Cybersecurity is not an isolated IT topic for Pegamento, but an integral part of how we work. Our customers trust us with technology, processes and data. That’s why we think it’s important to be transparent about how we handle security and where we stand in the context of NIS2.
NIS2 is the European directive that requires organizations to structurally organize and continuously improve cybersecurity. The directive goes beyond technology alone. Policy, risk management, incident reporting, vendor management and management responsibility also play an important role.
For Pegamento, this fits well with how we view security: as a continuous process that must be demonstrable, manageable and mature.
What does NIS2 mean for organizations?
NIS2 asks organizations to organize their digital resilience in a demonstrable way. That means not only taking measures, but also being able to show why those measures are appropriate and how they are managed.
It focuses on, among other things:
- risk management and security policies;
- measures to mitigate cyber risks;
- incident reporting for data breaches or cyber attacks;
- security within the supply chain;
- responsibility of board and management.
In doing so, NIS2 makes cybersecurity an explicit part of its business operations.

Our first step: pre-registration
Pegamento has taken the first step in the NIS2 process by looking at its applicability. Pre-registration is designed to determine whether an organization is covered by NIS2 and to register the organization with the appropriate regulator.
Basic information is provided for this purpose, such as:
- The sector in which an organization operates;
- the size of the organization;
- main activities.
Important to know: the pre-registration is not yet an audit nor a substantive assessment of all security measures. It is primarily an inventory and the starting point of the further process.

Understanding with the NIS2 CyberScore
In addition to pre-registration, we use the NIS2 CyberScore questionnaire to gain insight into our cybersecurity maturity. This self-assessment helps to clarify where we are already good and where further improvement is possible. We already score an 8.6 there.
The CyberScore looks at topics such as:
- access management;
- backups and recovery;
- incident response;
- awareness and training;
- supplier management.
The result is a score with concrete areas for improvement. This makes the CyberScore a practical basis for a targeted action plan toward further compliance.
What this means for our customers
For our customers, this means that Pegamento takes a serious and transparent approach to security. We don’t wait, but actively map out where we stand, which measures are already in place and where further improvement is needed.
NIS2 requires demonstrable cybersecurity. By carefully addressing pre-registration and CyberScore, we show that security at Pegamento is not just a promise, but part of the way we work.
That fits our role as a technology partner. Customers must be able to trust us to handle systems, data, processes and supply chain responsibility with care.
Security as a continuous improvement process
For us, NIS2 is not a checklist to be ticked off once. Cybersecurity requires constant attention. Threats change, organizations evolve and laws and regulations become more and more concrete.
Therefore, we use the insights from the pre-registration and CyberScore as a basis for further improvement. Where necessary, we tighten policy, processes and measures. In this way, we continue to work on safe, reliable and future-proof services.
Transparent, serious and mature
Pegamento sees NIS2 as an important step in further professionalizing cybersecurity within organizations. The pre-registration and CyberScore give us insight into where we are now and what steps are logical towards further compliance.
In addition, NIS2 touches on an issue that is becoming important to more and more organizations: data sovereignty. Customers want to know where their data is processed, who has access to systems and what dependencies there are within the vendor chain. For Pegamento, this is part of the same security approach. Digital resilience is not only about technical measures, but also about control, transparency and clear agreements about data, processing and responsibility. This makes NIS2 closely aligned with our broader vision of secure and reliable services.
For our customers, the message is clear: Pegamento takes security seriously, works demonstrably on improvement and opts for transparency. This is how we continue to build trust, continuity and digital resilience.

