Save the date

The impact of legislation and regulations on technology companies is increasing rapidly. With the European NIS2 Directive already in force and the arrival of the Cyber Resilience Act (CRA) in 2027, the playing field in which you operate is changing. These developments affect not only compliance and risk management but also have a direct influence on product development, supply chain collaboration, and your position in the market.

During this members' meeting, we bring together the most important developments. You will gain insight into the impact of NIS2 and the Cyber Resilience Act (CRA) on your organization and your products. We will show how other companies deal with this in practice and the challenges they face.

Moreover, you gain insight into the importance of securely storing cryptographic keys. This strengthens the continuity of products and processes while simultaneously meeting the requirements of the CRA.

In addition, you will discover how to make your organization resilient against cyber threats, the role the National Cyber Security Center (NCSC) plays, and what is expected of you during incidents. We also zoom in on what happens when things really go wrong: from a system failure to effectively responding to a cyber incident.

Finally, you will gain insight into the role of insurers and regulators. When are you insurable? How is liability changing? And what will supervision look like in the future?

We share knowledge, experiences, and perspectives so that you are better prepared for what is to come. In this way, we help you not only to comply with the rules but also to deploy them strategically.

What can you expect?

  • A practical overview of NIS2 and the Cyber Resilience Act and the implications for technology companies.
  • Practical experience from an FHI member company.
  • Insight into the role of the National Cyber Security Centre (NCSC) and the current cybersecurity landscape of the Netherlands.
  • Practical tips to prevent cyber incidents and to act effectively if things do go wrong.
  • A look at future oversight of the Cybersecurity Act and the CRA.

Program

12:00 PM – Reception with lunch

12:30 PM – Presentation on Cyber Security legislation and regulations: NIS2 & CRA (Bureau Veritas) + extensive Q&A session

1:30 PM - CRA-compliant until your supplier collapses: why key escrow makes the difference or (Sander Remans – Escrow Alliance)

2:00 PM – Practical presentation by a member company (subject to change)

14:30 – What is the role/function of the NCSC and the Cyber Security landscape of the Netherlands – Mart Marconi – NCSC

3:00 PM – Break

3:15 PM – When the screen goes black: getting a grip on cyber incidents in practice (Hiscox/Klap Insurance Broker)

15:45 – Presentation by regulator RDI on supervision of the Cybersecurity Act and CRA.

4:15 PM – Closing

4:30 PM – Networking drinks with snacks and beverages

Practical information

Date: Wednesday, September 2
Time: 12:30 – 17:30
Location: FHI, Leusden
Costs: participation is free for FHI members.

Do you want to know what implications the new cybersecurity legislation has for your organization and exchange experiences with other members? Then register for this members' meeting. Please note that there is a maximum capacity of 100 people.

Register

NIS2 & Cyber Resilience Act: what changes?

FHI Member Bureau Veritas helps organizations from strategy to execution to stay ahead of digital threats. Bureau Veritas provides an overview of (upcoming) legislation and regulations (CRA, NIS2). Legislation that is becoming increasingly concrete and directly impacts how you develop products, secure systems, and collaborate within the supply chain.

What do these rules mean in practice? What do you, as an organization, need to take into account now? And how do you ensure that you not only comply but also keep looking ahead?

With a clear view of current events and an eye for practical application, Bureau Veritas translates the most important developments into concrete insights. This way, you know where you stand and what steps you can/must take.

Bureau Veritas Bureau Veritas | Wim Boonstra

Supervision of the Cybersecurity Act and CRA – RDI

Monitoring digital resilience is essential for the Netherlands given our digitized economy and increasing geopolitical threats. There are new European guidelines for increasing digital resilience throughout the EU. In the Netherlands, these guidelines are being implemented in the form of the Cybersecurity Act (Cbw) – mid-2026 and the Critical Entities Resilience Act (Wwke).

How does the National Inspectorate for Digital Infrastructure (RDI) supervise the Cybersecurity Act (Cbw) once it comes into force?

FHI, federatie van technologiebranches