Skip to content

NIS2 duty of care and incident reporting: what your customers will ask of you

5 min read Last checked on

The NIS2 duty of care requires measures on ten topics, from risk analysis and incident handling to supply chain security and multi-factor authentication. Incident reporting requires an early warning within 24 hours, a notification within 72 hours and a final report within one month. An ISO 27001 ISMS covers most measures, but not the statutory deadlines, registration or management training.

The NIS2 duty of care consists of ten topics listed in Article 21 of the NIS2 Directive, and incident reporting runs on three deadlines: 24 hours, 72 hours and one month. In the Netherlands both have been part of the Dutch Cybersecurity Act (Cyberbeveiligingswet) since 15 August 2026. For an IT provider with ISO 27001, the good news is that most measures are already in the ISMS. The work lies in what the law adds, and in what customers will ask of their suppliers as a result.

This page is an explanation, not legal advice.

The duty of care in ten topics

The Directive asks for appropriate and proportionate measures, based on a risk analysis that takes all hazards into account, including physical ones. How strong a measure needs to be depends on the risks, the size of the organisation and the state of the art. The Dutch NCSC stresses that an organisation decides for itself what is appropriate, with risk management as the foundation.

For cloud computing providers, data centres, managed service providers and similar digital service providers, the European Commission has spelled out the measures in Implementing Regulation (EU) 2024/2690. It is more detailed than the Directive itself.

From NIS2 topic to Annex A

The table links each topic in Article 21(2) to the ISO 27001 controls that overlap with it most. It is our own grouping, not an official mapping. ENISA publishes a more extensive mapping table alongside its technical implementation guidance.

NIS2 Art. 21(2) Topic in plain language ISO 27001
a Risk analysis and security policies clauses 6.1 and 8.2; A.5.1
b Incident handling A.5.24 to A.5.28, A.6.8
c Continuity, backup, recovery and crisis management A.5.29, A.5.30, A.8.13, A.8.14
d Supply chain security A.5.19 to A.5.23
e Secure acquisition, development and maintenance, vulnerabilities A.8.8, A.8.25 to A.8.29, A.8.32
f Assessing whether measures work clauses 9.1 to 9.3; A.5.35
g Basic cyber hygiene and training A.6.3, A.8.7, A.8.9
h Cryptography and encryption A.8.24
i Personnel, access control and assets A.6.1, A.6.2, A.6.5, A.5.9 to A.5.11, A.5.15 to A.5.18
j Multi-factor authentication and secured communication A.8.5, A.5.14

An organisation whose Statement of Applicability includes and justifies these controls has a solid starting point for the duty of care.

What ISO 27001 does not cover on its own

An ISMS is built around the risks an organisation chooses to manage. The law adds requirements that do not come out of a risk assessment:

  1. Reporting deadlines. ISO 27001 asks you to handle and communicate incidents, but sets no deadlines. The law requires an early warning within 24 hours, an incident notification within 72 hours and a final report no later than one month after that, to the CSIRT and the supervisor. Your incident procedure has to know that clock explicitly, including who decides whether an incident is significant.
  2. Informing recipients. The Directive asks you, where appropriate, to inform the recipients of your service about a significant incident and about measures they can take themselves.
  3. Registration. Registering with the NCSC, and reporting changes within 14 days, sits outside any ISMS.
  4. Management. ISO 27001 asks for leadership, but the law requires directors to formally approve the measures, oversee them and complete training.
  5. Scope. An ISO 27001 scope may be narrower than the service the law applies to. A certificate covering only the development team does not cover the production environment of a SaaS service.
  6. Mandatory topics. Under ISO 27001 you can exclude a control with a justification. The ten topics in the law are minimum topics; excluding them is not an option, though the way you meet them should fit your risks.

What your customer will ask of you

An organisation under the Dutch Cybersecurity Act must manage the risks of its suppliers. The NCSC expects it to request more information and agree terms on security measures, incident reporting, vulnerability handling and continuity. For a hosting company, SaaS provider or healthcare software supplier, that means in practice:

  • A questionnaire about your measures, often ordered along the same ten topics.
  • A certificate and its scope. Customers increasingly check whether your ISO 27001 scope includes the service they buy, and sometimes ask for the Statement of Applicability.
  • A notification deadline in the contract. Because your customer has to report within 24 hours, it will ask you to report faster. Record what you commit to and whether you can meet it outside office hours.
  • Vulnerabilities. How you find, fix and disclose vulnerabilities in your own software and in the components you use.
  • Continuity and exit. Recovery times, backups and what happens if your service stops.
  • Your own suppliers. Whether you pass the same requirements on to your cloud platform and other subcontractors.

The NCSC is clear that the law does not prescribe a certificate. An ISO 27001 certificate with a fitting scope does answer many of these questions in one go.

A practical order of work

Put the ten topics next to your Statement of Applicability and note which controls cover each one. Then work on the gaps the ISMS does not close by itself: the reporting clock in your incident procedure, a standard text for customer contracts, and a check that your scope includes the services customers ask about. Test the reporting clock in a tabletop exercise: a scenario in which the incident starts on a Friday evening quickly shows whether 24 hours is realistic.

Frequently asked questions

What does the NIS2 duty of care involve?

An organisation takes appropriate measures, based on a risk analysis, to secure its network and information systems. Article 21 of the NIS2 Directive lists ten topics those measures must at least cover. In the Netherlands this is worked out in the Cybersecurity Act (Cyberbeveiligingswet) and the Cybersecurity Decree.

Does ISO 27001 certification mean I meet the NIS2 duty of care?

Not automatically. ISO 27001 covers most of the measures, but your scope has to include the relevant systems, and the reporting deadlines, registration and management training are legal duties you arrange separately.

How quickly must an incident be reported under NIS2?

A significant incident is reported with an early warning within 24 hours, an incident notification within 72 hours and a final report no later than one month after that.

Do I have to report incidents to my customer as a supplier?

The law does not require it directly, but customers under the Cybersecurity Act increasingly put it in the contract. They need your notice to meet their own 24-hour deadline.

Read next

Sources

  1. EUR-Lex, Directive (EU) 2022/2555 (NIS2), Articles 20, 21 and 23
  2. NCSC, Duty of care under the Cybersecurity Act
  3. NCSC, Reporting incidents under the Cybersecurity Act
  4. NCSC, The Cybersecurity Act and suppliers
  5. EUR-Lex, Commission Implementing Regulation (EU) 2024/2690
  6. ENISA, NIS2 Technical Implementation Guidance
  7. ISO, ISO/IEC 27001 Information security management systems

Trustbird is being built with two certified design partners, and we are looking for more companies to join them at co-founder pricing.

Become a design partner