NIS2 compliance and cloud sovereignty
A large part of the duty of care under NIS2 revolves around the question: where are your data and systems located, who has access to them, and how well is that secured? This makes the choice of your cloud infrastructure directly relevant to your NIS2 compliance.
When business-critical or personal data is hosted by parties outside the EU, or by providers subject to foreign legislation such as the US Cloud Act, a risk arises that is difficult to manage within your own risk analysis. A sovereign cloud, fully hosted in Dutch data centers and under Dutch law, significantly limits this risk: data remains within the Dutch jurisdiction, under your own control over people, processes, and technology.
With its sovereign cloud, Fundaments offers an infrastructure that is fully hosted in the Netherlands, distributed across data centers in the East, Central, and West of the Netherlands, and where data is demonstrably subject to Dutch laws and regulations. This makes it a logical building block for organizations that want to fulfill their NIS2 duty of care without compromising on control over their data. You can find more information about this on our page about the Fundaments sovereign cloud.
Demonstrating that you are in control: certifications
Under NIS2, it is not enough to say that you "have things well organized"; you must be able to demonstrate it. Independent certifications are an important tool for this, both for supervisory authorities and for your own customers and supply chain partners. When choosing a cloud partner, it is therefore wise to look for the following certifications:
• ISO 27001. The international standard for information security. An ISO 27001 certification demonstrates that an organization has implemented a structured Information Security Management System (ISMS), including risk assessment, policy, and continuous improvement. This is directly relevant to the duty of care under NIS2.
• NEN 7510. The Dutch standard for information security in healthcare, based on ISO 27001 and 27002 but supplemented with sector-specific requirements. For healthcare organizations falling under NIS2, a NEN 7510-certified cloud provider is often a prerequisite for being able to demonstrate their own compliance.
• ISAE 3402. An international assurance standard through which a service provider, via an independent auditor, demonstrates that internal control measures regarding continuity, change management, and access security are effectively in place (Type II report). For organizations that must manage supply chain risks under NIS2, an ISAE 3402 statement from their cloud provider serves as concrete evidence for their own auditor or regulator.
Fundaments holds these certifications for its infrastructure and organization, allowing customers to use them directly in their own NIS2 documentation.