11 December 2024

The NIS2 Directive: What Changes for Your Business?

Stelt u zich eens voor: u werkt al jaren met dezelfde zelfstandige. Hij stuurt facturen, factureert btw en heeft een eigen kvk-nummer. Toch krijgt u in 2026 ineens vragen van de Belastingdienst over de aard van uw samenwerking. Hoe heeft het zo ver kunnen komen?

Cybersecurity is an increasingly important topic in our digital world. To better protect companies and organizations against cyber threats, the EU has designed the NIS2 Directive (Network and Information Security). This directive sets out obligations that the Dutch legislature must impose on companies and organizations in critical sectors to strengthen cybersecurity and counter cyberattacks. The directive is the successor to the original NIS Directive, which was implemented in the Netherlands through the Network and Information Systems Security Act (Wbni). The NIS2 Directive introduces even stricter requirements and a broader scope than its predecessor.

Who does the NIS2 Directive apply to?

The NIS2 Directive targets a broader range of sectors than the original directive, while remaining applicable to sectors that were already covered by the first NIS Directive.

Your organization automatically falls under the NIS2 Directive if:

And

  • You have a medium-sized organization with at least 50 employees or an annual turnover or balance sheet total of more than €10 million (your organization is an “important entity”); or
  • You have a large organization with more than 250 employees or a net turnover of more than €50 million and a balance sheet total of more than €43 million (your organization is an “essential entity”).

Examples of highly critical sectors include energy, transport, banking, healthcare, digital infrastructure, and public administration.

Examples of critical sectors include digital providers, postal and courier services, and chemicals. These are classified as “critical” because disruptions or incidents in their services can have serious consequences for society, the economy, or national security.

What obligations apply under the NIS2 Directive?

Organizations that fall under the NIS2 Directive face various obligations. Among other things, they acquire a duty of care to assess cybersecurity risks and take measures to safeguard the security of their services. This includes protecting sensitive information and minimizing the impact of security incidents.

These organizations also acquire a reporting obligation. Incidents that significantly disrupt essential services must be reported to the supervisory authority, the Digital Infrastructure Inspectorate (Rijksinspectie Digitale Infrastructuur, RDI), within 24 hours. If the incident is a cyber incident, it must also be reported to the Computer Security Incident Response Team (CSIRT). Factors such as the number of those affected and the financial impact determine whether an incident is subject to the reporting obligation.

Organizations falling under the NIS2 Directive will also be subject to supervision. This means checks will be carried out to determine whether the organization complies with its NIS2 obligations, such as the duty of care and the reporting obligation. Work is currently underway to determine which sectors will fall under which supervisory authority.

How can you prepare?

Although the Dutch implementation of the NIS2 Directive, in the form of the Cybersecurity Act (Cyberbeveiligingswet, Cbw), is not expected to take effect until the third quarter of 2025, it is important to start taking steps now. You can read how to prepare in our earlier blog on the NIS2 Directive.

Do you have questions or need advice on the above? Please contact us directly at info@thelegalcompany.nl or call 020 345 0152.

De afgelopen jaren stonden in het teken van de Wet VBAR, het wetsvoorstel dat een einde moest maken aan onduidelijkheid over de zzp’er. Het kabinet heeft delen van dat voorstel inmiddels geschrapt. Op het eerste gezicht is dat goed nieuws: minder regels, minder administratieve last. Maar in de praktijk blijven dezelfde toetsen overeind.

“De inhoud van de samenwerking is leidend, niet wat er op papier staat.”

De Belastingdienst handhaaft sinds 1 januari 2025 weer actief op schijnzelfstandigheid. En recente uitspraken van de Hoge Raad bevestigen dat rechters strikt toetsen of er sprake is van ondergeschiktheid en gezagsverhouding.

Voor uw praktijk betekent dit drie dingen. Een: leg de samenwerking duidelijk vast, met aandacht voor de inhoud. Twee: voorkom dat een zzp’er feitelijk werkt als werknemer. Drie: wees voorbereid op een controle, en weet hoe u de relatie kunt herzien als dat moet.

Heeft u vragen over uw concrete situatie? Wij sparren dagelijks met opdrachtgevers over hun zzp-relaties. Vraag een offerte op of bekijk onze Legal Safe abonnementen.

Hella Vercammen LL.M.
Bente Brouwer LL.M.
Niels Terlouw LL.M.
Puck de Jong LL.M.

Read more