For many people, it feels remote, but the government is working hard on a new cybersecurity law, and there is a chance it will affect you too. Do not worry — straightforward solutions exist.
What exactly is NIS2?
NIS2 is a European directive intended to strengthen organisations' digital resilience. With major failures such as Odido's prominent in the news, it is a hot topic. In the Netherlands, the directive is implemented through the Dutch Cybersecurity Act (Cbw). The idea is simple: as a society, we have become so dependent on digital systems that we need better arrangements around them. This concerns not only banks and energy companies, but a much wider range of organisations. The aim is to manage risks and prevent incidents, but also to limit their consequences by preparing in advance.
The first version of NIS mainly applied to large players in vital sectors. NIS2 broadens that considerably. That is precisely why it suddenly becomes relevant to many SMEs too.
Are you covered?
The law distinguishes between “essential” and “important” entities. That sounds abstract, but in practice you are likely to be affected if your business has more than 50 employees and operates in a designated sector. Examples include ICT services, manufacturing, transport, healthcare, waste management and food production, among many others.
Even if you are not directly covered, it can still affect you. Larger businesses that are covered must include their entire supply chains in their security policies. If you supply such an organisation, requirements will therefore be imposed on you too.
So even if you think “we are only a small company”, this may well become relevant to you. The biggest issue is that as a director, you are personally liable for the consequences if arrangements are inadequate and things go wrong, and fines can be substantial.
What is expected?
The law describes ten duty-of-care measures that organisations must meet. These range from risk analysis and incident response plans to access management and ensuring business continuity.
In practice, this means setting up an Information Security Management System (ISMS). It sounds complicated, but it is essentially a structured way to document how you handle information security. What risks do you face? Which measures do you take? Who is responsible for what?
For companies already working with ISO 27001, DORA or NEN 7510, there is considerable overlap. For organisations not yet working on this, however, it can feel like a mountain of work.
What is the timeline?
The European implementation deadline was originally October 2024, but Dutch legislation is running somewhat behind. The precise content is currently being determined by the House of Representatives. My advice: do not wait until the law takes effect; start preparing now. Not because you should be afraid, but because it is sensible. Good information security is valuable regardless — the law now provides an extra push to take it seriously.

It does not have to be complicated
From my own experience, I know that SME owners always try to address this risk with minimal effort. That is why we are developing a tool especially for you: a platform that guides you through the process step by step without requiring in-depth information security knowledge. The heavy groundwork — policy documents, risk analyses and measures — has already been done, so you can concentrate on what you do best: running your business. We also have an extensive ISMS ourselves, so we have the experience needed to help with the choices involved.
What can you do now?
My tip: keep it small and practical. You do not need a complete ISMS tomorrow, but you can start thinking about the basics today. Which systems are critical to your business? What would happen if they failed for a day? Who on your team is responsible for security? Which customer data passes through your organisation?
Asking those questions already gets you started. That is exactly where it begins. Naturally, I am happy to help you think it through without obligation.
More information: info@42.nl