Skip to content

Smart Compliance

The file is always current, even if the auditor calls tomorrow

NIS2, ISO 27001 and NEN 7510 all ask the same thing every year: show what you have arranged. Our compliance team keeps that file for you inside Digital Care, so you can show it whenever someone asks.

Smart Compliance

A compliance team that takes the paperwork off your hands

NIS2 affects far more organisations than people think, and it does not stop at ticking a box once. Our compliance team keeps your file up to date inside Digital Care. You see exactly what is arranged, what is still open and what you can show when somebody asks. That turns compliance into maintenance instead of a project that starts over every year.

  • A baseline assessment that shows where you stand, in plain language
  • Measures, owners and deadlines in a single file in Digital Care
  • Evidence that grows with your environment, so it is always current
  • The same base for NIS2, ISO 27001 and NEN 7510, so no duplicated work
  • A fixed contact from the compliance team who knows your organisation

Infodatek Group is itself ISO 27001 and NEN 7510 certified. We ask nothing of you that we do not do ourselves.

Your NIS2 readiness

Quarter 3

Risk management and policy92%
Incident handling85%
Supply chain64%
Continuity and recovery78%
Staff awareness96%

Supply chain: three suppliers without signed security agreements. Proposal: include them in next month's quarterly round.

The law itself

NIS2 in plain language

Since 15 August 2026, NIS2 has applied in the Netherlands as the Cyberbeveiligingswet. Below you can read what the law asks, who keeps an eye on it and what you need to be able to demonstrate.

NIS2 is a European directive from 2022 about the digital resilience of the organisations that keep a country running. A directive does not apply directly: every country turns it into a law of its own. In the Netherlands that is the Cyberbeveiligingswet, which came into force on 15 August 2026. With no transition period, so the obligations apply from that date.

The law covers eighteen sectors: energy, drinking water and waste water, transport, banking, digital infrastructure, managed IT services, government, healthcare, food, chemicals, waste management, manufacturing, postal services and a few more. Over 8,000 Dutch organisations fall under it directly. Around them sits a far larger group that runs into it through their customers, and that is usually the group that calls us.

In short

Since when
15 August 2026. There is no grace period in which you can still leave it for a while.
For whom
Eighteen sectors, in two categories. Essential: 250 or more staff, or over €50 million in turnover and €43 million on the balance sheet. Important: 50 or more staff or over €10 million in turnover.
What it asks
Register yourself, take measures that match your own risk analysis, and report serious incidents.
Who watches
No central regulator, but ten existing inspectorates divided across the sectors. And in practice your own customers as well.

What the law asks of you

Three obligations and one instruction to the board. Briefly summarised, but there is a lot of work behind them.

Register

If you fall under it, you register your organisation yourself in the entity register through mijn.ncsc.nl. No letter arrives telling you it is your turn: working out whether you are covered is part of the obligation.

Duty of care

You carry out a risk analysis and take measures that match it: access management, backup and recovery, an incident procedure, agreements with your suppliers and training for your people. The law prescribes no brands or products, but it does ask you to explain why your choices are appropriate.

Duty to report

For a serious incident you give an early warning within 24 hours, a report with a first assessment within 72 hours, and a final account within a month. That runs through a single point at the NCSC, which reaches both the CSIRT and your supervisor.

And the board itself

The board approves the measures, keeps an eye on how they are carried out, and completes a cybersecurity training within two years, with a certificate as proof. That is not a formality: directors can be held personally accountable.

Questions we get a lot

You have it in order. And then?

These are the questions we hear most often after a baseline measurement. The law does not answer them in a single sentence. We do.

Who actually checks this?

There is no separate NIS2 regulator. Supervision is divided across ten existing inspectorates, each for their own sectors. The Rijksinspectie Digitale Infrastructuur (RDI) covers most of them, including digital infrastructure, managed IT services, energy, manufacturing, postal services and government. The Inspectie Leefomgeving en Transport (ILT) covers transport, water, waste and chemicals. De Nederlandsche Bank covers the banks, the AFM the financial market infrastructure, the NVWA food, and the Inspectie Gezondheidszorg en Jeugd healthcare. If you do not know which inspectorate is yours, the NCSC referral tree points it out.

So the NCSC is not my supervisor?

No, and that difference is worth knowing. The NCSC is your CSIRT: that is where you report an incident and where you get help with threats. It does not assess you and it does not fine you. The inspectorate for your sector does. So you can call without it counting against you.

Will somebody come round, or only once something goes wrong?

That depends on your category. As an essential entity, the supervisor may come and look of its own accord, unannounced as well. As an important entity, supervision is reactive: they only look after a report, a signal or an incident. The measures you have to take are all but identical in both cases. The difference is in how closely it is checked and in the size of the fine.

Who else may ask me for evidence?

Your customers, and in practice that happens far more often than an inspection. Anyone covered by the law has to account for the risks in their supply chain too. That turns into questionnaires, a security annex to the contract and requests for an audit report. Insurers and tenders ask for it just as readily these days.

Am I covered if I supply a company that is covered?

Formally no. You only have to register and report if you are in one of the sectors yourself and large enough. But the contract with your customer will impose requirements on you, and those can turn out stricter than the law itself. That is the route by which most smaller companies meet NIS2.

Is there a NIS2 certificate?

No. You cannot call yourself NIS2 certified, because that certification does not exist. Anyone offering such a certificate is selling their own stamp. What is recognised is ISO 27001, and NEN 7510 in healthcare. A large part of what the duty of care asks is already in there, which is exactly why we keep one file for all of it rather than three.

Who benefits from my having this in order?

You do, most of all, and not because of the law. What the duty of care asks is precisely what keeps an organisation standing on a bad day: knowing what you have, your access rights in order, a backup you have watched come back, and an agreed order of play when things go wrong. Then your customers, who increasingly have to ask, and your own board, who can show they have not been sitting still.

And if it is not in order?

The supervisor can issue an instruction and, in the last resort, a fine: up to €10 million or 2 per cent of worldwide annual turnover (whichever is higher) for essential entities, and up to €7 million or 1.4 per cent for important ones. Directors can also be held personally accountable. In practice it almost never starts with a fine, but with the question of whether you can show what you have arranged. That is exactly what the file is for.

How do I know whether I am covered?

By putting two things side by side: your sector and your size. That sounds simpler than it is, because some sectors are described broadly and managed IT services were added with NIS2. If you cannot work it out, put the question to us. We will go through it with you, and we will say so just as plainly if you are not covered.

This explanation is based on the Cyberbeveiligingswet and the guidance of the NCSC and the RDI, updated in September 2026. It is general information and not legal advice: whether the law applies to your organisation depends on your sector and your size.

Read on at the NCSC and the RDI.

Do you know whether NIS2 applies to your organisation?

In half an hour we walk through it: what is asked of you, what you already have in place and where you would start.

An Infodatek Group colleague picking up the handset of a desk phone.