NIS2 - CYBERSECURITY ACT

Obligations under NIS2

The Cybersecurity Act imposes four interrelated obligations on organizations: duty of care, duty to report, obligation of registration, and supervision. Below you can see what each obligation entails, and where you can find the full explanation.

Four obligations, one law

Duty of care

Taking appropriate technical and organizational measures to manage risks to your network and information systems. The most extensive of the four obligations.

Duty to report

Reporting significant incidents within fixed deadlines to the supervisor and the CSIRT: an early warning, a full report, and a final report.

Obligation of registration

Registering yourself in the national entity register, so that a Europe-wide picture emerges of all organizations covered by NIS2.

Supervision

Being accountable for compliance with the duty of care and duty to report: proactively for essential entities, reactively for important entities.

What falls under the duty of care?

The duty of care is the most extensive of the four obligations and touches almost every part of your organization:

What makes an incident reportable?

Among other things, the number of people affected, the duration of the disruption, and the potential financial consequences. In the event of a cyber incident, you also report to the Computer Security Incident Response Team (CSIRT), which then supports you.

Do you already know where you stand?

From duty of care to supervision: we help you bring structure to all four obligations.