The Cyberbeveiligingswet has applied since 15 August 2026. So the question for your organisation isn't "are we getting ready?" any more. It's this: can you show a supervisor that your measures, your governance and your incident process actually work?
We help Dutch organisations confirm scope, test their controls against the Cbw and the Cyberbeveiligingsbesluit, close the gaps that matter, and build evidence that holds up. That covers hands-on NIS2 consulting, independent audits, or both, with our testing team doing the technical checks in-house.
21+ years in security audit and compliance
CREST-accredited penetration testing
PCI QSA company · CERT-In empanelled
EU contracting via Zulon Audits OÜ, Tallinn
Where things stand
The Netherlands transposed the NIS2 Directive through the Cyberbeveiligingswet, and it's been law since 15 August 2026. According to the NCTV and the NCSC, it puts cybersecurity obligations on more than 8,000 organisations that provide essential or important services. Whether yours is one of them is something you work out yourself, and that's where a lot of organisations still have loose ends.
7 July 2026
Government confirms the Cbw and the Wet weerbaarheid kritieke entiteiten (Wwke) will take effect on 15 August.
15 August 2026
The Cbw (Stb. 2026, 187) and the Cyberbeveiligingsbesluit (Stb. 2026, 189) enter into force, replacing the Wbni. Registration with the NCSC is due from this date.
Now
Supervisors can use their powers. Seven sector ministerial regulations set incident-reporting thresholds.
By August 2028
Executive board members must have completed the required cybersecurity training (two years after entry into force).
Register in the NCSC's entity register through MijnNCSC (eHerkenning EH2+ or SSOnRijk). Keep the details current; changes go in within 14 days.
Take appropriate and proportionate technical, operational and organisational measures, based on a risk analysis. The Cyberbeveiligingsbesluit spells out what those measures must cover.
Report significant incidents through the central reporting point on MijnNCSC: early warning within 24 hours, notification within 72 hours, final report within one month.
The board approves the measures, oversees them, and has to know enough to judge cyber risk. Executive directors must complete suitable training.
NCTV / Ministry of Justice and Security owns the policy and explains the law. The NCSC runs the entity register and the MijnNCSC reporting point, and acts as the CSIRT for registered organisations. Sector supervisors check whether you comply. The NCSC's overview lists, among others: RDI (digital infrastructure, ICT service management, digital providers, energy, manufacturing, space, post and most government bodies), ILT (transport, waste water, water management, waste, chemicals; water boards), IGJ (health), DNB (banking), AFM (financial market infrastructure), NVWA (food) and ANVS (nuclear). Check the NCSC supervision page for your exact allocation.
One thing we'd flag straight away: if you're a bank or other financial entity under DORA, DORA takes precedence for ICT risk management and incident reporting. DNB notes that financial entities in NIS2 scope also report to the NCSC, so map both regimes rather than assuming one cancels the other. Our DORA compliance services cover that overlap.
Scope check
Most of the scoping questions we get are some version of "we're in manufacturing and have 120 people, so are we in?" The honest answer is "probably, if you make one of the listed products", and that's why it's worth being precise. Five questions will get you a first read.
Your indication
Answer the questions to see an indication
This is a first filter, not a legal conclusion. Scope under the Cbw depends on exactly which service you provide, how your group is structured and whether any special rules apply.
Confirm with the RDI's Cbw self-evaluation tool and the NCSC's scope guidance. That tool also indicates whether you're likely essential or important.
Talk through our scope with a consultantClassification
The obligations are the same. What changes is how closely you're watched. Being "important" doesn't mean lighter measures; it means a supervisor is more likely to arrive after something has gone wrong than before.
| Essential entity | Important entity | |
|---|---|---|
| Typical profile | Large organisations in Annex 1 (high-criticality) sectors, plus certain providers and government bodies regardless of size | Medium-sized organisations in Annex 1 sectors and medium or large organisations in Annex 2 sectors |
| Registration, zorgplicht, meldplicht | Yes | Yes, the same obligations |
| Board approval, oversight and training | Yes | Yes |
| How supervision works | Proactive (ex ante). The RDI may ask for information or visit; the IGJ can open an investigation at any time. | Mainly reactive (ex post), for example after an incident or when there are signs you're not complying. |
| Maximum fines under NIS2 | Member States must allow at least €10 million or 2% of worldwide annual turnover, whichever is higher | At least €7 million or 1.4% of worldwide annual turnover, whichever is higher |
| Temporary ban on managers (NIS2 Art. 32(5)) | Available as a last-resort measure | Not available |
Fine ceilings above are the NIS2 Directive minima (Art. 34); check the Cbw text for the exact Dutch amounts and for fines on individual directors. Your classification follows from sector, size and service, and the RDI tool gives an indication.
Consulting
People search for "NIS2 consulting" and "NIS2 consultancy" and mean the same thing: someone who'll work alongside the team and get the Cbw requirements properly embedded. Here's what our NIS2 consultancy work in the Netherlands covers, from the first scope call through to evidence you can show a supervisor.
Entity by entity, service by service. We look at group structure, the Annex 1/2 activity and the size test, and write down the reasoning so you can defend it.
Cbw, Cyberbeveiligingsbesluit and your sector's ministerial regulation, mapped to the frameworks you already run: ISO 27001, NEN 7510, BIO2 or IEC 62443.
A risk analysis method that ties threats to the services you deliver, not a generic register nobody opens.
Roles, reporting lines and the board decisions the Cbw expects, including how approval and oversight get minuted.
Only the policies you actually need, written so staff can follow them and auditors can test them.
Hands-on help with MFA, logging, access reviews, patching and hardening, prioritised by risk.
A playbook that meets 24h / 72h / one-month reporting through MijnNCSC, with your sector thresholds built in.
BCP, backup and recovery tested against the services that matter, plus crisis management.
Supplier tiering, questionnaires, contract clauses and monitoring for direct suppliers.
A lean evidence library: what exists, who owns it, when it was last reviewed.
Proof that controls operate: tickets, logs, test results, sign-offs, not just policy PDFs.
A funded, owned plan to close the gaps, and a re-test once they're closed.
Already on ISO 27001 or running several frameworks? Our AuditFusion360 approach maps one set of controls to NIS2, ISO 27001, GDPR and DORA, so you aren't testing the same thing four times.
Discuss Your NIS2 RequirementsWorking with a consultant
If you're looking for a NIS2 consultant, you probably want to know what the work looks like day to day. Here it is.
Turning a principle-based law into decisions. The Cbw doesn't give you a checklist; it says "appropriate and proportionate". A consultant helps you decide what that means for your services, your risks and your budget, then helps you implement it.
A fixed scope and timeline agreed up front, a named lead consultant, fortnightly progress check-ins, and draft findings shared early so there are no surprises at the end.
Your NCSC registration (or reasons you haven't registered), org chart and group structure, a service catalogue, existing policies and risk register, recent audit or pen-test reports, supplier list, and incident records from the last 12 months.
A scope memo, a requirements-to-control map, a gap register rated by risk, a remediation roadmap with owners, board briefing material, and an evidence index.
Every gap gets an owner, a target date and an acceptance test. We help fix the high-risk ones first, then re-test and close them with evidence rather than a status change in a spreadsheet.
Audit
An independent NIS2 audit answers the question a supervisor will eventually ask: do your measures work, and can you prove it? Our auditors test design and operating effectiveness against the Dutch requirements. Our CREST-accredited testers check the technical controls themselves rather than taking a screenshot on trust.
The Auditdienst Rijk has published a Cbw (NIS2) control framework that many Dutch public bodies use. We can audit against it, or against your own ISO 27001 or NEN 7510 control set mapped to the Cbw.
| Activity | Question it answers | How it works | What you get |
|---|---|---|---|
| Gap assessment | Where are we against the requirements? | Mostly design and documentation | Gap register, roadmap |
| Current-state / compliance assessment | How mature are we now, with some testing? | Design plus sample testing | Maturity view, prioritised gaps |
| NIS2 compliance audit | Do our controls operate effectively? | Evidence over a period, technical testing | Audit report, findings, opinion on the scope audited |
| Supervisor inspection | Is the entity complying with the law? | Supervisor's own powers under the Cbw | Instructions, orders, fines where needed |
| Certification (e.g. ISO 27001) | Does the ISMS meet a standard? | Accredited certification body | Certificate. Useful evidence, not proof of Cbw compliance |
Assessment
Our NIS2 gap assessment is where most organisations start, because it gives you a defensible baseline fast. Because the law is already in force, we treat it as a compliance assessment of what you have today, not a readiness exercise for later. There's a longer walkthrough in our NIS2 compliance checklist.
Entities, services, locations and systems in scope.
Cbw, Cbb and sector regulation to your control set.
Interviews and walkthroughs with owners.
Policies, procedures, risk analysis, BCP.
Sample what exists: logs, tickets, approvals.
Missing, partial or unproven controls.
Rate each gap by impact on your services.
Owners, dates, budget, quick wins first.
Re-test closed gaps and update the register.
Zorgplicht
The zorgplicht is risk-based: measures must be proportionate to your risks, the nature of your activity and what's technically available. The NCTV lists ten areas the measures have to cover, set out in detail in the Cyberbeveiligingsbesluit. The NCTV also notes you can use existing frameworks such as ISO 27001, NEN 7510 or BIO 2.0 to meet them.
01
Risk analysis, security policy
02
Detection, triage, response, reporting
03
Backups, disaster recovery, crisis management
04
Direct suppliers and service providers
05
Including vulnerability handling and disclosure
06
Policies and procedures to test your measures
07
Basic practices and staff awareness
08
Policies on cryptography and, where appropriate, encryption
09
Joiners, movers, leavers; least privilege; inventories
10
Multi-factor or continuous authentication, secured voice, video and text, emergency communications where appropriate
On effectiveness (area 06), independent testing is the fastest way to find out whether a control works. We run vulnerability assessments, CREST-accredited penetration testing and red team exercises in-house.
Meldplicht
A significant incident is one that causes, or could cause, serious disruption to your services or financial loss, or considerable damage to others. You report it once, through the central reporting point on MijnNCSC, and it reaches both your CSIRT and your supervisor (NCSC).
Within 24 hours
Say whether you suspect malicious action and whether there could be cross-border impact.
Within 72 hours
Update the early warning with an initial assessment of severity and impact, and indicators of compromise where available.
Within one month
Describe the incident, the likely root cause and the measures taken. If it's still ongoing, send a progress report and the final report within one month of handling it.
What counts as significant in your sector is set out in the ministerial regulation for that sector. Seven ministries have published one. Your playbook should quote your thresholds, not the general definition.
Smaller incidents and near-misses can be reported voluntarily. Those go to the CSIRT only, not the supervisor. More detail is in our NIS2 incident reporting timeline.
Bestuurders
Under the Cbw, cybersecurity is explicitly a board responsibility. This summary follows the NCTV guidance for directors.
Approve
The board approves the measures the organisation takes to meet the zorgplicht.
Oversee
It monitors whether those measures are implemented, and stays accountable even when a CISO runs the programme.
Know
Board members need enough knowledge and skills to understand cyber risks and their impact, keep that knowledge current, and actively ask for information on risks, measures and incidents.
Train
Executive directors of essential and important entities must complete suitable training within two years of entry into force. Supervisory board and non-executive members aren't covered by the training duty. The certificate must be in Dutch or English.
Need ongoing senior support? See our CISO advisory service.
Keten
The Cbw makes you responsible for the security of your relationships with direct suppliers and service providers. In practice that means eight things.
Tier suppliers by what they touch: your network, your data, your critical services.
MSPs, cloud, SaaS and hosting get the closest look; they often hold the keys.
Know which products and components your services rely on, including single points of failure.
Proportionate questionnaires and evidence requests before you sign, not after.
Check suppliers' secure development and vulnerability handling where it matters.
Track supplier advisories and patch windows for the products you run.
Clauses for incident notification, audit rights, subcontracting and exit.
Annual reviews for critical suppliers, event-driven reviews when something changes.
If you're on the other side of this, as a supplier to a Cbw-regulated organisation (an IT provider, payroll bureau or accountancy firm, say), you'll be getting these questionnaires too. An independent assessment or ISO 27001 certificate usually answers them faster than a hundred bespoke replies. Our third-party risk management service works from both sides.
Evidence
A policy that says "we use MFA" was fine for a readiness project. Now the law applies, it's the chain behind the policy that counts. Here's a worked example, followed from requirement to monitoring.
STEP 1
Requirement
Cbb: MFA where appropriate
STEP 2
Control
MFA on all remote and admin access
STEP 3
Implementation
Conditional access policy in the IdP
STEP 4
Evidence
Policy export, coverage report, exceptions list
STEP 5
Testing
Sample 25 admin accounts, try legacy protocols
STEP 6
Finding
Two service accounts bypass MFA
STEP 7
Remediation
Convert to managed identities, close legacy auth
STEP 8
Ongoing monitoring
Monthly coverage report to the CISO
The same chain works for every requirement. See our guide to NIS2 documentation requirements and policies for the document side.
Implementation
If you registered in August and haven't done much since, this is the order we'd tackle it in. If you're further along, start at the phase that fits.
Audit readiness
This is the evidence we usually ask for in a NIS2 audit. Not all of it applies to every entity, and a small important entity won't need the same depth as a large essential one. Proportionality works for you here, as long as you can explain your choices.
Requirements matrix
A one-page view you can use in a steering meeting. Scroll sideways on mobile.
| NIS2 / Cbw area | What it covers | Questions to ask | Potential evidence | How VISTA can support |
|---|---|---|---|---|
| Governance | Board approval and oversight of measures | Is there a recorded board decision on the measures? | Board minutes, decision log | Board briefing, decision template, assurance |
| Risk management | Risk analysis as the basis for measures | Does the analysis tie to our services and suppliers? | Risk method, register, treatment plans | Risk framework design and facilitation |
| Incident handling | Detection, response, meldplicht | Can we report within 24h via MijnNCSC? | Playbook, logs, tabletop results | Playbook, sector thresholds, tabletop exercise |
| Business continuity | Backups, DR, crisis management | When did we last restore a critical service? | BCP, restore tests, crisis exercises | BIA, BCP review, restore-test witness |
| Supply chain | Security of direct suppliers | Which suppliers could stop our service? | Supplier tiering, assessments, contracts | Supplier programme, assessments |
| Vulnerability management | Handling and disclosure of vulnerabilities | How fast do we patch criticals? | Scan results, patch SLAs, exceptions | VA and CREST pen testing |
| Access control | Least privilege, joiners/movers/leavers | Who has admin rights and why? | Access reviews, PAM logs | Access review design and testing |
| MFA | MFA or continuous authentication where appropriate | Are there any bypasses? | IdP policy exports, coverage reports | Configuration review, bypass testing |
| Training | Cyber hygiene, staff and board training | Can we show directors were trained? | Training records, certificates | Board and staff training |
| Management oversight | Ongoing monitoring of measures | Does the board see cyber KPIs? | Dashboards, reports to the board | KPI design, quarterly reporting |
| Audit & evidence | Assessing effectiveness | Would our evidence survive a supervisor's request? | Audit reports, remediation records | Independent NIS2 audit, re-testing |
Across the Netherlands
The Cbw looks very different depending on which supervisor you answer to. A logistics operator around the Port of Rotterdam deals with the ILT. A hospital group in Utrecht deals with the IGJ and already works to NEN 7510. A high-tech manufacturer in the Eindhoven region may be in Annex 2 without ever having thought of itself as "critical". Data centres and cloud providers around Amsterdam fall under the RDI. Ministries and agencies in The Hague work with BIO2.
Our NIS2 compliance services start from that sector reality: your supervisor, your ministerial regulation, the frameworks you already use. That's how we avoid giving you a generic EU answer.
Being upfront about how we work: VISTA Infosec has no office in the Netherlands. EU engagements are contracted through our Estonian entity, Zulon Audits OÜ in Tallinn, and delivered remote-first, with on-site visits by agreement. We work in English and use the Dutch legal terms (zorgplicht, meldplicht, bestuurders) as your team does. Evidence can be processed and stored in the EU.
Sectors
These are the sectors in the Cbw annexes. Being in one of them doesn't put you in scope automatically: the service you provide and your size decide that. And there are exceptions both ways, for example size-independent providers and government bodies.
Health is a good example of the detail that matters. The IGJ names healthcare providers, EU reference laboratories, pharmaceutical R&D, pharmaceutical manufacturers and medical device manufacturers, each subject to the size test.
Why us
We'd rather show you how we work than tell you we're the best. Here's what you can check.
21+ years of security audits. We're a PCI QSA company and PCI SSFA, ISO 27001-certified ourselves, and our team holds CISSP, CISA, CRISC and ISO 27001 Lead Auditor credentials.
CREST-accredited penetration testing and CERT-In empanelment mean technical controls get tested properly, not just asked about.
NIS2, ISO 27001, DORA, GDPR and SOC 2 mapped together, so your team answers each question once.
No fake certificates, no guaranteed outcomes, no Dutch office we don't have. Fixed-fee proposals with defined timelines.
Prefer to talk it through first? Book a free compliance consultation.
Cost
It depends on scope, and we won't pretend otherwise with a price list. A focused gap assessment for a single-entity important organisation is a very different job from a multi-entity audit with penetration testing. These are the factors that drive the fee:
Send us the basics through the form. We come back with questions, then a fixed fee, timeline and deliverables list. No hourly surprises.
Request a NIS2 AssessmentFAQ
Yes. The Cyberbeveiligingswet, the Dutch law that implements the NIS2 Directive, entered into force on 15 August 2026 together with the Cyberbeveiligingsbesluit. It replaced the Wbni. The obligations to register, take measures and report incidents apply from that date.
It applies to organisations that provide a service in one of the 18 sectors in the Cbw annexes and are medium-sized or larger (50 or more FTE, or turnover and balance sheet both above 10 million euros, counting linked enterprises). Some providers, such as DNS and trust service providers, and government organisations are in scope whatever their size. You determine this yourself; the RDI self-evaluation tool gives an indication.
Yes, if you fall under the Cbw. Registration is done in the NCSC entity register through MijnNCSC, using eHerkenning (EH2+) or SSOnRijk, and was due from 15 August 2026. You provide organisation and contact details and network data such as public IP ranges, domain names and AS numbers, and report changes within 14 days.
Both have the same obligations: registration, the zorgplicht, the meldplicht and board responsibilities. The difference is supervision. Essential entities are supervised proactively, so a supervisor can request information or visit at any time. Important entities are mainly supervised after the fact, for example after an incident. The maximum fines are also higher for essential entities.
A NIS2 consultant helps you confirm scope, map the Cbw requirements to your existing controls, decide what appropriate and proportionate measures look like for your risks, implement missing controls, set up incident reporting and supplier security, and build evidence. Typical deliverables are a scope memo, a gap register, a remediation roadmap and board briefing material.
A NIS2 auditor tests whether your measures are designed properly and operate effectively. That covers governance and board approval, the risk analysis, policies, technical controls such as MFA, access control and vulnerability management, incident handling and reporting, business continuity, and supply-chain security. The result is a report with findings rated by risk. It is evidence for you and your supervisor, not a regulatory decision.
A gap assessment compares what you have today with the Cbw requirements and produces a prioritised list of gaps and a roadmap. It focuses mainly on design and documentation. An audit goes further and tests evidence over a period to check that controls actually work. Many organisations start with a gap assessment and follow with an audit once the main gaps are closed.
For a significant incident you send an early warning within 24 hours, an incident notification within 72 hours and a final report within one month, all through the central reporting point on MijnNCSC. If the incident is still ongoing after a month, you send a progress report and the final report within one month of handling it. Sector thresholds are set in ministerial regulations.
The board must approve the cybersecurity measures, oversee their implementation and have enough knowledge to understand cyber risks. Executive board members of essential and important entities must complete suitable training within two years of the law entering into force. Delegating the work to a CISO does not transfer the board's responsibility.
No. There is no certificate that proves compliance with the Cbw. You can use frameworks such as ISO 27001, NEN 7510 or BIO 2.0 to meet the zorgplicht, and certification or an independent audit is useful evidence, but only the supervisor decides whether you comply.
Not simply because they are accountancy firms. Accountancy is not one of the sectors in the Cbw annexes, so a firm is only in scope if it provides a listed service and meets the size test. Most accountancy firms feel NIS2 indirectly: clients that fall under the Cbw ask their suppliers about security as part of their supply-chain duty, and auditors may consider a client's Cbw compliance when looking at laws and regulations.
It depends on scope: the number of entities and locations, your classification, the technology environment, current maturity, the number of critical suppliers, the audit period and how much technical testing is needed. We give a fixed-fee proposal with a defined timeline after a short scoping call.
Expert Auditors. Faster Certification.
European Operations
European engagements are delivered through Zulon Audits OÜ, the European practice of VISTA InfoSec.
Visit Zulon Audits →
VISTA InfoSec LLC,347 Fifth Ave,
Suite 1402-526, New York, NY 10016
© Copyright 2026. VISTA InfoSec. All Rights Reserved. | Disclosure Policy | Privacy Policy | Sitemap
Enquire Now
WhatsApp us