16 May 2024

Is your business digitally resilient under the NIS2 Directive: what’s the latest state of affairs?

Stelt u zich eens voor: u werkt al jaren met dezelfde zelfstandige. Hij stuurt facturen, factureert btw en heeft een eigen kvk-nummer. Toch krijgt u in 2026 ineens vragen van de Belastingdienst over de aard van uw samenwerking. Hoe heeft het zo ver kunnen komen?

We increasingly hear stories about cyberattacks disrupting organizations or institutions. In its annual overview of data breach notifications in the Netherlands, the Dutch Data Protection Authority has issued a clear warning: do not underestimate the risks of cyberattacks.

To limit the threat and consequences of cyberattacks as much as possible, the European Union has introduced the “Network and Information Security” (NIS2) Directive. This directive is designed to improve the digital and economic resilience of European member states.

The internet consultation on this directive is expected to start in May 2024. The NIS2 Directive must subsequently be transposed into national legislation by 17 October 2024 at the latest. Organizations that fall within the scope of the NIS2 Directive must already have implemented measures by 18 October 2024 (!).

How can your business prepare for the arrival of the NIS2 Directive?

  1. Ahead of the national legislation, it is important to first check whether you fall under this new directive. You can do this by:
  • Using the NIS2 Self-Assessment tool of the Radiocommunications Agency / Rijksinspectie Digitale Infrastructuur. This allows an organization to assess whether it falls under the NIS2 Directive and whether it is considered “important” or “essential” (terms from the directive).
  • Doing a NIS2 QuickScan. This QuickScan is also provided by the national government and is aimed in particular at IT and cybersecurity specialists and those responsible within organizations. The QuickScan contains 40 yes/no questions. For each theme in the QuickScan, technical or organizational measures are suggested that can help improve organizations’ digital resilience and their preparation for NIS2.
  • Whether or not you fall under the NIS2 Directive remains a matter of qualification that is best left to an expert if you have any doubts.
  1. It is wise to set aside budget and capacity to comply with the directive. Think of capacity from your IT officer or compliance officer, or hire an external expert.
  2. The national government advises organizations not to wait for the legislation. If your organization is likely or certain to fall under the NIS2 Directive, you can already start preparing for your duty of care by taking measures that improve the security and resilience of your processes and services. Think, for example, of drawing up an incident register, mapping and analyzing company- and system-specific risks in advance, drafting crisis management protocols (incident response plan), identifying alternative supply chains, and raising staff awareness (training) of risks and security measures to be taken. Does your company have ISO 27001 certification? Then that certification will in principle already largely achieve this.

Should you need advice or help determining whether you fall under NIS2, or with applying this new directive, do not hesitate to contact us at 020-345 0152 or info@thelegalcompany.nl

Nothing changes as constantly as laws and regulations. Please note that our blogs may no longer align with current laws and regulations and may therefore be outdated. If you have questions or an issue relating to this blog, or would like legal assistance, please contact us.

De afgelopen jaren stonden in het teken van de Wet VBAR, het wetsvoorstel dat een einde moest maken aan onduidelijkheid over de zzp’er. Het kabinet heeft delen van dat voorstel inmiddels geschrapt. Op het eerste gezicht is dat goed nieuws: minder regels, minder administratieve last. Maar in de praktijk blijven dezelfde toetsen overeind.

“De inhoud van de samenwerking is leidend, niet wat er op papier staat.”

De Belastingdienst handhaaft sinds 1 januari 2025 weer actief op schijnzelfstandigheid. En recente uitspraken van de Hoge Raad bevestigen dat rechters strikt toetsen of er sprake is van ondergeschiktheid en gezagsverhouding.

Voor uw praktijk betekent dit drie dingen. Een: leg de samenwerking duidelijk vast, met aandacht voor de inhoud. Twee: voorkom dat een zzp’er feitelijk werkt als werknemer. Drie: wees voorbereid op een controle, en weet hoe u de relatie kunt herzien als dat moet.

Heeft u vragen over uw concrete situatie? Wij sparren dagelijks met opdrachtgevers over hun zzp-relaties. Vraag een offerte op of bekijk onze Legal Safe abonnementen.

Hella Vercammen LL.M.
Bente Brouwer LL.M.
Niels Terlouw LL.M.
Puck de Jong LL.M.

Read more