Introduction

The impact of legislation and regulations on technology companies is increasing rapidly. With the European NIS2 Directive already in force and the arrival of the Cyber Resilience Act (CRA) in 2027, the playing field in which you operate is changing. These developments affect not only compliance and risk management but also have a direct influence on product development, supply chain collaboration, and your position in the market.

During this members' meeting, we bring together the most important developments. You will gain insight into the impact of NIS2 and the Cyber Resilience Act (CRA) on your organization and your products. We will show how other companies deal with this in practice and the challenges they face.

Moreover, you gain insight into the importance of securely storing cryptographic keys. This strengthens the continuity of products and processes while simultaneously meeting the requirements of the CRA.

In addition, you will discover how to make your organization resilient against cyber threats, the role the National Cyber Security Center (NCSC) plays, and what is expected of you during incidents. We also zoom in on what happens when things really go wrong: from a system failure to effectively responding to a cyber incident.

Finally, you will gain insight into the role of insurers and regulators. When are you insurable? How is liability changing? And what will supervision look like in the future?

We share knowledge, experiences, and perspectives so that you are better prepared for what is to come. In this way, we help you not only to comply with the rules but also to deploy them strategically.

What can you expect?

  • A practical overview of NIS2 and the Cyber Resilience Act (CRA) and the implications for technology companies.
  • Practical experience from FHI member company Würth Elektronik
  • Insight into the role of the National Cyber Security Centre (NCSC) and the current cybersecurity landscape of the Netherlands.
  • Practical tips to prevent cyber incidents and to act effectively if things do go wrong.
  • A look at future supervision and enforcement of the CRA.

Program

12:00 PM – Reception with lunch

12:30 pm – Presentation on Cyber Security legislation and regulations: NIS2 & CRA + extensive Q&A session (Wim Boonstra, Bureau Veritas)

1:30 PM – CRA-compliant until your supplier collapses: why key escrow makes the difference (Sander Remans – Escrow Alliance)

14:00 – Practical presentation by member company Würth Elektronik on how they implement the Cyber Resilience Act (CRA), with a strong focus on embedded systems and 'connected devices'. (Adithya Madanahalli – Würth Elektronik)

14:30 – What is the role/function of the NCSC and the Cyber Security picture of the Netherlands. (Mart Marconi – NCSC)

3:00 PM – Break

3:15 PM – When the screen goes black: getting a grip on cyber incidents in practice (Hiscox/Klap Insurance Broker)

15:45 – Presentation by regulator RDI on supervision of the CRA (Jarek Bieńkowski)

4:15 PM – Closing

4:30 PM – Networking drinks with snacks and beverages

Practical information

Date: Wednesday, September 2
Time: 12:00 – 17:30
Location: FHI, Leusden
Costs: participation is free for FHI members.

Do you want to know what implications the new cybersecurity legislation has for your organization and exchange experiences with other members? Then register for this members' meeting. Please note that there is a maximum capacity of 100 people.

Register

NIS2 & Cyber Resilience Act: what changes?

FHI Member Bureau Veritas helps organizations from strategy to execution to stay ahead of digital threats. Bureau Veritas provides an overview of (upcoming) legislation and regulations (CRA, NIS2). Legislation that is becoming increasingly concrete and directly impacts how you develop products, secure systems, and collaborate within the supply chain.

What do these rules mean in practice? What do you, as an organization, need to take into account now? And how do you ensure that you not only comply but also keep looking ahead?

With a clear view of current events and an eye for practical application, Bureau Veritas translates the most important developments into concrete insights. This way, you know where you stand and what steps you can/must take.

Bureau Veritas | Wim Boonstra

Supervision of CRA – RDI

Supervision of digital resilience is essential for the Netherlands given our digitized economy and increasing geopolitical threats. There are new European guidelines for increasing digital resilience throughout the EU. How does the National Inspectorate for Digital Infrastructure (RDI) supervise the Cyber Resilience Act?

CRA-compliant until your supplier collapses: why key escrow makes the difference

Bankruptcy or breach of contract is then no longer a crisis, but a pre-arranged moment of release.

The CRA sets requirements. Is your key management prepared for this? Demonstrable key escrow assurance supports both compliance and continuity.

Cryptographic keys are indispensable for secure boot, firmware updates, authentication, and secure communication. But what happens when the vendor or administrator of these keys fails?

Without access to the correct private keys, security updates, maintenance, and even production can come to a standstill.

Escrow Alliance | Sander Remans

What is the role/function of the NCSC and the Cyber Security landscape of the Netherlands?

Cyber threats are constantly evolving. Organizations are increasingly facing digital attacks, vulnerabilities, and incidents that have a direct impact on their business operations. But what happens if you are affected? And what role does the National Cyber Security Centre (NCSC) play in this? 

During this session, the NCSC provides insight into its role/function within the Dutch cybersecurity landscape. You will hear how the NCSC supports organizations during cyber incidents, what to expect when making a report, and why it is important to report incidents. 

In addition, the NCSC will discuss the current cybersecurity landscape in the Netherlands in detail. Which threats require the most attention at the moment? What developments does the NCSC observe, and what do they mean for organizations? After this session, you will have a better understanding of the current state of affairs and know how the NCSC contributes to the digital resilience of the Netherlands. 

NCSC | Mart Marconi

When the screen goes black: getting a grip on cyber incidents in practice

Cybercrime is no longer just an IT problem. It is a business risk that can affect any organization. But what does a cyber incident mean concretely for your company? And how do you limit the impact if things go wrong? 

In this session, you will discover how cyber threats evolve and why SMEs are also an attractive target. Using practical examples, current trends, and recognizable figures, you will gain insight into the financial and operational consequences of a cyberattack. The role of AI, vulnerabilities within and outside the organization, and a comparison with traditional business risks, such as fire damage, will also be covered. 

In addition, you will receive five practical actions that you can immediately implement to increase your organization's digital resilience. Finally, the speakers will show what happens after a cyber incident: from the first 72 hours and incident response to financial settlement and practical examples of claims. This will give you a realistic picture of the impact as well as the possibilities to limit damage. 

Hiscox/Klap Insurance Broker | Richard van Eck and Jurgen Struiksma 

Practical presentation by member company Würth Elektronik

During this English presentation, Würth Elektronik demonstrates how they implement the Cyber Resilience Act (CRA), with a strong focus on embedded systems and connected devices.

Speaker Adithya Madanahalli will share how Würth Elektronik is approaching the Cyber Resilience Act with a strong focus on embedded devices and connected products. From my perspective at the intersection of technology, product strategy, and customer engagement, I will outline how CRA is already influencing the way we think about product development, security responsibilities, lifecycle support, and collaboration across the value chain. Rather than treating CRA as a pure compliance exercise, I want to highlight why it should be seen as an enabler for better products, stronger customer trust, and clearer security-by-design practices. I will also bring in practical observations from the embedded world, where constraints around hardware, firmware, connectivity, and long product lifecycles make implementation especially relevant. The goal is to offer a realistic and forward-looking view on how companies can use CRA not just to meet requirements, but to create competitive advantage and build more resilient products.

FHI, federatie van technologiebranches