This NIS2 checklist helps you meet the requirements of the Dutch Cybersecurity Act, which has been in force since 15 August 2026. Use the points below as a starting point for recording actions, gathering evidence and embedding governance. Use the checklist as an NIS2 compliance checklist for audits, gap analyses and management reporting.

Components:
  • Scope & Classification
  • Governance & Governance
  • Risk management
  • Cyber hygiene & basic measures
  • Authentication & Access Management
  • Encryption & Backups
  • Suppliers & supply chain
  • Incident response & reporting obligation
  • Continuity & Recovery (BC/DR)
  • Monitoring, audit & evaluation
  • Awareness & Training
  • Technical Measures & Network Security
  • oversight, compliance & reporting

NIS2 Scope determination

Actions

  • Determine whether your organisation is NIS2 (essential or important entity).
  • Capture Scope: services, systems, processes and locations under NIS2.
  • Provide registration/notification to the competent authority.

Evidence (Annexes)

  • Scope document, list of critical processes/systems, registration files.
  • Organisation profile (size, sector, chain position) and criteria supporting.

Governance & Governance

Actions

  • Assign and record board-level responsibility (management body).
  • Provide periodic reporting to governance on risks, KPIs and incidents.
  • Provide governance of NIS2 knowledge demonstrated (training/briefing).

Evidence (Annexes)

  • Board decisions, risk analyses, meeting documentation, management reviews.
  • Training overviews and attendance certificates for board members.

Remarks

  • NIS2 explicitly imposes responsibility on the management; Governance must be demonstrable.

Risk management

Actions

  • Perform periodic risk analyses (threats, vulnerabilities, impact/probability).
  • Link measures to risks (policy, technical, organisational).
  • Emphasise chain and supplier risks explicitly.

Evidence (Annexes)

  • Risk matrix, register of owners, evaluation reports and improvement plans.

Remarks

  • Risk-based work is the basis of NIS2; follow measures from identifiable risks.

Cyber hygiene & basic measures

Actions

  • Regular patch and vulnerabilities management (including justification for delay).
  • Standard safe configurations, hardening and endpoint security.
  • Logging and log retention for forensic analysis.

Evidence (Annexes)

  • Patch overviews, CVE reports, config Baselines, AV/EDR overviews.

Remarks

  • Basic hygiene prevents most incidents and reduces recovery time and costs.

Authentication & Access Management

Actions

  • At least implement MFA/strong authentication for administrators and preferably for all online accessible data/sites.
  • Apply least-privilege and periodic recertification of rights.
  • Segment networks and separate administrative accounts/tenants.

Evidence (Annexes)

  • Access policy, role/right matrix, reports, segmentation scheme.

Remarks

  • Strong access management prevents malicious access and limits lateral movement and reduces the impact of potential compromise.

Encryption & Backups

Actions

  • Encrypt sensitive data at rest and during transport; Manage keys securely.
  • Maintenance isolated, periodically tested backups (3-2-1 line). air-gapped backups provide greater recovery opportunities.

Evidence (Annexes)

  • Encryption policy, key management procedures, recovery reports, backup logs.

Suppliers & supply chain

Actions

  • Perform security assessments from suppliers/service providers (pre- and periodic).
  • Provide contractual security requirements, audits and incident reporting.
  • Compliance Monitor (reports, independent attestations/certifications).

Evidence (Annexes)

  • DPIA's where relevant, due-diligence files, contract clauses, audit reports.

Remarks

  • Chain incidents are often disruptive; security requirements established in the contract and the view of compliance in the supply chain.

Incident response & reporting obligation

Actions

  • Describe and test an incident response process (detection, triage, response, recovery).
  • Deposit notification obligations (terms, channels, criteria) and contact points.
  • Practice scenario scripts (ransomware, data breach, DDoS, vendor failure).

Evidence (Annexes)

  • Incident Response Plan, schematics, incident reports etc.

Continuity & Recovery (BC/DR)

Actions

  • Define RTO/RPO, emergency facilities and fallback processes for critical services.
  • Regularly test for different scenarios (site failure, cloud failure, OT failure).

Evidence (Annexes)

  • BC/DR plans, test reports, lessons-learning, investment decisions on redundancy.

Remarks

  • Continuity is a core outcome of NIS2: faster recovery reduces business and social impact.

Monitoring, audit & evaluation

Actions

  • Implement monitoring/telemetry, SIEM/SOC where appropriate, and thresholds.
  • Plan internal audits and management reviews; Capture improvement actions and follow them up.

Evidence (Annexes)

  • Logs, audit reports, KPI/KRI dashboards, status improvement registry.

Remarks

  • Showability Showability is essential: without measuring points and reviews compliance is difficult to prove.

Awareness & Training

Actions

  • Roll a continuous security awareness program from (staff and board).
  • Simulate relevant threats (phishing, social engineering) with feedback and repetition.

Evidence (Annexes)

  • Training calendar, content, participation registrations, simulation results and enhancement actions.

Remarks

  • People remain crucial in resilience; training significantly reduces the risk of incidents.

Technical Measures & Network Security

Actions

  • Apply network segmentation, firewalls, IDS/IPS, EDR and email security where appropriate.
  • Management of vulnerabilities (scans, prioritisation, remedy) and security audits in accordance with policy.

Evidence (Annexes)

  • Network diagrams, changelogs, scan reports, audit reports, acceptance criteria.

Remarks

  • Technical controls shall be demonstrated to be compatible with risk performance and operating targets.

oversight, compliance & reporting

Actions

  • Align processes to the Dutch Cybersecurity Act, applicable lower regulation and sectoral guidance.
  • Prepare reporting to supervisors (formats, deadlines, responsibilities).
  • Determine your route to detection (e.g. ISO 27001/ISAE/SOC as a supporting framework) and test this against your NIS2 compliance checklist.

Evidence (Annexes)

  • Compliance register, mapping NIS2→controls, reporting templates, certificates/attestations.