The three duties
What do you need to arrange under NIS2?
The Dutch act revolves around three duties. They sound heavy, but in practice they cover things many organisations already partly do. The difference is that you now record them, keep them up to date and can show them.
- Registration: you enter your organisation in the national entity register of the NCSC, the Dutch National Cyber Security Centre, through the MijnNCSC portal with eHerkenning. You then keep your details up to date.
- Duty of care: you carry out a risk analysis and take appropriate measures, from incident handling and backup to secure suppliers, secure sign-in and an encryption policy.
- Incident reporting: you report a significant incident to your CSIRT and the supervisor within 24 hours of discovering it. Not every small problem needs to be reported.
- Board: management approves the measures, oversees their implementation and takes appropriate training.
