⚖️ Dutch Cybersecurity Act (NIS2) — Art. 21

Ten duty-of-care measures? We will guide you through them.

Article 21 of the Dutch Cybersecurity Act requires ten measures — from risk analysis to incident response. Normatik provides templates, checklists and guidance for every measure.

Request a free demo →

All 10 measures explained

What the law requires — and how Normatik supports you at every step.

1
Art. 21(3)(a)

Map your risks

Risk analysis is the foundation. You need to know which threats affect your organisation and how significant their impact is. Normatik helps you identify and assess all relevant risks.

Risk inventory Threat analysis
2
Art. 21(3)(b)

Set up incident response

You need a plan for when things go wrong. Who takes the lead? How do you communicate? Normatik provides ready-to-use incident response playbooks.

Incident register Playbook templates
3
Art. 21(3)(c)

Prepare for outages

What if your systems fail? How long can you manage without them? Normatik helps you create a business impact analysis (BIA), a continuity plan and a backup strategy.

BIA & continuity plan Backup strategy
4
Art. 21(2)(d)

Secure your supply chain

You depend on suppliers. You need to know which security risks they introduce. Normatik helps you assess suppliers and assign risk ratings.

Supplier assessment Supply chain risks
5
Art. 21(3)(g)

Get your cyber hygiene in order

Cyber hygiene covers daily practices: strong passwords, regular patching and safe working. Normatik helps you record awareness training and increase awareness.

Training records Awareness programme
6
Art. 21(2)(e)

Secure network and information systems

You must take measures to protect your network and systems. Normatik gives you a checklist of all the required security measures from Annex A.

Measures register Annex A checklist
7
Art. 21(3)(i)

Personnel, access & asset management

You need control over who can access which systems and data. Normatik helps you create and maintain access and asset policies.

Access policy Asset register
8
Art. 21(2)(j)

Document your authentication policy

How do you verify that someone is who they claim to be? How do you use multi-factor authentication (MFA)? Normatik provides an authentication policy template.

MFA guidelines Password policy
9
Art. 21(2)(h)

Create a cryptography policy

How do you protect sensitive data? Which encryption standards do you use? Normatik helps you establish a cryptography policy that meets the requirements.

Encryption standards Key management
10
Art. 21(2)(f)

Assess the effectiveness of your measures

You must regularly check whether your measures work. Normatik reminds you of annual reviews and audits, and helps you record progress.

Annual review Audit planning

Ready to set this up?

Normatik guides you through all 10 measures step by step. No expertise needed — we explain everything and provide all the templates and checklists.

Request a free demo →