Your outcome
You are likely in scope of the Cbw, as an essential entity.
The Act applies to your organisation. The supervisor may check whether you meet your obligations even without a specific reason.
You are likely in scope of the Cbw, as an important entity.
The Act applies to your organisation. The obligations are the same as for essential entities; the supervisor checks after the fact, for example after an incident or a report.
You are likely not in scope yourself, but the requirements reach you through your customers.
The Act does not bind you directly. Customers who are in scope must secure their supply chain, and that lands with you.
You are likely not in scope of the Cbw.
Based on your answers the Act does not apply to your organisation. If your services change or you grow, run the check again.
Why this outcome
- Public administration organisations are in scope regardless of their size.
- Your organisation is large and operates in a sector from annex 1.
- Your organisation is medium-sized and operates in a sector from annex 1.
- Your organisation is large and operates in a sector from annex 2. Organisations from annex 2 are important, not essential.
- Your organisation is medium-sized and operates in a sector from annex 2.
- You provide DNS services. These are in scope regardless of size.
- You run a top-level domain name registry. That is in scope regardless of size.
- You provide qualified trust services. These are in scope regardless of size.
- Your organisation has been designated a critical entity. The Act then applies regardless of size.
- You provide public electronic communications and your organisation is medium-sized or large.
- You provide public electronic communications. Small providers are in scope too, as important entities.
- You provide trust services and your organisation is large.
- You provide trust services. These are in scope regardless of size, as important entities up to medium size.
- Your sector is covered by the Act, but your organisation is small: fewer than 50 FTE, and an annual turnover or balance sheet total of at most 10 million euros.
- Your sector is not in the annexes of the Act.
- You supply organisations that are in scope of the Act.
- You are not sure whether your customers are in scope. Find out: if they are, their requirements will reach you.
Do you deliver software as a service over the internet (SaaS)? Then you may count as a provider of cloud computing services, which puts your organisation under digital infrastructure. That depends on how the service is set up. If in doubt, run the check with that sector as well.
What the Act asks of you
- Register with the NCSC
- Through MijnNCSC, with eHerkenning at level EH2+. You provide organisation and contact details, and your public IP ranges, domain names and AS numbers. Changes are reported within 14 days.
- Duty of care
- Take appropriate measures, based on a risk assessment, to secure your network and information systems, from incident handling and continuity to suppliers and access control.
- Incident reporting
-
A significant incident is reported in three steps, counted from the moment you become aware of it.
- Within 24 hours an early warning.
- Within 72 hours an incident notification with a first assessment of severity and impact.
- Within one month of the notification a final report, or a progress report if the incident is still ongoing.
- Management body
- Management approves the measures, oversees their implementation and completes training within two years of the Act taking effect. It remains accountable, even when a CISO carries out the work.
Supervision up front: the supervisor may inspect even without any sign of an infringement. The EU directive sets fines of at least up to 10 million euros or 2 percent of worldwide annual turnover.
Supervision after the fact: the supervisor acts after an incident or a report. The EU directive sets fines of at least up to 7 million euros or 1.4 percent of worldwide annual turnover.
What your customers will ask of you
Organisations under the Cbw must manage the risks of their suppliers. Expect questions and contract terms on:
- the security measures you take;
- how and how quickly you report incidents to them, so they can report within 24 hours themselves;
- how you handle vulnerabilities;
- the continuity of your service.
Your answers
- Sector
- FTE
- Annual turnover
- Balance sheet total
- Special services
- Supplies organisations under the Cbw
This self-check gives an indication based on your own answers. It is not legal advice and not a decision by a supervisor. If in doubt, read the text of the Act or put your situation to the NCSC or a lawyer. Your answers are not stored: they live only in your browser and in the link you choose to share.
Made with trustbird.com