secria.eu

who should be responsible within my organisation for a measure

Ownership is assignable per measure, not organization-wide

Each measure from the duty of care can be assigned to one owner within the organization, and in practice this works better than a general 'security is everyone's responsibility' approach. Article 21(2) of the NIS2 Directive lists ten categories of measures, ranging from risk analysis to access control to incident handling, and these span across an organization. Whoever manages IT infrastructure is a logical owner for access control and network security; whoever handles HR processes fits with personnel screening and awareness training; whoever manages procurement or contracts belongs with supply chain security of suppliers. One person carrying everything, usually the owner or an IT manager at smaller organizations, becomes overburdened in practice and loses sight of the full picture.

The second paragraph addresses what ownership means in practice: not that this person executes everything themselves, but that this person knows what the status is, which evidence belongs to it, and when adjustments are needed. That oversight is precisely what a living register per measure helps with — per measure a status, evidence, and a name alongside it, instead of knowledge that exists only in someone's head. For organizations that still need to determine which measures are relevant and who fits where, a step-by-step approach is a suitable starting point, as is the question what the duty of care means in plain language before the division across owners is made.

Where this comes from: Article 21(2) and Annex A of ISO 27001

Article 21(2) of the NIS2 Directive lists the ten measures that make up the duty of care, without prescribing an internal role division — that choice lies with the organization itself. The Dutch Cybersecurity Act, as the national transposition of that Directive, repeats that obligation without imposing an organizational structure. ISO/IEC 27001 Annex A offers with its control measures a standard framework often used to translate those same ten categories into concrete, assignable tasks. The NCSC emphasizes in its guidance on the duty of care that responsibility lies with the organization as a whole, which in practice means that the internal division is a choice that fits the existing structure of that organization.

What you concretely need to do

The breakdown per obligation, including the associated deadlines and templates for documentation, is included in the subscription.

View the subscription First the free NIS2 check

This is not legal advice. This page provides general information about cybersecurity for SMEs. We do not know your business operations and do not provide sustainability advice, assurance or certification. If you are in doubt about your specific situation, consult an advisor or your accountant.

Written with AI based on the sources above, reviewed by a human on 2026-09-05. Is something incorrect? Let us know — corrections take priority.