Legislation
NIS2. The duty of care, linked to controls you already have.
NIS2 is an EU directive on cybersecurity, Directive (EU) 2022/2555, implemented in the Netherlands through the Cyberbeveiligingswet (Cybersecurity Act), in force since 15 August 2026. Organizations in scope register, take risk-based security measures and report significant incidents, and their management approves the measures, oversees them and completes training. IT and software providers meet it directly or through their customers. Trustbird maps the duty of care to your ISO 27001 controls and keeps the additional duties in view.
- Duty of care topics linked to Annex A controls
- Incident reporting deadlines in your procedure
- Management approval and training recorded
How Trustbird supports NIS2
A working ISO 27001 management system covers much of the NIS2 duty of care. What remains are the parts that come from the law itself. Trustbird shows both in one view.
Duty of care mapped to controls
Each duty of care topic, from risk analysis and incident handling to supply chain security and multi-factor authentication, is linked to the controls that cover it.
Gaps the ISMS does not close
Trustbird lists what ISO 27001 does not settle on its own, such as the reporting deadlines and registration, so they get an owner and a place.
Incident reporting clock
Record incidents with the moment you became aware of them, decide whether they are significant and track each reporting step against its deadline: an early warning within 24 hours, an incident notification within 72 hours and a final report within a month.
Management responsibility
Record when management approved the measures, how it oversees them and which training directors completed.
Supply chain
Keep track of your own suppliers, what you agreed with them on security and incident notification, and what your customers ask of you.
Scope that matches your services
Check that your management system scope includes the services that NIS2 applies to, not only part of the organization.
Working on NIS2
-
01
Establish your position
Record whether you are in scope yourself or receive the requirements through customers. Trustbird does not decide this for you.
-
02
Adopt NIS2
Switch on NIS2 next to ISO 27001. The duty of care topics are linked to your existing controls.
-
03
Arrange what the law adds
Add the reporting deadlines to your incident procedure, record management approval and plan training.
-
04
Test and review
Practice the reporting process, for example in a tabletop exercise, and include the results in your management review.
Frequently asked questions
- Does ISO 27001 mean I comply with NIS2?
- Not automatically. ISO 27001 covers much of the duty of care, but the reporting deadlines, registration and management duties are legal obligations you arrange separately. Your scope also has to include the relevant services.
- Does Trustbird tell me whether NIS2 applies to us?
- No. Whether you are in scope depends on your sector, services and size. Trustbird helps you organize the work, and it does not give legal advice. For a first indication, see the guidance from the NCSC and the self-assessment from the RDI. For a formal assessment, consult a legal adviser.
- Is a certificate required under NIS2?
- The Dutch implementation does not prescribe a certificate. An ISO 27001 certificate with a fitting scope does answer many of the questions customers and supervisors ask.
See what Trustbird does for your organization
Trustbird is being built with two certified design partners, and we are looking for more companies to join them at co-founder pricing. Apply as a design partner, or mail us with a question.