The directives ask for proof — this is ready

Per anchor: what the directive asks, and what is ready for it. Each member state transposes NIS2 and CER into national law — in the Netherlands the Cyberbeveiligingswet (Cbw) and the Wwke, in force since 15 August 2026. The mapping below uses the directive requirements, with the Dutch transposition as the lived example.

Full duty-of-care obligations apply 9 to 10 months after designation as a critical or essential entity — starting now puts an organisation well ahead of that deadline.

The NIS2 directive — five anchors

For the cyber column: CISO, information security and compliance.

The directive asks

Policies and procedures to assess the effectiveness of cybersecurity risk-management measures.

This is ready

The PDCA improvement matrix, recurring threads, investigation and action-item management: that cycle on screen — per theme and per year, tracking what is open, closed, or recurring.

The directive asks

Incident handling: preventing, detecting and handling incidents — and learning from them.

This is ready

The log and the response report, started by the responder while it is fresh; followed by a structured evaluation with assignment and feedback.

The directive asks

A final report within one month after the incident notification (which itself follows a 24-hour early warning and a 72-hour notification).

This is ready

The archived — unchangeable — evaluation report, the report in the organisation's own branding, and the dossier with a timeline and action items with owner, deadline and status: the elements of the final report, prepared in advance.

The directive asks

Business continuity and crisis management — with plans that are tested and exercised periodically.

This is ready

The activity planner for BCM and crisis exercises: every exercise planned, held, evaluated and archived — the whole sequence demonstrable.

The directive asks

Basic cyber hygiene practices and training for the organisation — and training for the management body itself.

This is ready

The planner with year-goal coverage, digital attendance and staffing levels — including the training participation of management body members themselves.

The management body approves the measures, oversees their implementation, and is accountable (art. 20 NIS2; art. 24(4) Cbw: kept "demonstrably" up to date).

Forward this: the art. 20 block is for the board; the CER section below is for the crisis management advisor.

The CER directive — one anchor

For the crisis management advisor.

CER duty of care CER directive

Designated as a critical entity too? Then: the same cycle applied to physical disruptions — one administration for both directives. A critical entity is automatically an essential entity under NIS2, with the same competent authority.

Demonstrability toward the regulator competent authority

A dossier per incident and per exercise, with export, timeline and multi-year archive. When the question comes — "how does your organisation learn from incidents?" — open the dossier, not a folder of loose reports.

Not a notification tool. Not a risk-analysis tool. Not technical measures.

The early warning, the incident notification and filing the final report stay with the organisation itself; risk analysis and technical measures belong to other tools. What is here:

the quality management system — evaluate against one yardstick recurring threads with follow-through readiness from exercise and response data