secria.eu
Frequently asked questions

Frequently asked questions

Is this legal advice or security advice?

Neither. We structure what you provide and indicate where the regulation comes from. We do not know your network and do not assess it either. For your own situation, consult an adviser.

Do I fall under NIS2 if I'm not sure?

Take the free check: three questions and you'll know whether you are an essential entity, an important entity, or whether you receive the requirements through your customers. If you're still in doubt afterwards, assume you do — incorrectly thinking you fall outside it is the most expensive scenario.

Will I get a NIS2 certificate with this?

No, and you won't get one anywhere. There is no body that issues a certificate stating that an organisation complies with NIS2. What you get is a dossier with which you can demonstrate what you have arranged, with date and evidence. Anyone promising something else is selling something that does not exist.

Will you report an incident for me?

No, and that is a deliberate choice. Reporting goes through the portal of your own regulator, with your own login credentials. That access should not lie with a supplier. We prepare the report text, completed from your dossier, with the deadlines included — you submit it yourself.

Do you perform audits, pentests or incident response?

No. That is people's work for others, and whoever builds the dossier cannot also assess it. If you need something like that, we'll tell you and refer you on.

I don't fall under it myself. Is there anything here for me?

Probably all the more so. The vast majority of visitors do not fall under it themselves but receive a security questionnaire from a customer who does. You have no registration or reporting obligation, but without an answer you'll lose the contract.

Is the content written by AI?

The knowledge base texts are, based on official sources, with a technical review afterwards and a human approval before publication. That is also stated under every page. Your own dossier is not invented: you fill it in yourself, and anything not in it is flagged as missing.

Does ISO 27001 or NEN 7510 help me with this?

Considerably — many of the ten due care topics are covered in it, and the documentation is already arranged. But it does not cover the registration obligation, the reporting obligation and the board liability. Do not start with it solely for NIS2 reasons.

In which languages and countries does this work?

The directive applies EU-wide, so the knowledge base does too. The obligations only arise through national law, and that differs by country: for countries that have not yet transposed it, we show no deadlines and no portal, only what is known — with the date on which we last checked that status.

What do you do with my data?

Record as little as possible, and what we record you get back. Via Settings → Download all your data you export everything we have about you as a ZIP file with one click. You can also delete it yourself. Your dossier contains sensitive information about your security; see the privacy statement and the security page for how we shield that.