Translate the duty of care under NIS2 and the Dutch Cybersecurity Act into concrete controls, owners and evidence.
Start with risk and board responsibility
Bring critical services, network and information systems, dependencies and threats together in one risk assessment. The board should set the direction, approve measures and oversee implementation.
For each control, show which risk it manages, who owns it, how its operation is checked and what evidence is available.
The topics below summarise the risk-management duty. They are not a complete statutory checklist. The specific measures follow from your risk assessment and the applicable rules.
- risk assessment and system security policies
- incident handling and reporting processes
- business continuity, backups and crisis management
- supply chain security
- secure development, maintenance and vulnerabilities
- effectiveness assessment, training and cyber hygiene
- cryptography, personnel, access and assets
- where appropriate: multi-factor authentication and secure communication
Make controls appropriate and proportionate
Not every organisation needs to implement the same technology in the same way. Explain why a control is appropriate to the size, exposure, potential impact of incidents and state of the art.
Document which measures are appropriate and proportionate, how they are implemented and any alternatives. Board acceptance of a risk does not remove statutory obligations. Also check the additional requirements applying to your type of organisation.
From a plan to demonstrable operation
Turn actions into a practical plan with priorities. Collect evidence as part of the work process: test results, reviews, reports, incident records and supplier assessments.
Reuse existing management systems
An existing ISO 27001 or NEN 7510 ISMS can provide many of the building blocks. Explicitly map it to the Dutch Cybersecurity Act so that additional requirements, reporting deadlines, registration and board responsibilities are not lost among existing processes.
Frequently asked questions
Is an ISO 27001 certificate sufficient for NIS2?+
It can support many controls, but does not replace an assessment of statutory applicability and additional obligations.
Must all controls be completed at once?+
Meet the applicable statutory deadlines and prioritise according to risk and legal requirements. Make outstanding issues and corrective actions visible to the board; your own priority list does not grant additional time.
Who is responsible?+
The board has an active role; implementation is assigned to appropriate owners.
Sources and further reading
We prioritise primary sources for factual and time-sensitive information. Always check the current official publication when making important decisions.
- NCSC: the risk-management duty and controlsAccessed on 20 September 2026
- EUR-Lex: NIS2 DirectiveAccessed on 20 September 2026
- Dutch Cybersecurity Act: enacted legislation (Staatsblad 2026, 187)Accessed on 20 September 2026
- Dutch Cybersecurity Decree: detailed rules and commencement (Staatsblad 2026, 189)Accessed on 20 September 2026
Related articles
This is general guidance and does not replace a legal assessment or the official standard.
