Ga naar inhoud

NIS2 ·

NIS2 registration duty: who must register and what evidence belongs with it

Many organisations associate NIS2 with measures and incident reporting, but the first concrete step is often administrative: the registration duty. Essential and important entities must register with the supervisor so it knows who falls under the law. Miss it, and you are already on the back foot with oversight.

Who must register?

The duty applies to organisations that fall under the Dutch Cybersecurity Act (the NIS2 implementation) as an essential or important entity. First determine your applicability: sector, size and whether you fall within one of the designated categories. If in doubt, document the assessment — even “we are out of scope, because…” is a decision you must be able to substantiate. That justification is your first piece of evidence, whether or not you end up registering.

Determine your applicability carefully

The trap is in the details. You can fall directly under NIS2 based on sector and size, but also be affected indirectly because a client who does fall under it passes requirements down to you. So look not only at your own classification, but also at your largest customers. Record the outcome and the reference date; sector and size thresholds can change and your assessment must be reproducible at some point.

What does registration involve?

  • Basic data: name, sector, contact person and site(s).
  • Digital contact points and, where requested, IP ranges or domains.
  • Keeping it current: report changes — do not fill in once and forget.
  • Evidence: keep a record of what you registered and when.

Do not see registration as standalone, but as the starting point of your NIS2 file — it links directly to governance and chain responsibility.

Why it is more than a form

Registration puts your organisation on the supervisor’s radar. From that moment the duty of care (appropriate measures) and the reporting duty for incidents also apply. Under NIS2, directors are personally co-responsible; registration is the point at which that responsibility becomes formal. So make sure registration goes hand in hand with a minimum set of demonstrable measures, not as a standalone administrative tick.

What comes after registration?

Once registered, the supervisor expects you to demonstrably work on the duty of care: risk management, incident processes, business continuity and chain measures. An ISO 27001 ISMS is the most efficient way to make those measures demonstrable — no need to reinvent the wheel. The reporting duty also becomes concrete: you report a significant incident within tight deadlines, with an initial notification shortly after discovery and a fuller follow-up later.

Common mistakes

  • Assuming you are out of scope without recording the assessment — that justification is exactly what a supervisor wants to see.
  • Register and stop — registration without duty-of-care measures is an empty shell.
  • Not keeping data current — an outdated contact point means you miss a notification or instruction.
  • Not involving the board — the personal responsibility of directors makes this a management topic, not an IT task.

Getting started

Determine your applicability this week and record the assessment. If you are in scope, arrange registration and immediately link it to a minimum set of measures. Unsure about your position or measures? Take the NIS2 readiness scan or see our page on NIS2.

Deep dive in the knowledge base

Run the NIS2 readiness scan

Align NIS2 expectations with your existing management system.

Start NIS2 scan

← Back to overview