By topic
NIS2 by topic
Each topic answers one question about the security measures obligation, the incident notification obligation or the registration obligation, with the reference in the directive or the Dutch Cybersecurity Act. Are you looking for an explanation from the beginning? Then start with the knowledge base.
20 topics
Getting started
- how do I know if my company falls under NIS2
- what is the difference between an essential entity and an important entity
- my customer is asking me to fill out a security questionnaire what should I do
- why do I receive security requirements if I myself do not fall under NIS2
- what is the duty of care under NIS2 in plain language
- which sectors fall under the NIS2 directive
- does NIS2 or DORA apply to my bank or insurance company
- what is the Cybersecurity Act and what is changing
In depth
- which ten measures must I take according to NIS2
- do I still need ISO 27001 if I am already compliant with NIS2
- when must I report a cyber incident to the supervisory authority
- which supervisory authority oversees my sector under NIS2
- why am I responsible for the security of my suppliers
- can the board be personally liable for NIS2 violations
- what happens if I do not comply with NIS2 obligations
Get practical
- how do I register my organisation as a NIS2 obligated entity
- which evidence document must I provide for each security measure
- who should be responsible within my organisation for a measure
- which policy documents must I have for NIS2
- why do I need a certificate of participation for a cybersecurity training
Is your situation not listed? Take the free NIS2 check — five questions, and you'll see which category your AI use falls into. Or let us know; missing topics will be prioritised.