The most practical ISMS platform for NIS2 / Dutch Cybersecurity Act

Normatik is the platform that helps you meet the Dutch Cybersecurity Act (NIS2) and supply chain duty-of-care requirements independently, step by step. Behind the platform is 42 BV: a software company that has built business-critical systems for organisations such as ANWB and VZVZ since 2003. These two things belong together. Anyone building software that enables others to demonstrate their information security must be able to show that they have mastered that discipline themselves.

2003The year 42 BV was founded in Zoetermeer
20+ yearsExperience in custom software and system integrations
ISO 27001Certified, with in-house Security Officers
100% NLHosted in Dutch data centres
Why we built Normatik

The Dutch Cybersecurity Act affects far more than just large organisations. Even if the law does not apply to you directly, you will encounter it through the supply chain duty of care: customers covered by the law must impose verifiable requirements on their suppliers. Increasing numbers of SMEs and suppliers therefore face questionnaires, audit requests and contractual security requirements — often without a security department of their own to respond.

The usual responses do not convince us. Struggling with spreadsheets and separate Word templates rarely produces a controlled management system. And a consultancy engagement costing €10,000 or more is disproportionate to the size of many SMEs.

Our mission is therefore simple: compliance should be a workable process, not a project that requires hiring an external party. In understandable Dutch, without security jargon, Normatik guides you through all ten duty-of-care measures in the Dutch Cybersecurity Act — from risk analysis and policies to incident handling and supplier management.

The result: a working information security system that you understand and maintain yourself, and that lets you demonstrate to customers, auditors and regulators that everything is in order. Not as a paper exercise, but as an integral part of your operations.

42 BV — building software since 2003

42 BV (Dutch Chamber of Commerce number 24293804) was founded in 2003 and operates from Zilverstraat 1 in Zoetermeer. For more than twenty years, the company has built robust custom software: enterprise Java applications, complex system integrations and, in recent years, carefully designed, secure AI applications. We use technology where it demonstrably adds value, rather than chasing hype.

This approach has led to long-term partnerships with organisations whose software cannot afford to fail:

ANWB

The DienstVerlener Beheer application for the emergency assistance centre, coordinating assistance in the Netherlands and abroad.

VZVZ

Supportal, the national platform for healthcare communication.

Videma

Systems for licensing television use in businesses.

Tingit

A registration and communication platform for healthcare.

Why this matters when you use Normatik

42 BV is ISO 27001-certified and employs its own Security Officers. This means we run an information security system ourselves, undergo annual audits and experience first-hand what works and what remains paperwork. That practical experience feeds directly into Normatik: the platform's steps, templates and checks reflect how an ISMS works in practice, not simply how it appears in a standard.

It also means continuity for you. Normatik is not a startup that might disappear from the market next year. It is a product of an established organisation with a sound business, loyal customers and twenty years of experience maintaining software built to last.

The people behind the platform

Normatik is developed and maintained by 42's permanent team in Zoetermeer: software engineers, Security Officers and designers who work on the platform every day. Two people guide that work.

Robert Bor, CTO of 42 BV

Robert Bor

CTO, 42 BV

Robert oversees Normatik's technical quality. At 42, he is responsible for software quality and robust architecture, and for the controlled use of AI: only where it demonstrably helps users, and always within strict privacy and security boundaries.

Jeffrey de Vreede, Information Security Manager at 42

Jeffrey de Vreede

Information Security Manager

Jeffrey is responsible for information security at 42 and oversees its own ISMS, including the annual ISO 27001 audits. He brings that daily experience into Normatik: the platform's measures, templates and checks are tested against how information security works in a real organisation.

The 42 team during a team day on Scheveningen beach

The 42 team during a team day in Scheveningen

Tested, not just promised

In Normatik, you record how your organisation handles risks, incidents and suppliers. That information is confidential, and we treat it accordingly. Our choices around hosting and data processing are deliberately conservative.

Security promises are easy to write. That is why we have ours assessed: 42 BV's management system is ISO 27001-certified and regularly audited externally. In-house Security Officers oversee compliance in daily development, from access management and encryption to reviewing every change to the platform. Normatik follows the same principle we ask of our users: information security is not a document in a drawer, but a demonstrably functioning process.

🇳🇱

100% Dutch hosting

All data is stored in data centres on Dutch soil, powered by sustainable energy and subject entirely to Dutch and European law.

⚖️

GDPR compliant

Data processing is documented in a data processing agreement. Your data never leaves the European Union.

🛡️

ISO 27001-certified

The management system of developer 42 BV is regularly audited externally, with in-house Security Officers overseeing compliance.

🔄

No vendor lock-in

Your data remains yours and can be exported in standard formats at any time.

Know who you are doing business with

We believe you should be able to verify who is behind a compliance platform. Normatik is a product of 42 BV, registered with the Dutch Chamber of Commerce under number 24293804, with an office at Zilverstraat 1 in Zoetermeer. You are welcome to visit for coffee and an on-site demonstration.

Would you like to see how Normatik works first? Request a no-obligation demo. In half an hour, we will show you how to move from an initial risk analysis to a demonstrably functioning ISMS — then you decide whether it suits your organisation.

Contact details

Visiting address
Zilverstraat 1, 2718 RP Zoetermeer
Chamber of Commerce number
24293804 (42 BV)
Certification
ISO/IEC 27001
Want to see how Normatik works?

Request a free demo and discover how to meet the Dutch Cybersecurity Act step by step. No obligations or commitments.

Request a free demo →