NIS2 is coming: what does this new cyber directive mean for your business?

The cybersecurity directive NIS2 is expected to be implemented in the Netherlands in the third quarter of 2025. Do you supply vehicles/tools, parts or services to large and essential companies? If so, these "NIS2 companies" may ask you to demonstrate that your online security is in order. It is therefore important to take time to prepare now.
NIS2 is designed to better protect vital and important sectors - such as healthcare, energy and government agencies - from cyber threats. Fedecom companies are generally not directly covered by the NIS2 rules. But if you provide vehicles/tools, parts or services to large and essential companies and you are digitally connected (for example, through software), you may still have to deal with the law. This is because NIS2 companies must ensure that suppliers also work digitally securely to prevent cyber incidents in the chain. So they can ask you to demonstrate that you work safely. Don't you do that? Then you run the risk of losing such a customer.
What to do.
In the coming period, NIS2 companies are taking a close look at their chain. So you may receive requests to provide proof that you work digitally secure. You can do that by obtaining the NIS2 Quality Mark, for example. This is a standard for digital security specifically for SMEs. To obtain this certificate, you must take actions such as establishing procedures, training employees and getting the security of your digital systems in order.
Getting started
Want to get started on earning the NIS2 Quality Mark? Visit the Samen Digitaal Veilig platform for more information and practical tools. Samen Digitaal Veilig is hosting webinars on Wednesday, April 30, and May 7, which will provide more details on how to prepare for NIS2. These webinars are also suitable for small and medium-sized businesses and are free to attend.