Practice areas: Business and Commercial Law, Intellectual Property, Internet and IT Law
It will probably not have escaped your attention: last weekend, the Cybersecurity Act came into force, the Dutch implementation of the European NIS2 Directive. The Act introduces various duties of care and reporting obligations. Among other things, organisations are required to take measures to manage digital security risks, for example by drawing up appropriate security policies, establishing business continuity plans and raising staff awareness of security risks. In the event of serious incidents, such as a hack or data breach, reporting obligations apply. Companies must report incidents to the CSIRT (the Minister of Justice and Security) and the relevant supervisory authority. The law designates a supervisory authority for each sector. Depending on the type of incident, notification to affected customers may be mandatory.
The Cybersecurity Act does not apply to all businesses, and even where the Act does apply, not all obligations necessarily apply. Whether the Cybersecurity Act applies to you depends on a number of factors, which we set out step by step below. Once you have worked through this step-by-step guide, you will have an idea of whether the Act applies to you. For a definitive answer, please do not hesitate to contact us.
In principle, the Cybersecurity Act applies only to companies that have an establishment in the Netherlands and provide services or carry out activities within the European Union. If you are based outside the Netherlands, the Dutch Act therefore does not apply. However, the implementation of the NIS2 Directive in your country of establishment may well apply. There is one exception: the Act applies to providers of public electronic communications networks or communications services as soon as they offer services in the Netherlands, even if they are not established here.
For many ICT companies, the law applies only if they have their head office (i.e. the place where decisions on cybersecurity measures are taken) in the Netherlands.
Do you provide trust services or domain name registration services? Or are you the administrator of a top-level domain name registry (such as SIDN), a DNS service provider, a provider of public electronic communications networks, a provider of public electronic communications services, or a public authority? If so, the Act definitely applies to you. Depending on the size of your business, some aspects may be exempt.
The Cybersecurity Act also applies if your company has been designated by the competent minister as a critical, essential or important entity. The minister may decide to do so, for example, if your company is the sole provider of a key service, or if a disruption to the service you provide would have a major impact on public life. No minister has yet made use of this option.
The Cybersecurity Act may apply to the following types of organisations:
If your business does not fall into one of these categories, the Cybersecurity Act is unlikely to apply.
For most of the companies mentioned above, the law applies only if they are at least ‘medium-sized’. The law uses the European definition for this: a company is considered medium-sized if it employs more than fifty people, or if its annual turnover or balance sheet total exceeds €10 million. That threshold is therefore not particularly high, meaning the law will apply to many companies.
Whether the Cybersecurity Act applies to your business depends on several factors: the sector in which you operate, the size of your business and the nature of your activities. The step-by-step guide above provides an initial indication, but in practice, of course, things are more complex. Would you like more certainty as to whether the Act applies to you, or do you have any questions about the steps you need to take to comply with the duty of care and reporting obligations? Please feel free to contact us; we’d be happy to help you work through this.
Want to stay up to date? Subscribe to our newsletter!