← Guide

What are the ten NIS2 duty of care measures?

The NIS2 duty of care consists of ten measures, listed in article 21(2) of the directive, from risk analysis and incident handling to encryption and multi-factor authentication. Every questionnaire you get from a customer is a variation on these ten topics. Arrange and document them once and you can handle any list.

Anyone reading the Dutch Cybersecurity Act in search of a list of concrete requirements ends up at article 21(2) of the underlying NIS2 directive. It lists ten topics, labelled (a) through (j). They are deliberately written to be technology-neutral: the law says what has to be arranged, not with which product.

For a supplier, these ten are the whole playing field. The questionnaires you receive from customers differ in length and tone, but virtually every question traces back to one of these topics.

Which ten measures are they?

  1. Risk analysis and security policy: knowing what can go wrong and recording how you deal with it.
  2. Incident handling: knowing what you do when it goes wrong, including the report within 24 hours.
  3. Business continuity and backups: keeping going and recovering when systems fail.
  4. Supply chain security: knowing and assessing your own suppliers.
  5. Procurement, development and maintenance: buying secure systems and keeping them up to date.
  6. Testing effectiveness: checking that the measures work, not only that they exist.
  7. Cyber hygiene and training: staff and directors who know what they are doing.
  8. Cryptography and encryption: encrypting devices, connections and backups.
  9. Personnel and access control: who can reach what, and access stopping when employment stops.
  10. Multi-factor authentication and secure communication: MFA on everything reachable from the internet, and staying reachable in a crisis.

Do I have to have all ten fully in order?

The law asks for measures that fit your risks and your size; that is called proportionality. A company of fifteen people does not have to build a security department. What customers do expect: that you can say per topic what you have arranged, and that the basics (MFA, backups, incident reporting, patches) are demonstrably in place.

"Demonstrably" is the key word there. A measure that is recorded nowhere does not exist as far as an auditor is concerned. That is why each of the ten pages above ends with what you need to have on paper.

What does proportionate look like for a small company?

The directive names four things the size of a measure may be hung on: the risks you run, the likelihood and severity of an incident, the state of the art, and the cost relative to the company. That is not an escape clause but a yardstick, and it works both ways. An IT service provider with administrative access to a hospital's systems weighs heavier than a caterer with a pass for the canteen, even if both have fifteen staff.

In practice, proportionate for a small company means: the basics demonstrably in order, and one page per topic saying what you do and why that fits your situation. No security department, no certification programme, but no empty box either.

Do I need ISO 27001 for this?

No. Neither the directive nor the Dutch Cybersecurity Act prescribes a certificate. A certificate is one way to demonstrate that you have the topics under control, not the only one. For most suppliers the remedy costs more than the problem: months of work and a recurring audit bill, to answer a question that a filled-in answer and some evidence also answers.

The reverse does hold. If you are already certified against ISO 27001 or NEN 7510, that covers a large part of the ten topics, and you can point to your statement of applicability for many questions. If a customer explicitly asks for a certificate in the contract, that is a commercial requirement, not a legal one.

Where do I stand now?

Go through the ten topics above and decide per topic whether it is arranged, half arranged, or not at all. That is the same question a customer questionnaire asks, only spread across two hundred questions instead of ten topics.

Then tackle them in order of effort: what costs little and delivers a lot first, the heavy work after. That way, at the next questionnaire you have not only an answer but also a story about what is under way. Which order that is in practice is set out in the first steps.

Getting started yourself

Take the free scan: 39 questions in plain language, about ten minutes, no account needed. You will know where you stand and what deserves attention first, and you can share the result with your customer as a passport.

Already have a questionnaire on your desk? With Pro (€39 per month, excl. VAT) you upload it and have the answers filled in from your own scan and evidence. You review it and send it back.

Updated on 5 August 2026