secria.eu

what is the duty of care under NIS2 in plain language

Ten concrete measures to manage cyber risks

The duty of care means that an organisation takes appropriate measures to secure its network and information systems, and that it can demonstrate which measures those are. It is not about a single document or a single checkbox, but about a set of ten subjects that together form the foundation: from risk analysis and policy to supplier management, encryption, access control and what happens in the event of an incident. Any organisation subject to the Cyber Security Act must have organised something on each of those ten subjects — and not only on paper, but also in practice.

Important detail: the duty of care is not a fixed list of mandatory technical products. The word "appropriate" is decisive — what is appropriate for a large energy company looks different from what is appropriate for a medium-sized software supplier. The size of the organisation, the sensitivity of the data and the risk that a disruption or incident entails all play a role. An overview of which ten measures must I take according to NIS2 shows how those subjects look in content. Anyone already working with a management system such as ISO/IEC 27001 will recognise many of these subjects in the control measures of Annex A — although that in itself is no guarantee that the duty of care is fulfilled, as is also explained in do I still need ISO 27001 if I am already compliant with NIS2.

Where this comes from: Article 21 NIS2 and the Cyber Security Act

The duty of care and the ten measures are described in Article 21(2) of the NIS2 Directive; the Cyber Security Act transposes this obligation into Dutch law for the organisations that fall within its scope. The NCSC also provides information on how the duty of care and the reporting obligation work together in practice. Whether an organisation itself must comply with this obligation depends on sector and size — this can be determined via how do I know if my company falls under NIS2.

What you concretely need to do

The breakdown per obligation, including the associated deadlines and templates for documentation, is included in the subscription.

View the subscription First the free NIS2 check

This is not legal advice. This page provides general information about cybersecurity for SMEs. We do not know your business operations and do not provide sustainability advice, assurance or certification. If you are in doubt about your specific situation, consult an advisor or your accountant.

Written with AI based on the sources above, reviewed by a human on 2026-09-05. Is something incorrect? Let us know — corrections take priority.