- Duty of care, article 21
- Ten elements, lettered a to j: risk analysis policy, incident handling, business continuity, supply chain, secure acquisition and development, effectiveness assessment, cyber hygiene and training, cryptography, personnel and access, and authentication.
- Notification duty, articles 25 to 29
- An early warning within 24 hours, a full notification within 72 hours and a final report within one month of the notification. One portal, mijn.ncsc.nl, reaches the sectoral CSIRT and the supervisor at the same time.
- Registration, articles 43 and 44
- Registration in the national entity register at the NCSC, via mijn.ncsc.nl with eHerkenning. It asks for sector, contact details, public IP ranges, domain names and AS numbers. Every change is reported within two weeks.
- Management body, article 24
- The board approves the measures. Every board member must be able to identify and assess cybersecurity risks and must hold a training certificate, by 15 August 2028. A supervisor can fine an individual board member up to EUR 25,000.
- Supply chain, article 21(3)(d)
- Direct suppliers and service providers sit inside your own duty of care. You weigh each supplier's specific vulnerabilities, the overall quality of its products and its secure development practices. Suppliers below the threshold are reached by contract.
- Sanctions, articles 80, 87 and 93
- For an essential entity, at most EUR 10,000,000 or 2% of the total worldwide annual turnover of the undertaking it belongs to, whichever is higher. For an important entity, EUR 7,000,000 or 1.4%. The toolkit also holds security audits and binding instructions.