- What are the differences between the obligations under the NIS2 Directive and the requirements set out in the BIO (Baseline Informatiebeveiliging Overheid)?
- How does the duty of care under the NIS2 Directive align with existing standards such as NEN 7510 and ISO 27001?
- Which government bodies are subject to the NIS2 Directive?
- Are municipalities classified as essential entities or important entities under NIS2?
- Do suppliers also have to comply with NIS2 obligations?
- When must an entity report an incident?
- Does a supervisory authority already exist for the public sector?
- How do NIS2 and ENSIA relate to one another?
- Will supervision result in a significant administrative burden for government bodies?
- What are the liability implications for management or directors if government bodies fail to comply with the obligations under the Directive?
Duty of care
id=”v1″>1. What are the differences between the obligations under the NIS2 Directive and the requirements set out in the BIO (Baseline Information Security for Government)?
Organisations covered by the Cyberbeveiligingswet (Cbw) have a duty of care. This means they must take appropriate measures to ensure the continuity of their services as far as possible and to protect the information they use. Organisations determine these measures based on a risk assessment. The Cyberbeveiligingswet and its secondary legislation set out the duty of care in more detail. This includes the Cyberbeveiligingsbesluit (the General Administrative Order under the Cyberbeveiligingswet) and ministerial regulations issued by the relevant ministries for their sectors. For the government sector, this includes the requirement to apply the Baseline Information Security for Government (BIO)2.
id=”v2″>2. How does the duty of care under the NIS2 Directive align with existing standards such as NEN 7510 and ISO 27001
The sectors covered by the NIS2 Directive (Dutch) implement the duty of care through secondary legislation. In the public sector, this is done through the Baseline Information Security for Government (BIO). Other sectors may use different standards, such as NEN 7510 in healthcare. The relevant ministries determine which standards apply.
Scope
3. Which government bodies are subject to the NIS2 Directive?
Under the NIS2 Directive, the following government bodies will, in any event, be classified as essential entities:
- Central government (ministries and subordinate services, including executive agencies)
- Provinces
- Water authorities
- Municipalities
For the following organisations, it must first be determined whether they meet the 4 criteria for government bodies set out in the NIS2 Directive:
- Independent administrative bodies (Zbo’s, in Dutch): independent administrative bodies covered by the Framework Act on Independent Administrative Bodies are expected to meet the criteria for government bodies in most cases. They will be classified as essential entities under NIS2.
- Intergovernmental arrangements, including environmental services.
The size criteria (turnover and number of FTEs) that apply to other sectors under the NIS2 Directive do not apply to government bodies.
However, government bodies have a number of other exemptions. For example, organisations whose activities mainly concern national security, public security, defence or law enforcement, including the prevention, investigation and detection of criminal offences, are exempt from NIS2. Government bodies whose activities are only indirectly related to national security and similar areas fall within the Directive’s scope.
4. Are municipalities classified as essential entities or important entities under NIS2?
NIS2 classifies municipalities as essential entities. Former State Secretary for Kingdom Relations and Digitalisation Alexandra van Huffelen also communicated this in a letter to the umbrella organisations representing municipalities. Municipalities, provinces and water authorities are also responsible for providing several essential services, including road management and wastewater services. For this reason, they fall within the scope of NIS2.
The distinction between essential and important entities under the NIS2 Directive concerns supervision. The Ministry of the Interior and Kingdom Relations (BZK) is working with various ministries, umbrella organisations and supervisory authorities to determine how this supervision will be organised.
5. Do suppliers also have to comply with NIS2 obligations?
Suppliers that provide products or services to entities covered by the NIS2 Directive may fall under the Directive in their own right, but are not automatically covered.
As part of their duty of care, NIS2-covered entities must assess supply chain security. Suppliers can therefore expect a NIS2 entity to request information on the measures they take to address/or to impose its own requirements.
Incident reporting requirement
6. When must an entity report an incident?
The NIS2 Directive requires entities to report significant incidents to their supervisory authority and to their own Computer Security Incident Response Team (CSIRT) within 24 hours. Secondary legislation may set thresholds for determining when an incident is significant. The relevant ministries are currently working this out for their sectors.
In addition to mandatory incident reporting, entities may voluntarily report incidents to their CSIRTs. This allows organisations to receive support from their CSIRTs for these incidents and encourages organisations to report incidents to their CSIRTs.
Supervision
7. Does a supervisory authority already exist for the public sector?
The Dutch Authority for Digital Infrastructure (RDI) has been designated as the supervisory authority for the government sector. The RDI will oversee the entire information security framework and will rely primarily on information from existing accountability and supervisory structures. In November 2023, the State Secretary for Kingdom Relations and Digitalisation sent a letter to the umbrella organisations representing municipalities regarding the implications of NIS2 for the public sector (Dutch).
8. How do NIS2 and ENSIA relate to one another?
ENSIA (Uniform Standards for the Single Information Audit) is the existing accountability instrument for information security that municipal executive boards use to report to the municipal council. At the same time, they can report to specific system owners, such as those responsible for the Personal Records Database (BRP) and DigiD.
Work is underway to determine how ENSIA can be adapted for NIS2 supervision. For example, the supervisory authority can use ENSIA information to determine where additional investigation is needed.
9. Will supervision result in a significant administrative burden for government bodies?
NIS2 supervision will make use of existing accountability structures as much as possible. The information collected through these structures can be used by the supervisory authority. This means that government bodies will not need to collect the same information again for supervision.
This should allow government bodies to focus their time and capacity on improving security. The aim is also to reduce the need for supervision as government organisations mature.
Liability
10. What are the liability implications for management or directors if government bodies fail to comply with the obligations under the Directive?
NIS2 does not introduce any new liability for government leaders beyond what already applies. This does not mean there is no liability within government bodies. For example, management can already be held liable for gross negligence. Management’s liability is also separate from the political responsibilities that apply within government bodies.
The NIS2 Directive includes a provision on management liability if the obligations are not met. This provision does not directly apply to government bodies. The NIS2 Directive states that it does not affect national rules on the liability of civil servants or of elected or appointed public officials.




