X-Center

Belgium was one of the first European countries to implement NIS2 into law, with the law taking effect on 18 October 2024. Because we operate across the Benelux, we’ve seen concrete developments in content management at Belgian companies in recent months. Our ECM specialists advise and guide organizations in setting up their content platform for NIS2 compliance: what’s already in good shape, and what still needs tightening up?

What we mainly see at Belgian companies is that the emphasis lies on retention and records management. Those are precisely the areas where a well-configured OpenText platform makes an immediate difference.

Three things to do now for NIS2 compliance

  1. Treat NIS2 as a governance issue, not an IT ticket
    Make sure someone at board level owns it, and that the question “can we prove this?” becomes as central as “are we technically secure?”
  2. Bring your evidence file into one managed place
    Policies, risk assessments, incident procedures, continuity plans, and supply chain contracts belong in a governed content platform with version control, authorizations, and an audit trail, not in scattered folders.
  3. Look at what you already have
    If you’re already running on OpenText and SAP, take stock of which NIS2 obligations your existing platform can already fulfill. The distance to compliance is often smaller than you think, provided the platform is properly configured and managed.

Frequently asked questions about NIS2 and document management.

What is the deadline for the Cybersecurity Act (NIS2)?

The law takes effect on 15 August 2026. There is no transition period during which oversight doesn’t yet apply.

What does the duty of care under NIS2 mean in concrete terms?

Article 21 of the NIS2 directive requires organizations to take appropriate technical and organizational measures against cyber risks, including risks in the supply chain. These measures must be demonstrable to the regulator.

What does NIS2 have to do with document management?

Policies, risk assessments, incident registrations, supply chain contracts, and continuity plans must be demonstrable, current, and findable. That is, at its core, an information governance issue, not just a technical security issue.

How do OpenText and SAP help with NIS2 compliance?

Organizations already working with OpenText Content Management, integrated with SAP or Microsoft 365, often already have the building blocks in place: version control, retention rules, audit trails, and certified archiving.

In conclusion

The date is fixed: 15 August 2026. There’s no waiting period and no transition period during which oversight doesn’t yet apply. The organizations that will meet this deadline aren’t necessarily the ones with the most expensive security tools. They’re the ones who have their information in order and can show it.

That is, coincidentally or not, exactly what good document management has always been about.

X-Center specializes in SAP and OpenText Content Management, archiving, and cloud. Want to know which NIS2 obligations your existing content platform can already fulfill, and where the gaps are? Get in touch for a no-obligation exploration.

Vacancy details

Share this article

Table Of Contents

Featured posts

Stay updated with our latest articles, case studies, and expert perspectives

NIS2 and document management: why it’s not an IT job

Why organizations that treat the Cybersecurity Act as a job for the IT department will end up empty-handed in front of t...

The foundation for Agentic AI In SAP and OpenText ECM environments

Everyone is talking about AI. But who has already invested in it before a client asks? More and more organizations have ...

Single version of the truth

Having a “single version of the truth” is crucial for businesses… A single version of the truth? Are ...

Controlled Documents

Ensure seamless control of your organization’s documents with OpenText Extended ECM. Keep control over your...

Managed Services

Overcoming Key Challenges in OpenText Extended ECM with Proactive Application Management. As organizations continue to ...

Company Contact Day at Hogeschool Zuyd