Skip to content

NIS2 and the Dutch Cybersecurity Act

NIS2 and the Dutch Cybersecurity Act: learn more

The detail, topic by topic: how we approach it in practice.

The three duties

What do you need to arrange under NIS2?

The Dutch act revolves around three duties. They sound heavy, but in practice they cover things many organisations already partly do. The difference is that you now record them, keep them up to date and can show them.

  • Registration: you enter your organisation in the national entity register of the NCSC, the Dutch National Cyber Security Centre, through the MijnNCSC portal with eHerkenning. You then keep your details up to date.
  • Duty of care: you carry out a risk analysis and take appropriate measures, from incident handling and backup to secure suppliers, secure sign-in and an encryption policy.
  • Incident reporting: you report a significant incident to your CSIRT and the supervisor within 24 hours of discovering it. Not every small problem needs to be reported.
  • Board: management approves the measures, oversees their implementation and takes appropriate training.

Smart Compliance

From risk analysis to reporting: how we help

With Smart Compliance we guide you through the entire Dutch act. You do not need a lawyer or security specialist in house. We translate the law into concrete steps for your organisation and carry out many of those steps ourselves.

Infodatek is itself ISO 27001 and NEN 7510 certified. So we know from our own experience how to document information security, put it into practice and keep improving it.

  • Check: does the law apply to your organisation, directly or through the supply chain?
  • Registration: we prepare the details for the entity register with you
  • Risk analysis: we map out what matters most and where the risks are
  • Measures: from MFA and updates to backup, monitoring and supplier agreements
  • Reporting procedure: a clear incident plan, including who reports what within 24 hours
  • Board: explanation and training, so management knows what is going on

NIS2 as an opportunity

A solid foundation for your organisation

NIS2 gives you more than a tick in a box. You know better what is happening in your IT, your supplier agreements are clear and your team knows what to do when something happens. That brings peace of mind, for management too.

Customers and supply chain partners notice it as well. Demonstrably good security strengthens your position in tenders. And because we can also manage your IT, it does not stop at a report: the measures are actually carried out and maintained. If you want everything in one agreement, you end up at Digital Care, where management and security come together.

Wondering what Infodatek can do for you?

A thirty-minute call with one of our specialists. Your environment, your questions. An honest conversation.

An Infodatek Group colleague at his desk, ready to pick up the phone.