Governance codes and NIS2 meet in one board-level question: how do you know that digital risks are genuinely controlled? Under the Dutch Cybersecurity Act, boards of essential and important entities remain ultimately responsible for cyber-risk management. Sector codes also guide governance, supervision, continuity and accountability.
Each code has its own scope. Some explicitly address digital transformation, data, AI or cybersecurity. Others connect through quality, risk management, competence and continuity. The translation therefore needs to reflect the organisation and its sector.
Why governance codes and cyber resilience now meet
Digital services, personal data, suppliers and operational continuity have become part of the social mission. Disruption can affect clients, residents, tenants, children, audiences, donors or partners. Digital resilience therefore belongs in the regular governance cycle: strategy, risk assessment, decisions, oversight and accountability.
A governance code helps clarify roles and expected conduct. NIS2 and the Dutch Cybersecurity Act add statutory duties for organisations within scope. Together they show which information executive and supervisory boards require and which decisions should be documented.
What the Dutch Cybersecurity Act asks of boards
From 15 August 2026, essential and important entities must take appropriate and proportionate measures to manage risks to network and information systems. The board approves those measures, oversees implementation and remains ultimately responsible. Executive directors must complete appropriate training so they can assess risks and measures.
This responsibility becomes practical when risks are connected with critical services, risk appetite, suppliers, incidents, recovery capability and management information. A control list becomes useful to the board when ownership, effectiveness and residual risk are visible as well.
Sector examples and board questions
The table identifies the relevant governance connection for each sector. It does not suggest that every code contains the same digital requirements or that every organisation automatically falls within NIS2 scope.
| Sector | Governance code or framework | Digital connection | Board question |
|---|---|---|---|
| Healthcare | Healthcare Governance Code 2022 | Good care, governance, responsible supervision and continuous development connect digital dependencies with quality and continuity. | Which digital risks can affect the quality, safety or availability of care, and how are they reflected in reporting? |
| Social work | Social Work Governance Code 2025 | The code explicitly addresses digital transformation, cybersecurity, responsible use of data and AI. | Which vision and safeguards guide our use of technology, data and AI, and how does service delivery remain digitally resilient? |
| Childcare | Childcare Governance Code 2019 | Governance, supervision, quality, transparency and continuity connect with personal data, parent communication and digital operations. | How do we preserve continuity and trust if planning, parent apps, child data or suppliers are disrupted? |
| Housing associations | Housing Association Governance Code 2025 | Principle 5 addresses control of risks connected with the housing association's activities. | Which digital dependencies affect services, property processes and tenant data, and which residual risks do we accept? |
| Culture | Culture Governance Code 2019; the 2027 edition has been published | Governance, continuity, risk-aware conduct and accountability provide the board-level connection to digital resilience. | Which systems, data and suppliers determine programming, audience engagement, ticketing and continuity? |
| Charities | CBF Recognition Scheme | The current sector standard connects quality, accountability, governance, integrity and impact. The former SBF Good Governance Code no longer applies. | How do we protect donor data, fundraising and trust, and which digital risks require board follow-up? |
Roles of executive and supervisory boards
The executive board sets direction, approves measures and aligns risk, resources and accountability. Management organises delivery and produces useful information. The supervisory board considers whether the chosen approach is well founded, progress remains visible and material uncertainties reach the agenda in time.
A CISO, privacy officer, IT manager or supplier can perform specialist tasks. The board keeps the wider picture together: social purpose, risk appetite, continuity, data, suppliers and accountability.
Questions for the next board or supervisory meeting
- Which services and interests must remain protected during a digital disruption?
- Which three scenarios have the greatest social or operational impact?
- Which suppliers create concentration risk or a single point of failure?
- Which measures has the board approved, and how is effectiveness tested?
- Which residual risks fall outside the agreed risk appetite?
- Which information reaches the executive or supervisory board periodically, and which events trigger immediate escalation?
- How are decisions, exceptions, exercises and improvement actions documented?
When training or a boardroom session adds value
A joint session is useful when roles have different views, reporting is mainly technical or digital matters are spread across committees and departments. Training connects sector expectations and statutory duties through a shared board-level language.
The NIS2 Boardroom Masterclass covers responsibility, risk management, duty of care, suppliers, incidents, reporting and decisions. Sector examples are aligned with the participants. The In-company Boardroom Day adds application to the organisation and a board-level risk analysis.
Frequently asked questions about governance codes and NIS2
Does every governance code explicitly address cybersecurity?
No. The 2025 Social Work Governance Code explicitly addresses digital transformation, data, AI and cybersecurity. Other codes connect mainly through risk management, continuity, quality, oversight and accountability.
Can a sector governance code apply when an organisation is outside NIS2 scope?
Yes. Applicability of a governance code and statutory scope under the Dutch Cybersecurity Act are separate questions. A code can set governance expectations even when the organisation is not classified as an essential or important entity.
Does applying a governance code replace the NIS2 duty of care?
No. A governance code supports good governance and supervision. Organisations within statutory scope must also meet the registration, duty-of-care, incident-reporting and governance requirements of the Dutch Cybersecurity Act.
What is the role of a supervisory board in digital resilience?
The supervisory board considers the quality of the risk assessment, board information, progress of measures and treatment of material residual risks within its own oversight role.
When is NIS2 boardroom training useful?
Training is useful when executive and supervisory roles need a shared view of cyber risks, responsibilities, sector expectations and the decisions that belong in the governance cycle.
Boardroom dialogue
Discuss governance codes and NIS2 together
The NIS2 Boardroom Masterclass helps executive and supervisory boards translate cyber risk, sector expectations and the Dutch Cybersecurity Act into questions and decisions. For an assessment, baseline review or implementation support, contact Kynexis Informatiebeveiliging BV.