All articles

The NIS2 Directive for SMEs: what you need to know

The NIS2 Directive for SMEs: what you need to know

Cybersecurity is a hot topic, and the NIS2 Directive is the latest European legislation addressing it. This Directive is designed to strengthen cybersecurity within the EU and builds on the original NIS Directive with additional sectors and stricter measures. SMEs must take extra security measures to protect their own organisation, the supply chain in which they operate and their customers. There is also a reporting obligation: incidents must be reported to the regulator within 24 hours.

What does the NIS2 Directive mean for your organisation?

The NIS2 Directive helps SMEs improve their cybersecurity and provides protection against ever-growing threats. By complying with this Directive, you not only safeguard your business's continuity but also maintain the trust of customers and partners. The main obligations are:

  1. Risk management and assessment
    An ongoing risk management process is essential for identifying, assessing and managing potential threats and vulnerabilities. This includes regular risk assessments and documenting and accepting residual risks based on rational decision-making.
  2. Incident management and reporting obligations
    Establishing and implementing detailed procedures for reporting and responding to cybersecurity incidents is crucial. This includes reporting incidents to the competent authorities promptly and cooperating on incident response to minimise the impact.
  3. Security of ICT systems
    Write and enforce clear procedures for securing communication and information systems such as computers, servers, networks, software and mobile devices. Ensure adequate security through regular software updates and measures such as antivirus and anti-malware programs and encryption, to keep them effective against new threats.
  4. Staff training and awareness
    Providing comprehensive training and raising staff awareness of cybersecurity is essential. This ensures staff are competent in applying cybersecurity measures and aware of risks and best practices.
  5. Subcontractor management
    Manage the risks of subcontractors and subprocessors. Ensure all third parties meet NIS2 standards by documenting detailed conditions for subcontracting and subprocessing.

Extended protection for more sectors

The NIS Directive already protected sectors such as energy, transport and healthcare. The NIS2 Directive now adds sectors such as:

  • Public administration
  • Chemical industry
  • Food production
  • Digital infrastructure, such as data centres and network providers
  • Space

Implementation in the Netherlands

In the Netherlands, the NIS2 Directive is being implemented through the Cybersecurity Act (Cyberbeveiligingswet), which is currently being developed by the Ministry of Justice and Security. This means organisations must prepare for new legal obligations and adapt their security practices accordingly.

Where should you start?

Carry out a self-assessment to determine whether the NIS2 Directive applies to your organisation. This is available through the Dutch government: NIS2 Directive self-assessment.

The National Coordinator for Counterterrorism and Security (NCTV) recommends the following steps for organisations covered by the NIS2 Directive:

  1. Carry out a comprehensive risk analysis and assessment: analyse the physical and digital risks that could disrupt your services.
  2. Take measures: where possible, implement measures that better protect your organisation against these risks.
  3. Establish procedures: develop procedures to detect, monitor, resolve and report incidents.

By following these steps, an SME can not only comply with the NIS2 Directive but also establish a solid foundation for a resilient and secure digital future.

More information is available on the website of the Ministry of Economic Affairs and Climate Policy's Digital Trust Center. See the NIS2 starting point here.


Back to all articles