NIS2 en de
Cyber-beveiligingswet

Weet wat uw organisatie moet regelen
De Cyberbeveiligingswet maakt NIS2 in Nederland wettelijk bindend
Wat geldt voor ca. 8.000 organisaties
✓ Zorgplicht
✓ Registratieplicht
✓ Meldplicht
✓ Bestuurdersaansprakelijkheid

Controleer in vijf minuten of u eronder valt en wat uw eerste stap is.
ISOPlanner™ Supports These NIS2 Versions

Valt uw organisatie onder NIS2?

NIS2 verdeelt organisaties in essentiële en belangrijke entiteiten, op basis van sector en omvang. Daarnaast raakt de wet organisaties die zelf niet onder NIS2 vallen, maar wel leveren aan een organisatie die er wel onder valt. Die tweede groep wordt het vaakst verrast.
Drie vragen bepalen het grootste deel van het antwoord

In welke sector is uw organisatie actief?

Hoeveel medewerkers en omzet heeft u?

Levert u diensten of software aan een organisatie die onder NIS2 valt?

Hosted in EU Icon
100% Hosted in the eu
How ISOPlanner™ Supports NIS2

Wat de Cyberbeveiligingswet van u vraagt

NIS2 is een Europese richtlijn en werkt niet rechtstreeks. In Nederland is de richtlijn omgezet in de Cyberbeveiligingswet, en dat is de wet waar uw organisatie op wordt aangesproken. De wet legt vier verplichtingen op.

Zorgplicht

U beoordeelt de risico's voor uw netwerk- en informatiesystemen en neemt passende maatregelen. De maatregelenlijst is een minimum, geen volledige opsomming: wat passend is, hangt af van uw risicoprofiel.

1
Embedded ML
API Calling ML
2

Registratieplicht

Organisaties die onder de wet vallen registreren zich bij de overheid. Dat loopt via `mijn.ncsc.nl`.

Meldplicht

Een significant incident meldt u binnen 24 uur als eerste melding, gevolgd door een uitgebreidere melding binnen 72 uur en een eindrapport daarna.

3
ML Platform
API Calling ML
4

Bestuurdersaansprakelijkheid

Dit is het onderdeel dat het vaakst wordt onderschat. De RDI stelt het zo: "Het bestuur is eindverantwoordelijk voor governance en risicobeheersing." De wet maakt het mogelijk om bestuurders persoonlijk te beboeten of een last onder dwangsom op te leggen. Compliance is daarmee geen onderwerp dat uitsluitend bij IT belegd kan worden.

Registreren via mijn.ncsc.nl

Registreren en Wat u vooraf moet regelen

Registratie verloopt via `mijn.ncsc.nl` en vereist eHerkenning met een machtiging om namens uw organisatie te handelen. Over het benodigde betrouwbaarheidsniveau spreken twee officiële bronnen elkaar tegen.

Het NCSC, dat het portaal beheert, schrijft: 'Voor eHerkenning heb je betrouwbaarheidsniveau EH2+ nodig én een machtiging om namens jouw organisatie te registreren.'

De RDI, die toezicht houdt op de wet, schrijft: 'Regel toegang tot Mijn.NCSC.nl. Dit doet u via eHerkenning, minimaal veiligheidsniveau 3.'

Praktisch advies: met EH3 voldoet u aan beide lezingen. Belangrijker nog: een nieuw eHerkenningsmiddel regelt u niet dezelfde dag. Wie hier pas aan begint op het moment dat registratie moet, is te laat begonnen.
How ISOPlanner™ Supports NIS2

Van Verplichting naar Aantoonbaar op Orde

NIS2 is the EU cybersecurity directive for essential and important entities. Since 2025, suppliers to NIS2-obligated organisations must demonstrate compliance. ISOPlanner™ gives you the structure and tools to meet that obligation, built for Microsoft 365.

Uw verplichting

Wat ISOPlanner™ doet

Zorgplicht

Risicobeoordeling en maatregelen vastgelegd op één plek, met eigenaar en status.

Meldplicht

Incidentregistratie met de termijnen erin verwerkt, zodat de klok niet handmatig bewaakt wordt.

Bestuurdersaansprakelijkheid

Rapportage die aan de directie te tonen is, zonder dat iemand die eerst moet samenstellen.

Toezicht

Bewijsvoering verzameld op het moment dat het werk gebeurt, niet achteraf.

Doorgroeien

Dezelfde beheersmaatregelen hergebruikt richting ISO 27001.

Incident response to supply chain risk, regulator-ready at any time.

Book a demo
Answered

Frequently Asked Questions

01.

What is the difference between essential and important entities under NIS2?

NIS2 Article 3 divides in-scope organisations into two categories. Essential entities operate in critical sectors such as energy, transport, banking, health, and digital infrastructure. Important entities cover a broader set including postal services, waste management, food production, and digital providers. Essential entities face stricter supervision and higher maximum fines (up to €10M or 2% of global turnover). Important entities are subject to reactive supervision and lower maximum fines (€7M or 1.4%). ISOPlanner™ helps document the classification and governance obligations for either category.

02.

What security measures does NIS2 Article 21 require?

Article 21 requires appropriate and proportionate technical, operational, and organisational measures to manage cybersecurity risks. These include policies on risk analysis, incident handling, business continuity, supply chain security, secure development practices, cybersecurity training, and multi-factor authentication. ISOPlanner™ maps each Article 21 requirement to your risk register and control framework so every measure is tracked and evidenced.

03.

What are the NIS2 incident reporting timelines?

NIS2 Article 23 introduces a three-stage reporting timeline. An early warning must reach the national CSIRT or competent authority within 24 hours of detecting a significant incident. A full incident notification with initial assessment follows within 72 hours. A final report with root cause analysis, impact, and applied mitigations is due within one month. ISOPlanner™ includes an incident response workflow that tracks each stage and generates the required notification records.

04.

How does NIS2 address supply chain security?

Article 21 explicitly requires organisations to assess and manage cybersecurity risks from their supply chain and supplier relationships. This includes evaluating the security practices of direct suppliers and service providers, and considering how vulnerabilities in third-party products or services could affect your own security posture. ISOPlanner™ provides a supplier register and assessment template to document and monitor third-party security obligations under NIS2.

05.

What are the penalties for NIS2 non-compliance?

NIS2 imposes significant administrative fines. Essential entities can be fined up to €10 million or 2% of total global annual turnover, whichever is higher. Important entities face maximum fines of €7 million or 1.4% of global turnover. Beyond financial penalties, NIS2 also introduces personal liability for senior management who fail to implement required security measures. ISOPlanner™ helps document governance accountability to reduce management exposure.

06.

How does NIS2 relate to ISO 27001?

ISO 27001 and NIS2 are highly complementary. The security measures required by NIS2 Article 21 closely mirror the technical and organisational controls in ISO 27001 Annex A. Organisations with a certified ISO 27001 management system are well-positioned to meet NIS2 obligations, since ISO 27001 audit evidence can directly support NIS2 compliance demonstrations. ISOPlanner™ cross-maps NIS2 Article 21 requirements to ISO 27001 Annex A controls so a single evidence base serves both frameworks.

07.

Which sectors fall within NIS2 scope?

NIS2 covers a much broader set of sectors than its predecessor. Highly critical sectors include energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure (cloud, data centres, DNS, trust services), public administration, and space. Additional critical sectors include postal services, waste management, chemicals, food production, medical device manufacturing, and digital providers such as online marketplaces, search engines, and social networks.