NIS2 and the Dutch Cybersecurity Act

NIS2 controls: what do you need to put in place?

From risk assessment and incidents to continuity, suppliers and board oversight.

Translate the duty of care under NIS2 and the Dutch Cybersecurity Act into concrete controls, owners and evidence.

Start with risk and board responsibility

Bring critical services, network and information systems, dependencies and threats together in one risk assessment. The board should set the direction, approve measures and oversee implementation.

For each control, show which risk it manages, who owns it, how its operation is checked and what evidence is available.

The topics below summarise the risk-management duty. They are not a complete statutory checklist. The specific measures follow from your risk assessment and the applicable rules.

  • risk assessment and system security policies
  • incident handling and reporting processes
  • business continuity, backups and crisis management
  • supply chain security
  • secure development, maintenance and vulnerabilities
  • effectiveness assessment, training and cyber hygiene
  • cryptography, personnel, access and assets
  • where appropriate: multi-factor authentication and secure communication

Make controls appropriate and proportionate

Not every organisation needs to implement the same technology in the same way. Explain why a control is appropriate to the size, exposure, potential impact of incidents and state of the art.

Document which measures are appropriate and proportionate, how they are implemented and any alternatives. Board acceptance of a risk does not remove statutory obligations. Also check the additional requirements applying to your type of organisation.

From a plan to demonstrable operation

Turn actions into a practical plan with priorities. Collect evidence as part of the work process: test results, reviews, reports, incident records and supplier assessments.

Reuse existing management systems

An existing ISO 27001 or NEN 7510 ISMS can provide many of the building blocks. Explicitly map it to the Dutch Cybersecurity Act so that additional requirements, reporting deadlines, registration and board responsibilities are not lost among existing processes.

Frequently asked questions

Is an ISO 27001 certificate sufficient for NIS2?+

It can support many controls, but does not replace an assessment of statutory applicability and additional obligations.

Must all controls be completed at once?+

Meet the applicable statutory deadlines and prioritise according to risk and legal requirements. Make outstanding issues and corrective actions visible to the board; your own priority list does not grant additional time.

Who is responsible?+

The board has an active role; implementation is assigned to appropriate owners.

Sources and further reading

We prioritise primary sources for factual and time-sensitive information. Always check the current official publication when making important decisions.

Related articles

NIS2 and the Dutch Cybersecurity ActDoes the Dutch Cybersecurity Act apply to my organisation?Read article →Suppliers and supply chain securityWhat does NIS2 mean for suppliers and the supply chain?Read article →ISO 27001What is ISO 27001 and what does it mean for your organisation?Read article →

This is general guidance and does not replace a legal assessment or the official standard.

We remember your cookie choice and display preferences. This storage is necessary for the website and your settings to work.

Clarity records clicks, scrolling and page interactions for usage analysis and session recordings. Form fields are masked. The cookies _clck (up to 1 year) and _clsk (1 day) link page views to a visit or session.

We also use Plausible for aggregated, cookieless statistics. This measurement continues if you reject cookies.

We store your choice in this browser for 30 days. Withdrawing consent may reload the page to stop tracking software that has already loaded. Read our cookie policy.