+31 (0)73 - 220 2000 | info@brandcompliance.com
English
  • Dutch
  • English
  • Beglië
  • Dutch
  • English
  • Beglië
Brand Compliance
  • Certify
    • ISO 9001
    • ISO 22301 (BCM)
    • ISO 19770-1 (IT-assets)
    • ISO 27001
    • ISO 27017 and ISO 27018
    • BIO
    • ISO 27701 (Privacy)
    • NEN 7510
  • IT Assurance
    • SOC 2
  • Vacancies
  • Knowledge base
  • BC Academy
Contact
  • Information security
    • ISO 19770-1
    • ISO 27001
    • ISO 27017 and ISO 27018
    • ISO 27799
    • BIO
    • NEN 7510
    • SOC 2
    • ISAE 3402
  • Privacy
    • Whitepaper BC 5701
    • AVG standard BC 5701:2023 NL
    • GDPR standard BC 5701:2023 EN
    • GDPR standard BC 5701:2024 EN
    • BC 5701
    • ISO 27701
  • Quality
    • ISO 9001
    • ISO 14001
    • ISO 22301
  • Knowledge base
  • News
  • Academy
    • NIS2 training course
    • ISO 27001 training courses
    • BC 5701 training courses
  • About us
    • Start your certification journey
    • Accreditations
    • Compliment, complaint or tip
    • Privacy Statement
    • Vacancies
    • Contact

Certification process

10
  • Checklist certification
  • Do you have your first audit soon?
  • How long does ISO certification take?
  • What is a certification cycle?
  • Applying for a certification process
  • Initial audit Stage 1
  • Initial audit Stage 2
  • Nonconformities management system
  • Certificate suspended or revoked? This is how you solve it!
  • Transfer of certification

BC 5701

5
  • BC 5701 certification: where do you start?
  • Your record of processing activities and the GDPR
  • Your Data Protection Officer and the GDPR
  • Checklist for your BC 5701 certification
  • Data breach: What is it and how do you prevent it?

General

9
  • SOC 2 or ISAE 3402: which standard suits your organization?
  • The Traffic Light Protocol (TLP): what does it mean for you?
  • The Brand Compliance glossary
  • What is a management system?
  • Internal or external audit?
  • Find out more about internal audits
  • Tips to describe a proper scope
  • Accreditation versus certification
  • The use of certification logos

ISO 27001:2022

3
  • Operational Capabilities: The Backbone of Information Security
  • ISO 27001:2022 – FAQ transition
  • ISO 27001:2022 – Transition process

Whitepapers

2
  • Whitepaper management system audits
  • Whitepaper GDPR Certification Standard and Criteria BC 5701

Best practices

3
  • Mastering GDPR compliance: best practices
  • Excelling in information security: best practices
  • Quality Management: best practices for success

NEN 7510

4
  • Transition to NEN 7510-1:2024
  • NEN 7510 without healthcare institution?
  • How to expand with NEN 7510
  • The differences between ISO 27001 and NEN 7510

NIS2 Directive

2
  • NIS2 liability
  • NIS2 & the Belgian CyberFundamentals
View Categories

NIS2 liability

1 min read

In this article we inform you about the NIS2 liability for board members. The recently updated Network and Information Security (NIS2) directive represents a shift in the approach to cybersecurity within the European Union. The NIS2 Directive expands the responsibilities of organizations. In doing so, it imposes requirements on the boards of both essential and important entities.

The NIS2 regulations will come into effect from the end of 2024. This makes it necessary for many companies to take measures and implement cybersecurity. Would you like to know whether your organization is subject to NIS2 liability? Via this link you will find extensive information and you can check whether NIS2 applies to your organization.

NIS2 liabilityNIS2 obligations

One of the most striking changes is the explicit NIS2 liability imposed on management. Boards of essential and important entities are directly liable for compliance.

To meet its responsibilities, management must:

  • adopt cybersecurity risk management measures, as required by Article 18;
  • monitor the implementation of the directive;
  • take responsibility for compliance with the directive.

It is therefore important for directors to be proactive in managing cybersecurity and remain alert to potential threats.

Cybersecurity training

It constitutes a requirement under the NIS2 directive that members of management be trained in cybersecurity risk and management. After all, members of management teams should be well equipped to evaluate cybersecurity risks and understand the impact on business operations. This is achieved by attending cybersecurity training courses. Directors should have demonstrably participated in such training.

Who will be the supervisor of NIS2?

The enforcement of NIS2 lies with national authorities, who have the power to:

  • conduct on-site and remote inspections, including taking samples;
  • conduct regular audits and targeted security audits;
  • initiate information requests to assess an entity’s controls.

Phased approach

Cyber risks have a rapidly escalating nature. They can have a significant impact. That is why national authorities have the power to intervene immediately, with a range of controls. The NIS2 directive takes a phased approach to compliance and sanctions. This starts with warnings. In case of continued non-compliance, binding instructions and fines follow.

NIS2 fines

Non-compliance can result in the following sanctions, among others:

  • warnings and binding instructions to correct deficiencies;
  • requirements to stop certain activities;
  • obligations to adjust risk management measures;
  • disclosure of non-compliance and publication of the responsible individuals or organizations.

Essential entities may additionally face specific controls such as appointing a supervisory officer and, if necessary, temporarily preventing individuals in management positions from carrying out their responsibilities.

NIS2 liability

The introduction of NIS2 liability for the management emphasizes the importance of directors playing an active and informed role in cybersecurity. Due to the potential legal and financial consequences of non-compliance, they must take these responsibilities seriously. It is important that directors take the necessary steps to adequately protect their organizations against cyber threats.

Share This Article :
  • Facebook
  • X
  • LinkedIn
Updated on 4 June 2024
NIS2 & the Belgian CyberFundamentals

Accreditation

RvA C548Brand Compliance B.V. has accreditation (C548) to certify ISO 27001, ISO 27701 NEN 7510 and ISO 9001 scope 33 information technology and 35 other services.

Brand Compliance B.V.

Hambakenwetering 8D2
5231 DC ‘s-Hertogenbosch

+31 (0)73 220 2000
info@brandcompliance.com

Chamber of Commerce nr.: 32101659
VAT nr.: NL8130.78.854.B01

Brand Compliance Belgie B.V.

Uitbreidingstraat 66
2600 Berchem (Antwerpen)

+32 (0)14 48 0730
be-info@brandcompliance.com

VAT nr.: BE0735.675.516

Brand Compliance Nordics AB

Vasagatan 16 2 TR
111 20 Stockholm

+31 (0)73 220 2015
info@brandcompliance.com

Org.nr: 559238-1387

© Copyright 2025 Brand Compliance