vista infosec white

NIS2 Consultancy

NIS2 Consultancy and Audit in the Netherlands

The Cyberbeveiligingswet has applied since 15 August 2026. So the question for your organisation isn't "are we getting ready?" any more. It's this: can you show a supervisor that your measures, your governance and your incident process actually work?

We help Dutch organisations confirm scope, test their controls against the Cbw and the Cyberbeveiligingsbesluit, close the gaps that matter, and build evidence that holds up. That covers hands-on NIS2 consulting, independent audits, or both, with our testing team doing the technical checks in-house.

In force since 15 Aug 2026RegistratieplichtZorgplichtMeldplichtBoard training

Talk to a Compliance Expert

    21+ years in security audit and compliance

    CREST-accredited penetration testing

    PCI QSA company · CERT-In empanelled

    EU contracting via Zulon Audits OÜ, Tallinn

    Where things stand

    NIS2 Compliance in the Netherlands: The Law Is Live

    The Netherlands transposed the NIS2 Directive through the Cyberbeveiligingswet, and it's been law since 15 August 2026. According to the NCTV and the NCSC, it puts cybersecurity obligations on more than 8,000 organisations that provide essential or important services. Whether yours is one of them is something you work out yourself, and that's where a lot of organisations still have loose ends.

    Key dates

    7 July 2026

    Government confirms the Cbw and the Wet weerbaarheid kritieke entiteiten (Wwke) will take effect on 15 August.

    15 August 2026

    The Cbw (Stb. 2026, 187) and the Cyberbeveiligingsbesluit (Stb. 2026, 189) enter into force, replacing the Wbni. Registration with the NCSC is due from this date.

    Now

    Supervisors can use their powers. Seven sector ministerial regulations set incident-reporting thresholds.

    By August 2028

    Executive board members must have completed the required cybersecurity training (two years after entry into force).

    Four obligations you now carry

    Registratieplicht

    Register in the NCSC's entity register through MijnNCSC (eHerkenning EH2+ or SSOnRijk). Keep the details current; changes go in within 14 days.

    Zorgplicht

    Take appropriate and proportionate technical, operational and organisational measures, based on a risk analysis. The Cyberbeveiligingsbesluit spells out what those measures must cover.

    Meldplicht

    Report significant incidents through the central reporting point on MijnNCSC: early warning within 24 hours, notification within 72 hours, final report within one month.

    Bestuurders

    The board approves the measures, oversees them, and has to know enough to judge cyber risk. Executive directors must complete suitable training.

    Who does what in the Dutch system

    NCTV / Ministry of Justice and Security owns the policy and explains the law. The NCSC runs the entity register and the MijnNCSC reporting point, and acts as the CSIRT for registered organisations. Sector supervisors check whether you comply. The NCSC's overview lists, among others: RDI (digital infrastructure, ICT service management, digital providers, energy, manufacturing, space, post and most government bodies), ILT (transport, waste water, water management, waste, chemicals; water boards), IGJ (health), DNB (banking), AFM (financial market infrastructure), NVWA (food) and ANVS (nuclear). Check the NCSC supervision page for your exact allocation.

    One thing we'd flag straight away: if you're a bank or other financial entity under DORA, DORA takes precedence for ICT risk management and incident reporting. DNB notes that financial entities in NIS2 scope also report to the NCSC, so map both regimes rather than assuming one cancels the other. Our DORA compliance services cover that overlap.

    Scope check

    Does the Cyberbeveiligingswet Apply to Your Organisation?

    Most of the scoping questions we get are some version of "we're in manufacturing and have 120 people, so are we in?" The honest answer is "probably, if you make one of the listed products", and that's why it's worth being precise. Five questions will get you a first read.

    1. Do you provide a service in one of the Cbw's 18 sectors?

    Annex 1 and 2 of the Cbw: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management (B2B), public administration, space, post and courier, waste management, chemicals, food, manufacturing of certain products, digital providers, research.

    2. Is the organisation medium-sized or larger?

    50 or more FTE, or fewer than 50 FTE with annual turnover and balance sheet both above €10 million. Partner and linked enterprises (parent, subsidiaries) count too.

    3. Do you provide one of the services that's in scope whatever your size?

    For example DNS services, TLD registries, public electronic communications networks or services, trust services, or you're a government organisation.

    4. Is the organisation established in the Netherlands?

    Some digital providers are supervised where their main establishment in the EU sits, which may not be the Netherlands.

    5. Are you a financial entity under DORA?

    Banks, payment and e-money institutions, investment firms, insurers and similar. DORA applies as the specific regime for ICT risk and incident reporting.

    Your indication

    Answer the questions to see an indication

    This is a first filter, not a legal conclusion. Scope under the Cbw depends on exactly which service you provide, how your group is structured and whether any special rules apply.

    Confirm with the RDI's Cbw self-evaluation tool and the NCSC's scope guidance. That tool also indicates whether you're likely essential or important.

    Talk through our scope with a consultant

    Classification

    Essential vs Important Entities Under the Cbw

    The obligations are the same. What changes is how closely you're watched. Being "important" doesn't mean lighter measures; it means a supervisor is more likely to arrive after something has gone wrong than before.

    Essential entityImportant entity
    Typical profileLarge organisations in Annex 1 (high-criticality) sectors, plus certain providers and government bodies regardless of sizeMedium-sized organisations in Annex 1 sectors and medium or large organisations in Annex 2 sectors
    Registration, zorgplicht, meldplichtYesYes, the same obligations
    Board approval, oversight and trainingYesYes
    How supervision worksProactive (ex ante). The RDI may ask for information or visit; the IGJ can open an investigation at any time.Mainly reactive (ex post), for example after an incident or when there are signs you're not complying.
    Maximum fines under NIS2Member States must allow at least €10 million or 2% of worldwide annual turnover, whichever is higherAt least €7 million or 1.4% of worldwide annual turnover, whichever is higher
    Temporary ban on managers (NIS2 Art. 32(5))Available as a last-resort measureNot available

    Fine ceilings above are the NIS2 Directive minima (Art. 34); check the Cbw text for the exact Dutch amounts and for fines on individual directors. Your classification follows from sector, size and service, and the RDI tool gives an indication.

    Consulting

    NIS2 Compliance Consulting and Consultancy for Dutch Organisations

    People search for "NIS2 consulting" and "NIS2 consultancy" and mean the same thing: someone who'll work alongside the team and get the Cbw requirements properly embedded. Here's what our NIS2 consultancy work in the Netherlands covers, from the first scope call through to evidence you can show a supervisor.

    Scope determination

    Entity by entity, service by service. We look at group structure, the Annex 1/2 activity and the size test, and write down the reasoning so you can defend it.

    Requirements mapping

    Cbw, Cyberbeveiligingsbesluit and your sector's ministerial regulation, mapped to the frameworks you already run: ISO 27001, NEN 7510, BIO2 or IEC 62443.

    Risk-management framework

    A risk analysis method that ties threats to the services you deliver, not a generic register nobody opens.

    Governance

    Roles, reporting lines and the board decisions the Cbw expects, including how approval and oversight get minuted.

    Policies

    Only the policies you actually need, written so staff can follow them and auditors can test them.

    Control implementation

    Hands-on help with MFA, logging, access reviews, patching and hardening, prioritised by risk.

    Incident management

    A playbook that meets 24h / 72h / one-month reporting through MijnNCSC, with your sector thresholds built in.

    Business continuity

    BCP, backup and recovery tested against the services that matter, plus crisis management.

    Supply-chain security

    Supplier tiering, questionnaires, contract clauses and monitoring for direct suppliers.

    Documentation

    A lean evidence library: what exists, who owns it, when it was last reviewed.

    Evidence

    Proof that controls operate: tickets, logs, test results, sign-offs, not just policy PDFs.

    Remediation

    A funded, owned plan to close the gaps, and a re-test once they're closed.

    Already on ISO 27001 or running several frameworks? Our AuditFusion360 approach maps one set of controls to NIS2, ISO 27001, GDPR and DORA, so you aren't testing the same thing four times.

    Discuss Your NIS2 Requirements

    Working with a consultant

    What a NIS2 Consultant Does for You

    If you're looking for a NIS2 consultant, you probably want to know what the work looks like day to day. Here it is.

    What does a NIS2 consultant actually help with?

    Turning a principle-based law into decisions. The Cbw doesn't give you a checklist; it says "appropriate and proportionate". A consultant helps you decide what that means for your services, your risks and your budget, then helps you implement it.

    What should you expect from an engagement?

    A fixed scope and timeline agreed up front, a named lead consultant, fortnightly progress check-ins, and draft findings shared early so there are no surprises at the end.

    What information will the consultant need?

    Your NCSC registration (or reasons you haven't registered), org chart and group structure, a service catalogue, existing policies and risk register, recent audit or pen-test reports, supplier list, and incident records from the last 12 months.

    What deliverables will you get?

    A scope memo, a requirements-to-control map, a gap register rated by risk, a remediation roadmap with owners, board briefing material, and an evidence index.

    How does it get from gaps to remediation?

    Every gap gets an owner, a target date and an acceptance test. We help fix the high-risk ones first, then re-test and close them with evidence rather than a status change in a spreadsheet.

    Talk to a NIS2 Consultant

    Audit

    NIS2 Audit Services in the Netherlands

    An independent NIS2 audit answers the question a supervisor will eventually ask: do your measures work, and can you prove it? Our auditors test design and operating effectiveness against the Dutch requirements. Our CREST-accredited testers check the technical controls themselves rather than taking a screenshot on trust.

    What our NIS2 auditors look at

    • Audit scope agreed against the Cbw, the Cyberbeveiligingsbesluit and your sector regulation
    • Requirements mapped to your control framework (ISO 27001, NEN 7510, BIO2 or the Auditdienst Rijk Cbw control framework)
    • Governance: board approval, oversight minutes, training records
    • Documentation review: policies, procedures, risk analysis
    • Evidence sampling across the review period
    • Operating effectiveness: do controls work consistently, not just on the day?
    • Technical controls: MFA, access, logging, vulnerability management, hardening, backups
    • Incident process walkthrough and reporting against MijnNCSC timelines
    • Supply-chain security: supplier assessments, contracts, monitoring
    • Findings rated by risk, with management responses
    • Remediation plan and follow-up testing

    Let us be straight about three things

    • There is no official NIS2 or Cbw certificate. We won't sell you one, and you should be wary of anyone who does.
    • Our audit isn't a regulatory decision. Only your supervisor decides whether you comply; our report is evidence that helps you show it.
    • We're independent of the fixes. If we built your controls, we'll tell you, and we can separate the audit team from the consulting team.

    The Auditdienst Rijk has published a Cbw (NIS2) control framework that many Dutch public bodies use. We can audit against it, or against your own ISO 27001 or NEN 7510 control set mapped to the Cbw.

    Gap assessment, audit, inspection, certificate: which is which?

    ActivityQuestion it answersHow it worksWhat you get
    Gap assessmentWhere are we against the requirements?Mostly design and documentationGap register, roadmap
    Current-state / compliance assessmentHow mature are we now, with some testing?Design plus sample testingMaturity view, prioritised gaps
    NIS2 compliance auditDo our controls operate effectively?Evidence over a period, technical testingAudit report, findings, opinion on the scope audited
    Supervisor inspectionIs the entity complying with the law?Supervisor's own powers under the CbwInstructions, orders, fines where needed
    Certification (e.g. ISO 27001)Does the ISMS meet a standard?Accredited certification bodyCertificate. Useful evidence, not proof of Cbw compliance
    Request a NIS2 Audit

    Assessment

    NIS2 Gap Assessment: Nine Steps From Scope to Proof

    Our NIS2 gap assessment is where most organisations start, because it gives you a defensible baseline fast. Because the law is already in force, we treat it as a compliance assessment of what you have today, not a readiness exercise for later. There's a longer walkthrough in our NIS2 compliance checklist.

    1. 1

      Confirm scope

      Entities, services, locations and systems in scope.

    2. 2

      Map requirements

      Cbw, Cbb and sector regulation to your control set.

    3. 3

      Review current controls

      Interviews and walkthroughs with owners.

    4. 4

      Review documentation

      Policies, procedures, risk analysis, BCP.

    5. 5

      Assess evidence

      Sample what exists: logs, tickets, approvals.

    6. 6

      Identify gaps

      Missing, partial or unproven controls.

    7. 7

      Prioritise risk

      Rate each gap by impact on your services.

    8. 8

      Build the roadmap

      Owners, dates, budget, quick wins first.

    9. 9

      Validate improvements

      Re-test closed gaps and update the register.

    Request a NIS2 Gap Assessment

    Zorgplicht

    Cybersecurity Risk-Management Measures the Cbw Expects

    The zorgplicht is risk-based: measures must be proportionate to your risks, the nature of your activity and what's technically available. The NCTV lists ten areas the measures have to cover, set out in detail in the Cyberbeveiligingsbesluit. The NCTV also notes you can use existing frameworks such as ISO 27001, NEN 7510 or BIO 2.0 to meet them.

    01

    Risk analysis and information-system security policy

    Risk analysis, security policy

    02

    Incident handling

    Detection, triage, response, reporting

    03

    Business continuity and crisis management

    Backups, disaster recovery, crisis management

    04

    Supply-chain security

    Direct suppliers and service providers

    05

    Secure acquisition, development and maintenance

    Including vulnerability handling and disclosure

    06

    Assessing effectiveness

    Policies and procedures to test your measures

    07

    Cyber hygiene and training

    Basic practices and staff awareness

    08

    Cryptography

    Policies on cryptography and, where appropriate, encryption

    09

    HR security, access control and asset management

    Joiners, movers, leavers; least privilege; inventories

    10

    MFA and secure communications

    Multi-factor or continuous authentication, secured voice, video and text, emergency communications where appropriate

    On effectiveness (area 06), independent testing is the fastest way to find out whether a control works. We run vulnerability assessments, CREST-accredited penetration testing and red team exercises in-house.

    Meldplicht

    Incident Reporting Under the Cyberbeveiligingswet

    A significant incident is one that causes, or could cause, serious disruption to your services or financial loss, or considerable damage to others. You report it once, through the central reporting point on MijnNCSC, and it reaches both your CSIRT and your supervisor (NCSC).

    Within 24 hours

    Early warning

    Say whether you suspect malicious action and whether there could be cross-border impact.

    Within 72 hours

    Incident notification

    Update the early warning with an initial assessment of severity and impact, and indicators of compromise where available.

    Within one month

    Final report

    Describe the incident, the likely root cause and the measures taken. If it's still ongoing, send a progress report and the final report within one month of handling it.

    Sector thresholds decide when you must report

    What counts as significant in your sector is set out in the ministerial regulation for that sector. Seven ministries have published one. Your playbook should quote your thresholds, not the general definition.

    Smaller incidents and near-misses can be reported voluntarily. Those go to the CSIRT only, not the supervisor. More detail is in our NIS2 incident reporting timeline.

    Where teams usually slip

    • The 24-hour clock starts at awareness, and nobody knows who decides that awareness has happened.
    • The person who can log in to MijnNCSC is on holiday.
    • No one has the sector thresholds to hand at 2 a.m.
    • Customers who must be told about the incident get forgotten while the report goes out.
    • DORA entities send one report and forget the other route.

    Bestuurders

    Management Responsibility: What the Board Has to Do

    Under the Cbw, cybersecurity is explicitly a board responsibility. This summary follows the NCTV guidance for directors.

    Approve

    The board approves the measures the organisation takes to meet the zorgplicht.

    Oversee

    It monitors whether those measures are implemented, and stays accountable even when a CISO runs the programme.

    Know

    Board members need enough knowledge and skills to understand cyber risks and their impact, keep that knowledge current, and actively ask for information on risks, measures and incidents.

    Train

    Executive directors of essential and important entities must complete suitable training within two years of entry into force. Supervisory board and non-executive members aren't covered by the training duty. The certificate must be in Dutch or English.

    How we help boards

    • A two-hour Cbw briefing for the executive board, with attendance records you can keep as evidence
    • A board decision template for approving the zorgplicht measures
    • A quarterly cyber dashboard the board can actually read
    • Independent assurance so the board isn't just marking its own homework

    Need ongoing senior support? See our CISO advisory service.

    Keten

    Supply-Chain Security in Practice

    The Cbw makes you responsible for the security of your relationships with direct suppliers and service providers. In practice that means eight things.

    Supplier risk

    Tier suppliers by what they touch: your network, your data, your critical services.

    Service providers

    MSPs, cloud, SaaS and hosting get the closest look; they often hold the keys.

    Technology dependencies

    Know which products and components your services rely on, including single points of failure.

    Due diligence

    Proportionate questionnaires and evidence requests before you sign, not after.

    Security practices

    Check suppliers' secure development and vulnerability handling where it matters.

    Vulnerabilities

    Track supplier advisories and patch windows for the products you run.

    Contracts

    Clauses for incident notification, audit rights, subcontracting and exit.

    Ongoing monitoring

    Annual reviews for critical suppliers, event-driven reviews when something changes.

    If you're on the other side of this, as a supplier to a Cbw-regulated organisation (an IT provider, payroll bureau or accountancy firm, say), you'll be getting these questionnaires too. An independent assessment or ISO 27001 certificate usually answers them faster than a hundred bespoke replies. Our third-party risk management service works from both sides.

    Evidence

    From Policy to Evidence: What Compliance Looks Like Now

    A policy that says "we use MFA" was fine for a readiness project. Now the law applies, it's the chain behind the policy that counts. Here's a worked example, followed from requirement to monitoring.

    STEP 1

    Requirement

    Cbb: MFA where appropriate

    STEP 2

    Control

    MFA on all remote and admin access

    STEP 3

    Implementation

    Conditional access policy in the IdP

    STEP 4

    Evidence

    Policy export, coverage report, exceptions list

    STEP 5

    Testing

    Sample 25 admin accounts, try legacy protocols

    STEP 6

    Finding

    Two service accounts bypass MFA

    STEP 7

    Remediation

    Convert to managed identities, close legacy auth

    STEP 8

    Ongoing monitoring

    Monthly coverage report to the CISO

    The same chain works for every requirement. See our guide to NIS2 documentation requirements and policies for the document side.

    Implementation

    NIS2 Implementation Roadmap: 14 Steps in Four Phases

    If you registered in August and haven't done much since, this is the order we'd tackle it in. If you're further along, start at the phase that fits.

    Phase 1 · Know

    1. 1Confirm scope
    2. 2Determine entity classification
    3. 3Map requirements
    4. 4Assess current state

    Phase 2 · Decide

    1. 5Identify gaps
    2. 6Prioritise risk

    Phase 3 · Build

    1. 7Implement controls
    2. 8Strengthen supply chain
    3. 9Establish incident processes
    4. 10Build evidence
    5. 11Review management oversight

    Phase 4 · Prove

    1. 12Test effectiveness
    2. 13Remediate findings
    3. 14Maintain compliance
    Get Implementation Support

    Audit readiness

    NIS2 Audit and Evidence Readiness

    This is the evidence we usually ask for in a NIS2 audit. Not all of it applies to every entity, and a small important entity won't need the same depth as a large essential one. Proportionality works for you here, as long as you can explain your choices.

    Governance

    • Board approval of measures
    • Oversight minutes
    • Director training certificates
    • Roles and responsibilities

    Risk & policy

    • Risk analysis
    • Security policies
    • Asset inventories
    • Supplier assessments and contracts

    Operations

    • Access-control reviews
    • MFA coverage
    • Vulnerability and patch records
    • Training records

    Resilience

    • Incident procedures and records
    • BCP and crisis plans
    • Backup and recovery test results
    • Security testing reports

    Assurance

    • Audit findings
    • Remediation records
    • Management responses
    • Registration details on MijnNCSC

    Requirements matrix

    NIS2 Requirements Matrix for the Cbw

    A one-page view you can use in a steering meeting. Scroll sideways on mobile.

    NIS2 / Cbw areaWhat it coversQuestions to askPotential evidenceHow VISTA can support
    GovernanceBoard approval and oversight of measuresIs there a recorded board decision on the measures?Board minutes, decision logBoard briefing, decision template, assurance
    Risk managementRisk analysis as the basis for measuresDoes the analysis tie to our services and suppliers?Risk method, register, treatment plansRisk framework design and facilitation
    Incident handlingDetection, response, meldplichtCan we report within 24h via MijnNCSC?Playbook, logs, tabletop resultsPlaybook, sector thresholds, tabletop exercise
    Business continuityBackups, DR, crisis managementWhen did we last restore a critical service?BCP, restore tests, crisis exercisesBIA, BCP review, restore-test witness
    Supply chainSecurity of direct suppliersWhich suppliers could stop our service?Supplier tiering, assessments, contractsSupplier programme, assessments
    Vulnerability managementHandling and disclosure of vulnerabilitiesHow fast do we patch criticals?Scan results, patch SLAs, exceptionsVA and CREST pen testing
    Access controlLeast privilege, joiners/movers/leaversWho has admin rights and why?Access reviews, PAM logsAccess review design and testing
    MFAMFA or continuous authentication where appropriateAre there any bypasses?IdP policy exports, coverage reportsConfiguration review, bypass testing
    TrainingCyber hygiene, staff and board trainingCan we show directors were trained?Training records, certificatesBoard and staff training
    Management oversightOngoing monitoring of measuresDoes the board see cyber KPIs?Dashboards, reports to the boardKPI design, quarterly reporting
    Audit & evidenceAssessing effectivenessWould our evidence survive a supervisor's request?Audit reports, remediation recordsIndependent NIS2 audit, re-testing

    Across the Netherlands

    NIS2 Compliance Services Across the Netherlands

    The Cbw looks very different depending on which supervisor you answer to. A logistics operator around the Port of Rotterdam deals with the ILT. A hospital group in Utrecht deals with the IGJ and already works to NEN 7510. A high-tech manufacturer in the Eindhoven region may be in Annex 2 without ever having thought of itself as "critical". Data centres and cloud providers around Amsterdam fall under the RDI. Ministries and agencies in The Hague work with BIO2.

    Our NIS2 compliance services start from that sector reality: your supervisor, your ministerial regulation, the frameworks you already use. That's how we avoid giving you a generic EU answer.

    Being upfront about how we work: VISTA Infosec has no office in the Netherlands. EU engagements are contracted through our Estonian entity, Zulon Audits OÜ in Tallinn, and delivered remote-first, with on-site visits by agreement. We work in English and use the Dutch legal terms (zorgplicht, meldplicht, bestuurders) as your team does. Evidence can be processed and stored in the EU.

    Where we typically help

    • Amsterdam: digital infrastructure, cloud, SaaS
    • Rotterdam: ports, logistics, chemicals, energy
    • The Hague: government and public bodies
    • Utrecht: health, ICT service providers
    • Eindhoven: high-tech manufacturing, research

    Sectors

    Who May Be Affected?

    These are the sectors in the Cbw annexes. Being in one of them doesn't put you in scope automatically: the service you provide and your size decide that. And there are exceptions both ways, for example size-independent providers and government bodies.

    Annex 1: sectors of high criticality

    EnergyTransportBankingFinancial market infrastructureHealthDrinking waterWaste waterDigital infrastructureICT service management (B2B)Public administrationSpace

    Annex 2: other critical sectors

    Postal and courier servicesWaste managementChemicalsFood production, processing and distributionManufacturing (e.g. medical devices, electronics, machinery, vehicles)Digital providers (marketplaces, search engines, social networks)Research organisations

    Health is a good example of the detail that matters. The IGJ names healthcare providers, EU reference laboratories, pharmaceutical R&D, pharmaceutical manufacturers and medical device manufacturers, each subject to the size test.

    Why us

    Why Work With VISTA Infosec on NIS2

    We'd rather show you how we work than tell you we're the best. Here's what you can check.

    Audit is our day job

    21+ years of security audits. We're a PCI QSA company and PCI SSFA, ISO 27001-certified ourselves, and our team holds CISSP, CISA, CRISC and ISO 27001 Lead Auditor credentials.

    Testing in-house

    CREST-accredited penetration testing and CERT-In empanelment mean technical controls get tested properly, not just asked about.

    One control set, many frameworks

    NIS2, ISO 27001, DORA, GDPR and SOC 2 mapped together, so your team answers each question once.

    Honest about limits

    No fake certificates, no guaranteed outcomes, no Dutch office we don't have. Fixed-fee proposals with defined timelines.

    Prefer to talk it through first? Book a free compliance consultation.

    Cost

    How Much Does a NIS2 Audit or Consultancy Engagement Cost?

    It depends on scope, and we won't pretend otherwise with a price list. A focused gap assessment for a single-entity important organisation is a very different job from a multi-entity audit with penetration testing. These are the factors that drive the fee:

    • Organisation size and number of legal entities
    • Essential or important classification
    • Number of locations and business units
    • Technology environment (cloud, OT, legacy)
    • Current maturity and existing certifications
    • Number of critical suppliers
    • State of documentation
    • Audit scope and review period
    • Technical testing required
    • Implementation support needed
    • Volume of remediation

    Get a scoped, fixed-fee proposal

    Send us the basics through the form. We come back with questions, then a fixed fee, timeline and deliverables list. No hourly surprises.

    Request a NIS2 Assessment

    FAQ

    NIS2 Consultancy and Audit in the Netherlands: FAQs

    Is the Cyberbeveiligingswet in force in the Netherlands?

    Yes. The Cyberbeveiligingswet, the Dutch law that implements the NIS2 Directive, entered into force on 15 August 2026 together with the Cyberbeveiligingsbesluit. It replaced the Wbni. The obligations to register, take measures and report incidents apply from that date.

    Does the Cbw apply to my organisation?

    It applies to organisations that provide a service in one of the 18 sectors in the Cbw annexes and are medium-sized or larger (50 or more FTE, or turnover and balance sheet both above 10 million euros, counting linked enterprises). Some providers, such as DNS and trust service providers, and government organisations are in scope whatever their size. You determine this yourself; the RDI self-evaluation tool gives an indication.

    Do we need to register with the NCSC?

    Yes, if you fall under the Cbw. Registration is done in the NCSC entity register through MijnNCSC, using eHerkenning (EH2+) or SSOnRijk, and was due from 15 August 2026. You provide organisation and contact details and network data such as public IP ranges, domain names and AS numbers, and report changes within 14 days.

    What is the difference between an essential and an important entity?

    Both have the same obligations: registration, the zorgplicht, the meldplicht and board responsibilities. The difference is supervision. Essential entities are supervised proactively, so a supervisor can request information or visit at any time. Important entities are mainly supervised after the fact, for example after an incident. The maximum fines are also higher for essential entities.

    What does a NIS2 consultant do?

    A NIS2 consultant helps you confirm scope, map the Cbw requirements to your existing controls, decide what appropriate and proportionate measures look like for your risks, implement missing controls, set up incident reporting and supplier security, and build evidence. Typical deliverables are a scope memo, a gap register, a remediation roadmap and board briefing material.

    What does a NIS2 auditor assess?

    A NIS2 auditor tests whether your measures are designed properly and operate effectively. That covers governance and board approval, the risk analysis, policies, technical controls such as MFA, access control and vulnerability management, incident handling and reporting, business continuity, and supply-chain security. The result is a report with findings rated by risk. It is evidence for you and your supervisor, not a regulatory decision.

    What is a NIS2 gap assessment, and how is it different from an audit?

    A gap assessment compares what you have today with the Cbw requirements and produces a prioritised list of gaps and a roadmap. It focuses mainly on design and documentation. An audit goes further and tests evidence over a period to check that controls actually work. Many organisations start with a gap assessment and follow with an audit once the main gaps are closed.

    What are the incident reporting deadlines under the Cbw?

    For a significant incident you send an early warning within 24 hours, an incident notification within 72 hours and a final report within one month, all through the central reporting point on MijnNCSC. If the incident is still ongoing after a month, you send a progress report and the final report within one month of handling it. Sector thresholds are set in ministerial regulations.

    What do directors have to do under the Cbw?

    The board must approve the cybersecurity measures, oversee their implementation and have enough knowledge to understand cyber risks. Executive board members of essential and important entities must complete suitable training within two years of the law entering into force. Delegating the work to a CISO does not transfer the board's responsibility.

    Is there an official NIS2 or Cbw certificate?

    No. There is no certificate that proves compliance with the Cbw. You can use frameworks such as ISO 27001, NEN 7510 or BIO 2.0 to meet the zorgplicht, and certification or an independent audit is useful evidence, but only the supervisor decides whether you comply.

    Do accountancy firms fall under NIS2 in the Netherlands?

    Not simply because they are accountancy firms. Accountancy is not one of the sectors in the Cbw annexes, so a firm is only in scope if it provides a listed service and meets the size test. Most accountancy firms feel NIS2 indirectly: clients that fall under the Cbw ask their suppliers about security as part of their supply-chain duty, and auditors may consider a client's Cbw compliance when looking at laws and regulations.

    How much does a NIS2 audit or consultancy engagement cost?

    It depends on scope: the number of entities and locations, your classification, the technology environment, current maturity, the number of critical suppliers, the audit period and how much technical testing is needed. We give a fixed-fee proposal with a defined timeline after a short scoping call.

    Expert Auditors. Faster Certification.

     

    European Operations
    European engagements are delivered through Zulon Audits OÜ, the European practice of VISTA InfoSec.
    Visit Zulon Audits →