aanmelder.nl – looking back and ahead
Discover what aanmelder.nl has achieved over the past year and which steps we’re taking to make your events even easier in the future.
You've worked out a fantastic concept, the date is set, and then suddenly extensive security questions pop up in your inbox. Sent by the IT or procurement department, right before the event is officially approved. Sound familiar?
In the coming period, this likely won't happen any less. The reason? NIS2. This European cybersecurity directive focuses on increasing the digital and economic resilience of essential and important entities in EU countries. Every EU country needs to translate NIS2 into national law to make its own country more resilient.
And you'll notice it. Although your event agency or organization might not fall directly under the law, a strict 'supply chain responsibility' does apply. Does your organization, or your client, work in or for a sector that falls under NIS2? Then they must be able to demonstrate that their suppliers handle data securely, which is why IT and procurement ask for hard proof that your data is safe.
In short: time to step up your data security! In this blog, we'll bring you up to speed on the directive, how different countries are transposing it into national law, and what you as an event manager need to keep an eye on.
NIS2 is a European directive that obligates organizations with an essential or important societal role to structurally strengthen their cyber resilience. So the goal is to make organizations in the EU significantly more resilient against cybercrime. The directive entered into force on January 16, 2023.
NIS2 applies to essential and important entities, both large and medium-sized. Several strict requirements are set:
Organizations that fall under this must register.
They also have a faster and clearer reporting obligation.
A duty of care is required in which cybersecurity measures are implemented, for example regarding governance and risk management.
Ultimate responsibility is placed on the board.
EU countries were tasked with translating the directive into national law before October 17, 2024.
So, NIS2 applies to essential and important entities. The deciding factors are the sector, the company size, and in some cases, the activity.
The sectors are categorized as follows:
| Highly critical entities | Other critical entities |
| Energy | Postal and courier services |
| Transport | Manufacture, production, and distribution of chemicals |
| Financial market infrastructure and banking (both also under DORA legislation) | Waste management |
| Drinking water | Manufacturing |
| Wastewater | Digital providers |
| Digital infrastructure | Research |
| Government | Production, processing, and distribution of food |
| ICT service management | |
| Space | |
| Healthcare |
At its core, it comes down to organizations operating in one of these sectors that meet the conditions regarding company size:
Large companies: with 250+ employees or over 50 million in revenue.
Medium-sized companies: with more than 50 employees or over 10 million in revenue.
Don't fall into one of these sectors and/or work at a small organization? Odds are high that you don't fall under NIS2.
GDPR has made privacy and data protection mandatory for years, but NIS2 takes things a step further and turns this into an actively audited topic. The law also places accountability for meeting these requirements directly on the board itself.
The board must dive into this matter and complete training courses as well. There is also an obligation to ensure that the organization complies with this law. Because of this, it will become an active topic across all levels of the organization.
“By placing the responsibility on the board, a ladder of responsibility is actually created throughout the entire organization. A board member has to know what needs to be done, what your people are doing, and what obligations come along with it. Software procurement is also becoming more complicated—and therefore more work.”
Now you might think: aren't events usually not seen as essential? Usually not, no. However, essential and important entities do regularly organize events. Often, these are precisely the organizations that have many stakeholders. Think of a hospital organizing a symposium for hundreds of healthcare professionals, an energy company updating stakeholders on the energy transition, or a municipality organizing an event for residents and partner organizations.
And during event registration, you collect a lot of sensitive data without even realizing it: names, job titles, and direct contact details, but often dietary requirements, payment data, or access rights as well. To name a few.
Here are a few example scenarios where data security hits very close to home:
You're organizing an event for the residents of a specific municipality. During check-in, one of the hostesses leaves the tablet unattended on the table—with all available attendee data on it.
You work with an event software provider. There is a data breach through which attendee data may have been leaked. You'll then need to receive a notification within a specified timeframe, complete with the right information, and pass this along to the right people internally. As an event manager, you need to know how your software vendor handles this.
You work at an organization with multiple sub-entities, each organizing their own events with their own Excel spreadsheets and tools. Because of this, the board—which is now personally liable—has zero oversight of the amount of attendee data actually floating around the entire organization.
Is this new? Not entirely: data security has always been important, but NIS2 demands more from organizations. As an organization, you can't just 'quietly have your data security in order': you are required to actively audit it and verifiably prove it.
Of course, not all countries met the deadline. At the time of writing, some countries are still working on translating the law. We'll zoom in on the Netherlands, Belgium, and Germany as examples.
Belgium was one of the first EU countries to transpose the NIS2 law into national legislation, namely on October 18, 2024.
If you fall under this legislation, you must register with the CCB in Belgium. They have an online form for this, which is set up in this clear brochure. In Belgium, over 4,500 organizations have already registered through the CCB—though the CCB also advises organizations that don't fall under NIS2 to register as well.
Good to know: ISO 27001 is a handy certification to see if a vendor complies with various NIS2 measures. In Belgium, there is also CyberFundamentals (CyFun). This is recognized by the CCB as a comparable alternative to ISO 27001. This was specifically created for Belgium and is said to be faster and simpler to implement. 75% of Belgian organizations opted for CyFun instead of ISO 27001.
The Netherlands is translating the NIS2 directive into the Cybersecurity Act (Cyberbeveiligingswet). The law has been passed and goes into effect as of August 15, 2026. In the Netherlands, organizations must register with the supervisory authority via mijn.ncsc.nl. It is estimated that this involves at least 8,000 organizations.
The same guidelines regarding company size and sector apply for NIS2. The only exception to this is Higher Education: the Minister of Education has specifically designated this sector to comply with the Cbw as well.
The NIS2UmsuCG is an amended law that has been in force since December 6, 2025 (partly based on the EU NIS2 directive). In Germany as well, affected organizations must register with the BSI (in two steps) as an 'important' or 'particularly important' entity, for which a 'Mein Unternehmenskonto' via ELSTER must be set up in advance.
In Germany, approximately 21,600 companies are classified as important organizations and about 8,250 as particularly important—in addition to existing KRITIS operators.
With the right event software, you get the right guarantees. For yourself, your IT and compliance department, but also for external stakeholders. Here's what you can look out for:
Incident reporting process: Ask how quickly and in what manner a vendor reports a data breach.
Data retention periods or automatic deletion: Can you configure attendee data to be automatically and securely deleted after the event? This is also a good thing to ask about.
Check the Data Processing Agreement (DPA) upfront, not after the fact: Does the vendor have a standard DPA ready to go, instead of you having to push for one yourself?
Request the latest pentest/audit date: A vendor that can show on request when they were last externally tested provides more assurance than just a certification obtained a year ago.
Verifiable security certifications: Choose software with an ISO 27001 certification and a SOC 2 Type II report. This demonstrates that security and processes have been officially audited and proven. ISO is already a verifiable standard that focuses on policy and risk management around information security. SOC 2 takes it a step further and proves that it is actively tested.
European data storage: Check whether the servers are located within the EU, so that data processing also falls under EU law.
Strict access management: Make sure you can set exactly who within your team has access to specific (attendee) data, so sensitive information never ends up in the wrong place.
(Encrypted) uploading within the software: Avoid emailing personal data back and forth between team members and upload data securely within the software. Sometimes vendors take extra measures too, like encrypting attendee data within the software. That way, it stays safe even in the event of an unexpected data breach.
We recommend always asking about these matters when selecting a new vendor.
If you make data security and compliance an active priority from day one and set it up properly, that yields:
More peace of mind. You know this is properly handled and that risks are minimized.
Preventing doubts. Both among internal and external stakeholders.
Preventing delays in your planning process and making decisions faster.
This frees you up to fully focus on what counts: putting on a successful event.
Curious about how aanmelder.nl handles this? Read more on our security and compliance page or experience it for yourself.
At aanmelder.nl, we actively dive into data security to guarantee secure processes for event managers. However, this is general information based on our own expertise. It is not legal advice, so always consult an expert if in doubt.
Got security questions? We’ve got you covered.
Streamline your approval process with a platform built for strict EU compliance standards. Learn how we safeguard your attendee data, or start setting up your event right away.
Discover what aanmelder.nl has achieved over the past year and which steps we’re taking to make your events even easier in the future.
Increase the visibility and impact of your event with effective event marketing. Learn what it is, why it’s important, and how to apply it...
Discover what aanmelder.nl has achieved over the past year and the steps we’re taking to make organizing your events even easier in the future.