01Home02Services03About us04Pricing05Vacancies06Contact
Security & NIS2

NIS2 for accountants: what to look out for

24 September 2026 · 6 min read

Does your accountancy firm fall under NIS2, and what do your clients expect from you? In this article you read how NIS2 affects accountants, often via the chain, and what you can arrange now.

Max HoltropBy Max Holtrop

Accountancy firms work with sensitive financial data of many organisations. That is exactly why the question "do we fall under NIS2?" is extra relevant here. The answer is nuanced: possibly not directly, but via your clients. In this article you read how that works. Want the basics of the law first? Then read NIS2 for SMEs.

Do accountants fall directly under NIS2?

Usually not on the basis of the main rule, because accountancy is not listed as a separate sector in NIS2. But that is not the whole story. Many accountancy firms do face NIS2 via the chain: their clients fall under it and must safeguard the security of their suppliers. If you are that supplier, the requirements still land with you.

Why your clients will ask you about security

Because NIS2 obliges organisations to also assess their suppliers. If you work for companies in regulated sectors, they will want to know how you protect their data. If you cannot give a clear answer, you become a risk in their chain, and that can cost you assignments. Demonstrable security thus becomes a commercial argument.

What makes accountancy firms an attractive target?

The concentration of valuable data. At one accountant, the financial data of dozens to hundreds of clients is stored. For attackers that is a favoured target, and for you a reason to take security seriously, regardless of whether NIS2 formally applies.

What can you arrange now?

The basics, which are also good IT management:

  • Secure sign-in with multi-factor authentication (MFA) on all accounts.
  • Protection against phishing, technology plus awareness among your team.
  • Backups that you have tested for recovery.
  • Recording what you have arranged, so you can demonstrate it to clients.

You will find more steps in the NIS2 checklist for SMEs.

How IT-gemak helps accountants

We lay the technical foundation with our approach to IT security and NIS2 and help you get it demonstrably in order, so you can show your clients that their data is safe.

Want to know where you stand? Schedule a no-obligation consultation. We go through your situation and make a concrete plan.

← Back to news

Frequently asked questions

Good to know

Do accountancy firms fall under NIS2?

Usually not directly, because accountancy is not a separate NIS2 sector. But you can be affected via the chain: clients who fall under NIS2 impose security requirements on their suppliers.

Why do clients ask accountants for security measures?

Because NIS2 obliges organisations to safeguard the security of their suppliers too. If you work for regulated companies, they will want to know how you protect their data.

What can an accountancy firm do now?

Start with the basics: MFA on all accounts, phishing protection, tested backups and recording your measures. That is immediately good IT management and demonstrable to clients.

Are accountants a target for cyberattacks?

Yes. At one firm the financial data of many clients is stored, which makes it an attractive target. Good security is therefore sensible, regardless of whether NIS2 formally applies.

Questions about this?

Want to spar with a specialist?

Curious what this means for your organisation? Book a no-obligation consult — we’re happy to think along.

Book a consultation →