+31 88 8040 777

NIS2: does my organisation fall under it?

NIS2 and the Dutch Cybersecurity Act set stricter requirements for digital resilience. With this checklist you determine whether your organisation falls under it and what you should do now.

NIS2 is the renewed European directive for network and information security. The Netherlands is transposing it into the Cybersecurity Act. The rules affect far more organisations than the earlier NIS legislation, including SMEs, and bring with them a duty of care, a duty to report and management liability.

Step 1: Do you fall within the scope?

NIS2 looks at sector and size. You probably fall under the law if you meet both:

  • Your organisation is active in a designated sector (such as energy, water, transport, healthcare, digital infrastructure, ICT services, waste management, food, chemicals, postal services, or government);
  • and you generally have 50+ employees or more than 10 million euros in annual turnover.

Large organisations in "essential" sectors fall into the heaviest category; medium-sized ones in "important" sectors into a lighter one. Smaller organisations can also fall under the law if they play a crucial role. Note: even if you do not fall directly under NIS2 yourself, your customers may require you to demonstrate that you work securely (supply chain responsibility).

Step 2: Know your three core obligations

  • Duty of care: take appropriate technical and organisational measures (risk management, access control, backups, incident handling, supply chain security).
  • Duty to report: report significant incidents, with a first report generally within 24 hours.
  • Management liability: the management board is responsible, must exercise oversight and demonstrate knowledge of cyber risks.

Step 3: Do the quick self-test

  • Do you have an up-to-date picture of your greatest cyber risks?
  • Are backups arranged, tested and separated from your network?
  • Can you detect and report an incident within 24 hours?
  • Do you have agreements about security with your suppliers?
  • Does your management board know what NIS2 means for them?

If you answer one or more questions with "no", then there is work to be done.

Step 4: The first concrete steps

  1. Carry out a gap analysis: where do you stand in relation to the NIS2 requirements?
  2. Draw up a risk picture and an improvement plan with priorities.
  3. Set up detection and response, so that you spot incidents in time and can report them.
  4. Document policy, roles and supplier agreements.
  5. Involve and inform the management board.

Would you like to know where your organisation stands in relation to NIS2?

View our NIS2 guidance