Skip to main content
📬 Get weekly Production AI insights Practical notes on Kubernetes, AI infrastructure and platform engineering. No spam. Subscribe free
Luca Berton taking a selfie under the Cybersec Netherlands sign at Jaarbeurs Utrecht, next to the Media Plaza
DevOps

Cybersec Netherlands 2025: CYRA and the Regulatory Wave

Cybersec Netherlands and Data Expo 2025 at Jaarbeurs Utrecht: FME's regulatory wave, the CCV's CYRA growth model for IT and OT, DIVD and the expo floor.

LB
Luca Berton
¡ 7 min read

On Wednesday 10 September 2025 I spent the first day of Cybersec Netherlands 2025 at Jaarbeurs in Utrecht. It ran on 10 and 11 September. The neighbouring hall 12 hosted Data Expo, a data and AI trade show on the same two days, so I could walk from security vendors to graph databases and back.

This is a throwback built from my photos and two short clips. I’ve kept to what was on the screens and signs and what was said to me. Where a talk touched EU law, I’ve checked the dates against the official EU pages and linked them.

Luca Berton taking a selfie under the large Cybersec Netherlands sign at Jaarbeurs Utrecht, with Find us in hall 11 on the right and the Media Plaza entrance behind

Morning arrival at Jaarbeurs: Cybersec Netherlands in hall 11, Data Expo through the hall 12 entrance.

The main stage: “Stronger Together”

I saw the main stage before the sessions started. The set carried the Cybersec Netherlands logo, the line “Stronger Together”, and “Program powered by Computable”.

Luca Berton taking a selfie in front of the empty Cybersec Netherlands main stage, with rows of chairs, a Stronger Together banner and a Program powered by Computable panel

The main stage, still empty.

A couple of hours later the same room was full, with people standing at the back. The keynote on screen was about the EU’s cyber crisis set-up. The slide title was “EU Blueprint – The Who (II)”, with a box on the CSIRTs Network, the EU’s network of national computer security incident response teams, and its role in exchanging information about incidents.

Luca Berton taking a selfie at the back of a packed main hall during a keynote, with the slide EU Blueprint - The Who (II) and a CSIRTs Network box on the screen

Standing at the back for the “EU Blueprint” keynote.

On the expo floors

Most of my morning went to the stands. A few stood out for my own work.

Neo4j at Data Expo. The Neo4j stand’s headline was “Build GenAI Apps With a GraphDB”, with the tagline “Accurate | Transparent | Explainable” and a demo zone. It’s the same GraphRAG message as at GraphSummit Amsterdam 2025.

The Neo4j stand banner at Data Expo 2025: neo4j Graph Database and Analytics, Build GenAI Apps With a GraphDB

Neo4j’s pitch at Data Expo: graphs as the grounding layer for GenAI apps.

OX Security. At the OX Security stand I recorded a short clip with one of their solutions engineers for my channel. According to him, OX Security is an application security platform “from code to cloud”: SAST, SCA and open source scanning, plus pipeline security, container scanning and cloud posture (CSPM) checks. On containers, his point was that they scan the Dockerfile before the image is built, to catch vulnerabilities introduced by build instructions, and then scan the built container as well. He also explained their DAST engine, dynamic application security testing, as the complement to static analysis: it scans the running web application and its APIs, including authenticated sessions.

DIVD. I also stopped at the stand of DIVD, the Dutch Institute for Vulnerability Disclosure. Its mission, in its own words, is to “make the digital world safer by reporting vulnerabilities we find in digital systems to the people who can fix them”. It’s run by volunteers, most of whom work in cybersecurity as their day job.

FME and CCV: the regulatory wave and CYRA

The talk that gave this post its name was in a small inflatable dome theatre in the early afternoon. It was a joint session by FME, the Dutch trade association for the technology industry, and the CCV, the Dutch Centre for Crime Prevention and Safety. The slide footer read “Cybersec 10&11 September: The Operation Under Pressure”.

An FME speaker presenting the Facts and Figures slide in the dome theatre, listing 2200 members, 220,000 employees, 139 billion turnover, 59 billion export, 34 partner branches and 80% SME

FME in numbers: 2,200 member companies, 80% of them SMEs.

FME opened with its own numbers. The slide said FME is “the trade association for the technology industry”, with 2,200 members ranging from tech start-ups, trading companies and SMEs to large industrial companies and multinationals. The figures were 220,000 employees, 139 billion turnover, 59 billion export, 34 partner branches and 80% SMEs.

The regulatory wave

The Regulatory Wave slide under Compliance Bottlenecks: NIS2, CRA, CSA, AI Act and Data Act push companies to raise their cybersecurity level, with a risk of duplication and double conformity assessments, next to a cartoon of FME surfing a wave of EU acts

“Regulatory Wave”: a surfer labelled FME riding a wave of acronyms while everyone else runs.

The slide I keep coming back to was titled “Regulatory Wave”, under the heading “Compliance bottlenecks”. It made two points:

  1. NIS2, the CRA, the CSA, the AI Act and the Data Act push companies to raise their cybersecurity level.
  2. There is a risk of duplication, fragmentation and double conformity assessments, eventually leading to rising costs and administrative burden.

Under “Needs” it listed five words: clarity, streamlined reporting, consistency, realism, proportionality. The illustration did the rest: a giant wave made of “NIS2”, “GDPR”, “Data Act”, “Digital Services Act” and more, a surfer with an FME board on top, and a beach full of people in suits running from it.

For context, here’s where the two big ones stand, from the European Commission’s own pages:

  • NIS2 is Directive (EU) 2022/2555. Member States had until 17 October 2024 to transpose it into national law.
  • The Cyber Resilience Act is Regulation (EU) 2024/2847. According to the Commission’s CRA page, it entered into force on 10 December 2024. Its reporting obligations apply from 11 September 2026, and its main obligations from 11 December 2027. It covers products with digital elements, from connected hardware to software.

The reporting date is worth noticing. It fell exactly one year after the second day of this conference, so by the time you read this, manufacturers already have to report actively exploited vulnerabilities and severe incidents. I’ve written about how that reporting works separately.

CYRA: a growth model for IT and OT

Sanaa van de Pol-Assa speaking with a microphone next to her introduction slide, which lists independent cybersecurity professional, advisor on cybersecurity certification schemes at the CCV, and experience at the NCSC leading OT initiatives

The CCV half of the session, introduced on its own slide.

The second half was presented by Sanaa van de Pol-Assa. Her slide introduced her as an independent cybersecurity professional and advisor on cybersecurity certification schemes at the CCV, with experience at the NCSC leading OT initiatives. She presented CYRA, short for Cyber Rating.

According to the CCV’s CYRA page, CYRA is an online method that organisations use to map their digital resilience, and the CCV, an independent non-profit, manages it. There are modules for different situations: CYRA-IT is based on ISO/IEC 27001 and 27701, and CYRA-OT, for organisations running operational technology, is based on IEC 62443.

The CYRA Method growth model slide for CYRA-OT, based on IEC 62443, showing four levels: entry level at 30%, basic level at 60%, intermediate level at 80% and advanced level at 100%

The CYRA growth model for OT: four levels, each building on the one before.

The growth model slide showed CYRA-OT as four steps: Entry level (30%), Basic level (60%), Intermediate level (80%) and Advanced level (100%). Each level was drawn as three sub-levels, and each step adds a row of requirements on top of the previous ones. The CCV page describes those sub-levels as the maturity stages ad hoc, best effort and defined.

The CYRA Self Assessment Process slide: a company runs a self assessment against CYRA-IT or CYRA-OT at the CCV, receives a PDF, and can move on to certification

The closing slide Build your Digital Resilience, Want to know more? www.hetccv.nl/CYRA, with a QR code and the CCV and FME logos

From self-assessment to certificate, and the closing call to action.

The process slide was simple. A company runs a self-assessment against CYRA-IT or CYRA-OT through the CCV, gets a PDF report back, and can then go on to certification. The CCV page adds that the self-assessment uses an online tool with an annual fee, and that independent, accredited certification bodies do the certification. The closing slide read “Build your Digital Resilience” and pointed to hetccv.nl/CYRA.

My take: for an SME facing NIS2 in its supply chain and the CRA on its products, the hardest step is the first one. A growth model with a 30% entry level is a better on-ramp than a full ISO 27001 or IEC 62443 programme. It shows how far along you are and what comes next. It isn’t CRA conformity, though. The CRA asks for security by design, vulnerability handling and reporting on each product, and no organisation-level rating replaces that. I’d use something like CYRA to get the basics and the habits in place, then map the product obligations separately.

What I took away

My take on the FME session: the problem it described wasn’t the rules themselves, it was the overlap between them. “Streamlined reporting” and “double conformity assessments” were the phrases on the slide, and they’re the right ones. For engineering teams, the practical answer is to build the evidence once, through SBOMs, vulnerability handling and incident runbooks in the pipeline, and reuse it for every framework that asks.

Free 30-min Production AI consultation

Book Now