The directives ask for proof — this is ready
Per anchor: what the directive asks, and what is ready for it. Each member state transposes NIS2 and CER into national law — in the Netherlands the Cyberbeveiligingswet (Cbw) and the Wwke, in force since 15 August 2026. The mapping below uses the directive requirements, with the Dutch transposition as the lived example.
Full duty-of-care obligations apply 9 to 10 months after designation as a critical or essential entity — starting now puts an organisation well ahead of that deadline.
The NIS2 directive — five anchors
For the cyber column: CISO, information security and compliance.
Policies and procedures to assess the effectiveness of cybersecurity risk-management measures.
The PDCA improvement matrix, recurring threads, investigation and action-item management: that cycle on screen — per theme and per year, tracking what is open, closed, or recurring.
Incident handling: preventing, detecting and handling incidents — and learning from them.
The log and the response report, started by the responder while it is fresh; followed by a structured evaluation with assignment and feedback.
A final report within one month after the incident notification (which itself follows a 24-hour early warning and a 72-hour notification).
The archived — unchangeable — evaluation report, the report in the organisation's own branding, and the dossier with a timeline and action items with owner, deadline and status: the elements of the final report, prepared in advance.
Business continuity and crisis management — with plans that are tested and exercised periodically.
The activity planner for BCM and crisis exercises: every exercise planned, held, evaluated and archived — the whole sequence demonstrable.
Basic cyber hygiene practices and training for the organisation — and training for the management body itself.
The planner with year-goal coverage, digital attendance and staffing levels — including the training participation of management body members themselves.
Forward this: the art. 20 block is for the board; the CER section below is for the crisis management advisor.
The CER directive — one anchor
For the crisis management advisor.
Designated as a critical entity too? Then: the same cycle applied to physical disruptions — one administration for both directives. A critical entity is automatically an essential entity under NIS2, with the same competent authority.
A dossier per incident and per exercise, with export, timeline and multi-year archive. When the question comes — "how does your organisation learn from incidents?" — open the dossier, not a folder of loose reports.
Not a notification tool. Not a risk-analysis tool. Not technical measures.
The early warning, the incident notification and filing the final report stay with the organisation itself; risk analysis and technical measures belong to other tools. What is here:
Read the sources — NIS2 Directive (EU) 2022/2555 · CER Directive (EU) 2022/2557 · Dutch transposition: Cyberbeveiligingswet · Wet weerbaarheid kritieke entiteiten.