NIS2 Cybersecurity Act: A New Reality for SMEs in Construction

Imagine: a small installation company suddenly faced with strict cybersecurity requirements. Since the introduction of the NIS2 Act in the Netherlands, the digital security of SMEs in the construction and installation industry is changing drastically. How well is your organization prepared for these new obligations?

Who is covered by the NIS2 legislation and what does this mean for SMEs?

The NIS2 directive applies directly to medium-sized and large organizations in critical sectors such as energy, transport, healthcare, drinking water, and digital infrastructure. The thresholds are a minimum of 50 employees or an annual turnover and balance sheet total exceeding 10 million euros.

For SMEs, this means that smaller companies often do not fall directly under NIS2. However, they may still be affected indirectly. Organizations that are NIS2-compliant must also look at the security of their suppliers and supply chain. A construction company, installer, or technical service provider may therefore be asked to implement security measures.

In short, even smaller companies must get their cybersecurity in order now to meet supply chain obligations.

The Four Core Obligations of NIS2

For companies covered by the NIS2 Act, four obligations are central. First, there is the duty of care. Organizations must map out their cyber risks and take appropriate measures to mitigate them. Think of multi-factor authentication, proper access management, and other technical and organizational security measures.

In addition, a reporting obligation applies to significant cyber incidents. An initial report must be made to the National Cyber Security Centre within 24 hours. This is followed by a more detailed report within 72 hours. A final report must be submitted no later than one month after the incident.

There is also a registration obligation. Organizations covered by the law must register so that regulators have visibility into which companies fall under NIS2.

Finally, supply chain responsibility plays an important role. Companies must not only have their own digital security in order but also look critically at that of suppliers and other partners. By establishing clear requirements and agreements, cyber risks are better managed throughout the entire chain.

Practical Steps and Implementation of NIS2 within SMEs

For SMEs that fall directly or indirectly under NIS2, it starts with a clear risk assessment. Next, you draw up an incident response plan, which clearly states who takes which actions during a cyber incident and within what timeframes reports take place. Supply chain security is essential; this means you also evaluate your suppliers and make agreements regarding cybersecurity. Do not make cybersecurity a one-off project, but a permanent part of your business operations. This way, you build a resilient organization that complies with the duty of care, reporting obligation, and supply chain due diligence of NIS2.

Consequences of Non-compliance and the Role of Directors

The NIS2 directive imposes a heavy responsibility on directors. Non-compliance can lead to fines of up to €10 million or 2% of global turnover for essential entities. But the impact goes further: directors can be held personally liable and even temporarily suspended in the event of serious violations. This makes cybersecurity a direct boardroom issue, not an IT problem.

Start on Time

For SMEs, the message is clear. Do not wait until a client asks questions or an incident occurs. By making cybersecurity a structural part of your business operations, you not only increase the chance of meeting supply chain requirements. You also protect your organization, customers, and reputation.

Source: Equans, Interpolis, NLdigital

Interessante onderwerpen

NIS2 Cybersecurity Act: A New Reality for SMEs in Construction

Imagine: a small installation company suddenly faced with strict cybersecurity requirements. Since the introduction of the NIS2 Act in the Netherlands, the digital security of SMEs in the construction and installation industry is changing drastically. How well is your organization prepared for these new obligations?

Lees meer »

Growing demand for climate-adaptive solutions in construction

Increasingly, we see how heatwaves, heavy rainfall, and drought are putting pressure on our buildings and infrastructure. What does this mean for the future of the construction sector? Climate-adaptive solutions are no longer a choice, but a necessity to limit damage and keep our living environment safe.

Lees meer »

Deel op social media

Kunnen we je helpen?

Onze klantenservice staat klaar om je te helpen en neemt binnen 24 uur contact met je op.