NIS2 & DORA-COMPLIANCE
NIS2 & DORA COMPLIANCE

NIS2 & DORA: van regelgeving naar een dossier dat staat

NIS2 & DORA: from regulation to a dossier that holds up

Gecertificeerd NIS2 Lead Implementer, met DORA-kennis opgebouwd via gerichte zelfstudie op hetzelfde niveau als mijn NIS2-expertise.

Certified NIS2 Lead Implementer, with DORA knowledge built through focused self-study at the same level as my NIS2 expertise.

NIS2 en DORA zijn twee van de meest ingrijpende EU-regelgevingen van de afgelopen jaren: de ene voor cyberweerbaarheid in kritieke sectoren, de andere voor digitale operationele weerbaarheid in de financiële sector. Ik combineer de compliance-kennis met de projectmatige discipline om een implementatietraject écht te trekken - risicoregisters, incidentprocedures en leveranciersbeheer die niet in een lade verdwijnen, maar mee draaien in de organisatie.

NIS2 and DORA are two of the most far-reaching pieces of EU regulation in recent years: one for cyber resilience in critical sectors, the other for digital operational resilience in the financial sector. I combine the compliance knowledge with the project-management discipline to actually drive an implementation - risk registers, incident procedures and supplier oversight that don't end up in a drawer, but keep running inside the organisation.

Wat is NIS2?

What is NIS2?

NIS2 is een Europese richtlijn (Richtlijn (EU) 2022/2555) die de digitale veiligheid en weerbaarheid van belangrijke organisaties moet verhogen. In België is deze omgezet in de Belgische NIS2-wet, met het Centre for Cybersecurity Belgium (CCB) als toezichthouder. Waar de DPO-rol focust op persoonsgegevens, gaat NIS2 breder: over de veiligheid van de hele digitale organisatie tegen hacks, storingen en cyberaanvallen.

NIS2 is an EU directive (Directive (EU) 2022/2555) aimed at raising the digital security and resilience of important organisations. In Belgium it has been transposed into the Belgian NIS2 Act, with the Centre for Cybersecurity Belgium (CCB) as supervisory authority. Where the DPO role focuses on personal data, NIS2 is broader: it covers the security of the entire digital organisation against hacks, outages and cyberattacks.

  • Risicobeheer - cyberrisico's in kaart brengen en structureel beheersen.
  • Risk management - identifying and structurally managing cyber risks.
  • Incidentmelding - significante incidenten tijdig melden aan het CCB.
  • Incident reporting - reporting significant incidents to the CCB in time.
  • Bedrijfscontinuïteit - plannen en procedures voor herstel na een incident.
  • Business continuity - plans and procedures to recover after an incident.
  • Ketenveiligheid - ook leveranciers en dienstverleners moeten aan veiligheidseisen voldoen.
  • Supply chain security - suppliers and service providers must also meet security requirements.
  • Bestuurlijke verantwoordelijkheid - het management is persoonlijk mee verantwoordelijk voor de naleving.
  • Management accountability - senior management is personally accountable for compliance.
ToepasselijkheidApplicability Wie valt hieronderWho this covers
Volledig van toepassingFully applicable "Essentiële entiteiten": grote organisaties in de zeer kritieke sectoren van Bijlage I - energie, vervoer, bankwezen, infrastructuur van de financiële markten, gezondheidszorg, drinkwater, afvalwater, digitale infrastructuur, beheer van ICT-diensten, overheid en ruimtevaart. Bepaalde spelers (bv. DNS-diensten, TLD-registers, vertrouwensdiensten) vallen hier altijd onder, ongeacht hun grootte. "Essential entities": large organisations in the highly critical sectors of Annex I - energy, transport, banking, financial market infrastructure, healthcare, drinking water, waste water, digital infrastructure, ICT service management, government and space. Certain players (e.g. DNS providers, TLD registries, trust services) always fall under this, regardless of size.
Deels van toepassingPartly applicable "Belangrijke entiteiten": middelgrote organisaties in de sectoren van Bijlage I, en middelgrote of grote organisaties in de andere kritieke sectoren van Bijlage II - post- en koeriersdiensten, afvalstoffenbeheer, chemische stoffen, levensmiddelen, bepaalde vervaardiging (o.a. medische hulpmiddelen, elektronica, machines, voertuigen), digitale aanbieders en onderzoek. Lichter toezichtregime, maar wel dezelfde basisverplichtingen. "Important entities": medium-sized organisations in the Annex I sectors, and medium or large organisations in the other critical sectors of Annex II - postal and courier services, waste management, chemicals, food, certain manufacturing (e.g. medical devices, electronics, machinery, vehicles), digital providers and research. Lighter supervision, but the same core obligations.
Niet van toepassingNot applicable Micro- en kleine ondernemingen (minder dan 50 werknemers én minder dan €10 miljoen omzet) buiten de sectoren van Bijlage I en II zijn in principe vrijgesteld - denk aan de meeste detailhandel, horeca, bouw en vrije beroepen. Ben je leverancier van een essentiële of belangrijke entiteit, dan kunnen contractuele veiligheidseisen via de ketenverplichting alsnog gelden. Goede cyberhygiëne blijft voor elke organisatie sterk aan te raden. Micro and small businesses (fewer than 50 employees and under €10 million turnover) outside the Annex I and II sectors are in principle exempt - think of most retail, hospitality, construction and professional services. If you supply an essential or important entity, contractual security requirements can still apply through the chain-security obligation. Good cyber hygiene remains strongly advisable for every organisation.

Bron: NIS2-richtlijn (EU) 2022/2555, de Belgische NIS2-wet en het Centre for Cybersecurity Belgium (CCB). Dit is algemene informatie, geen juridisch advies - de exacte indeling van jouw organisatie wordt best individueel getoetst.

Source: NIS2 Directive (EU) 2022/2555, the Belgian NIS2 Act and the Centre for Cybersecurity Belgium (CCB). This is general information, not legal advice - your organisation's exact classification should be assessed individually.

Wat is DORA?

What is DORA?

DORA (Digital Operational Resilience Act, Verordening (EU) 2022/2554) is van toepassing sinds 17 januari 2025. In tegenstelling tot een richtlijn is DORA een Europese verordening: rechtstreeks toepasselijk, zonder omzetting in nationale wetgeving nodig. DORA verplicht financiële entiteiten om hun digitale operationele weerbaarheid tegen ICT-risico's aantoonbaar op orde te hebben. In België houden de FSMA en de Nationale Bank van België (NBB) toezicht, elk voor hun eigen categorieën van instellingen.

DORA (Digital Operational Resilience Act, Regulation (EU) 2022/2554) has applied since 17 January 2025. Unlike a directive, DORA is an EU regulation: directly applicable, without the need for transposition into national law. DORA requires financial entities to demonstrably have their digital operational resilience against ICT risk in order. In Belgium, the FSMA and the National Bank of Belgium (NBB) supervise compliance, each for their own categories of institutions.

  • ICT-risicobeheer - een intern beheerkader voor het identificeren, beschermen, detecteren en herstellen van ICT-risico's.
  • ICT risk management - an internal framework to identify, protect against, detect and recover from ICT risk.
  • Incidentenbeheer & -melding - classificatie en tijdige melding van ICT-gerelateerde incidenten aan de toezichthouder.
  • Incident management & reporting - classification and timely reporting of ICT-related incidents to the supervisor.
  • Testen van digitale weerbaarheid - periodieke tests, tot en met dreigingsgerichte penetratietests (TLPT) voor grotere instellingen.
  • Digital resilience testing - periodic testing, including threat-led penetration testing (TLPT) for larger institutions.
  • Beheer van ICT-derdenrisico - contractuele vereisten en een register van alle kritieke ICT-dienstverleners (cloud, hosting, SaaS).
  • ICT third-party risk management - contractual requirements and a register of all critical ICT providers (cloud, hosting, SaaS).
  • Informatie-uitwisseling - vrijwillige uitwisseling van dreigings- en kwetsbaarheidsinformatie tussen financiële entiteiten.
  • Information sharing - voluntary exchange of threat and vulnerability intelligence between financial entities.
ToepasselijkheidApplicability Wie valt hieronderWho this covers
Volledig van toepassingFully applicable Vrijwel alle gereguleerde financiële entiteiten: banken/kredietinstellingen, verzekerings- en herverzekeringsondernemingen, betalingsinstellingen, e-geldinstellingen, beleggingsondernemingen, beheerders van beleggingsfondsen, centrale tegenpartijen, effectenbeurzen, kredietbeoordelaars, crowdfundingplatformen en crypto-activadienstverleners. Ook kritieke ICT-derde partijen (bv. grote cloud providers) die door de Europese toezichthouders zijn aangewezen, vallen onder een specifiek oversight-regime. Virtually all regulated financial entities: banks/credit institutions, (re)insurance undertakings, payment institutions, e-money institutions, investment firms, fund managers, central counterparties, trading venues, credit rating agencies, crowdfunding platforms and crypto-asset service providers. Critical ICT third-party providers (e.g. major cloud providers) designated by the European supervisory authorities also fall under a specific oversight regime.
Deels van toepassingPartly applicable Kleine, niet-onderling verbonden beleggingsondernemingen en kleine instellingen voor bedrijfspensioenvoorziening (max. 100 aangeslotenen) vallen onder een vereenvoudigd, proportioneel ICT-risicobeheerkader - lichter, maar met behoud van de kernverplichtingen zoals incidentmelding. Small, non-interconnected investment firms and small institutions for occupational retirement provision (up to 100 members) fall under a simplified, proportionate ICT risk management framework - lighter, but retaining core obligations such as incident reporting.
Niet van toepassingNot applicable Micro-ondernemingen binnen de financiële sector (minder dan 10 werknemers én maximaal €2 miljoen jaaromzet of balanstotaal) zijn vrijgesteld van een deel van de vereisten. Organisaties buiten de financiële sector vallen niet rechtstreeks onder DORA - tenzij ze als kritieke ICT-leverancier aan een financiële instelling worden aangewezen. Micro-enterprises within the financial sector (fewer than 10 employees and no more than €2 million annual turnover or balance sheet total) are exempt from part of the requirements. Organisations outside the financial sector do not fall directly under DORA - unless designated as a critical ICT provider to a financial institution.

Bron: DORA-verordening (EU) 2022/2554, de FSMA en de Nationale Bank van België (NBB). Dit is algemene informatie, geen juridisch advies - de exacte indeling van jouw organisatie wordt best individueel getoetst.

Source: DORA Regulation (EU) 2022/2554, the FSMA and the National Bank of Belgium (NBB). This is general information, not legal advice - your organisation's exact classification should be assessed individually.

Waarom met mij samenwerken

Why work with me

Eén aanspreekpunt voor twee van de meest complexe EU-regelgevingen van dit moment, gecombineerd met de projectmatige discipline om ze ook echt uit te voeren.

One point of contact for two of the most complex EU regulations right now, combined with the project-management discipline to actually implement them.

Ik voer uit, ik adviseer niet enkel

I execute, not just advise

Geen rapport dat in een lade verdwijnt. Ik bouw het dossier, stuur de betrokken teams aan en zorg dat het staat wanneer de auditor of toezichthouder binnenkomt.

No report that ends up in a drawer. I build the dossier, direct the teams involved and make sure it holds up when the auditor or supervisor comes knocking.

Twee regelgevingen, één aanpak

Two regulations, one approach

NIS2 Lead Implementer én DORA-kennis via gerichte zelfstudie, aangevuld met 10+ jaar projectmanagement - geen overdracht tussen advies en uitvoering.

NIS2 Lead Implementer plus DORA knowledge through focused self-study, backed by 10+ years of project management - no hand-off between advice and execution.

Onafhankelijk & flexibel

Independent & flexible

Geen belangenconflict, geen vaste overhead. Op afroep, op contractbasis of projectmatig inzetbaar, tot 80 km rondom Mol en op afstand.

No conflict of interest, no fixed overhead. Available on call, on a contract or project basis, within 80 km of Mol and remotely.

Alle gratis NIS2- en DORA-templates

All free NIS2 and DORA templates

9 kant-en-klare templates om je compliance-traject te starten - vraag ze hierboven gratis aan via het formulier.

9 ready-to-use templates to kickstart your compliance journey - request them for free above via the form.

Gratis NIS2- & DORA-templates aanvragen

Search