Cybersecurity & Network Management | 4 min read

NIS2 Regulations in Practice: What Does the Dutch Cybersecurity Act Mean for Your Network Security?

The Dutch Cybersecurity Act (NIS2) sets strict requirements for the digital infrastructure and supply chain security of organizations. Discover what the duty of care entails and how to set up your network for NIS2 compliance.

NIS2 Regulations in Practice: What Does the Dutch Cybersecurity Act Mean for Your Network Security?

Sectie 1

1. Introduction

Digital security is no longer optional. With the formal implementation of the Dutch Cybersecurity Act (NIS2) and the Critical Entities Resilience Act (Wwke), clear legal frameworks now govern the protection of digital infrastructure in the Netherlands. Where previous legislation applied only to a select group of critical operators, NIS2 has a significantly broader scope. Many more organizations and sectors now fall under these rules. Since the government holds organizations responsible for compliance, it's essential to understand what this means for your daily network management and IT infrastructure.

Sectie 2

2. 1. The Scope of NIS2: From Essential Entity to Supply Chain Responsibility

The Cybersecurity Act requires organizations to assess whether they qualify as an 'essential' or 'important' entity based on their sector and size (such as number of employees and annual revenue):

Essential entities: Subject to proactive supervision, where regulators also conduct prior inspections.

Important entities: Subject to reactive oversight, where inspections occur following incidents or non-compliance signals.

Organizations not directly covered by the law will also feel the impact through supply chain security requirements. Organizations subject to the law are required to impose stricter security demands on their suppliers and service providers. This means you must be able to demonstrate that your network infrastructure—from access points and switches to routers and firewalls—is demonstrably secure and proactively managed.

Sectie 3

3. 2. The Four Core Obligations Under the Law

Organizations falling under the Cybersecurity Act face four central obligations:

Duty of Care: Taking appropriate and proportionate technical and organizational measures to manage risks to network and information systems. This includes risk analyses, incident management, business continuity, and supply chain security.

Reporting Obligation: In the event of a significant incident, there is a strict timeline. An initial notification must be submitted within 24 hours of discovery through the central NCSC portal and to the competent supervisory authority.

Registration Obligation: Entities must register in the national entity register via MijnNCSC.

Management Responsibility: The board is formally responsible for approving and ensuring compliance with security measures and has a statutory training obligation.

Supply chain security is a mandatory part of the duty of care: a secure network doesn't stop at your own door but encompasses all your digital partners.

Sectie 4

4. 3. Action Plan for NIS2 Compliance

To systematically meet the requirements of the Cybersecurity Act, follow this action plan:

  1. Run the NIS2 Self-Assessment Tool: Use the government's official self-assessment to determine whether your organization qualifies as an essential or important entity.
  2. Inventory Your Network Equipment (CMDB): Document all active network components (access points, switches, routers, and firewalls) clearly.
  3. Implement Proactive Network Management: Ensure continuous monitoring and regular firmware and security updates to prevent vulnerabilities before they are exploited.
  4. Strengthen Your Network Perimeter: Deploy an advanced firewall (such as Fortigate or Cisco) and implement VLAN segmentation and strict access controls.
  5. Establish Incident and Reporting Protocols: Create a documented procedure to report significant incidents to the NCSC within 24 hours.

Sectie 5

5. 4. How Cobra Systems Helps Meet Your Duty of Care

Independently conducting continuous risk assessments, network updates, and security checks requires significant time and expertise. Through Cobra Connectivity Care, Cobra Systems offers a managed solution that takes the technical duty of care off your shoulders.

With continuous monitoring, preventive maintenance, and proactive firewall and router management, we ensure your network performs optimally and remains continuously protected against the latest threats. This gives your organization clear documentation, an up-to-date equipment inventory (CMDB), and the confidence to demonstrate to customers, auditors, and supply chain partners that your digital infrastructure is in order.

Sectie 6

6. Conclusion

The Cybersecurity Act makes digital security and supply chain responsibility an integral part of business operations. By taking timely action, mapping your network infrastructure, and relying on proactive network management, your organization will not only meet legal requirements but also safeguard continuity and the trust of your customers.


Network Security & NIS2 Quick Scan

Want to know if your network infrastructure and firewalls meet the stricter requirements of the duty of care? Have the specialists at Cobra Systems conduct an inventory and security check.