What does NIS2 require of your organisation?
Explained for those encountering it for the first time. Every acronym is explained where it appears.
Do you know whether you fall under it?
Start here. Three questions, no account, and you will know whether you are an essential entity, an important one, or whether you receive the requirements through your customers.
Do the free NIS2 check- Does my business fall under NIS2? — Two things determine it: your sector and your size. But there is a third group that falls outside it and still receives the requirements.
- Your customer sends a security questionnaire — what now? — You do not fall under it yourself, but you receive the requirements anyway. Why that happens, and what a good answer is.
- The duty of care: the ten measures from article 21 — What is concretely expected of you, per measure — and how you can tell it is arranged.
- The reporting obligation: 24 hours, 72 hours and one month — Three moments, and none of them is the reporting obligation within 24 hours that is usually referred to.
- The Cybersecurity Act: what applies in the Netherlands — The Dutch implementation of NIS2, and why there is no phase-in period.
- NIS2 and ISO 27001: what is the difference? — The standard helps, but does not cover it. Where they overlap and where they do not.
The ten measures from the duty of care
Article 21, second paragraph of the directive lists them as a through j. This is what a dossier consists of, and what your customer's security questionnaire is based on.
-
Risk analysis and information security policy (sub a)
A documented assessment of what can go wrong, and the policy that responds to it. This is the foundation on which the other nine rest. -
Incident handling (sub b)
How you notice something is wrong, who does what then, and how you document it. Also the question of who decides whether reporting is required. -
Business continuity and crisis management (sub c)
Back-ups, recovery from an outage, and what happens if your most important system is down for a week. Including the recovery tested, not just described. -
Security in the supply chain (sub d)
The security of your suppliers and service providers, insofar as it affects your own systems. This is the provision that causes your own customers to send you a questionnaire. -
Security in procurement, development and maintenance (sub e)
How you factor security into buying or building systems, and how vulnerabilities are handled as soon as they become known. -
Assessment of effectiveness (sub f)
Measuring whether what you have arranged actually works. Without this, a list of measures remains an intention. -
Basic hygiene and awareness (sub g)
Updates, password policy, rights that are no broader than necessary — and people who know what to watch for. Training is attached to this. -
Cryptography and encryption (sub h)
When data is encrypted, in transit and at rest, and under what agreements. -
Personnel security, access policies and management of company assets (sub i)
Who has access to what, what happens when someone leaves the organization, and which devices and systems you actually have. -
Multi-factor authentication and secure communications (sub j)
Two-step verification where it matters, and secure voice, video and text communications. Also emergency communications if normal channels fail.
When must you report?
Three moments, and none of them is "the duty to report within 24 hours" that is often referred to. This only applies if you are yourself subject to the law.
| Step | Deadline | What it contains |
|---|---|---|
| Early warning | 24 hours | An initial signal: something serious is happening, possibly malicious, possibly crossing a boundary. More does not need to be included yet. |
| Incident report | 72 hours | The initial assessment: severity, consequences and, if you have them, indications of how it happened. |
| Final report | 1 month | What it was, what the cause was, what measures were taken and what the cross-border consequences were. |
The deadlines run from the moment you become aware of the incident. We prepare the texts; you submit them yourself, via your own regulator's portal.