This NIS2 checklist helps you meet the requirements of the Dutch Cybersecurity Act, which has been in force since 15 August 2026. Use the points below as a starting point for recording actions, gathering evidence and embedding governance. Use the checklist as an NIS2 compliance checklist for audits, gap analyses and management reporting.
Components:- Scope & Classification
- Governance & Governance
- Risk management
- Cyber hygiene & basic measures
- Authentication & Access Management
- Encryption & Backups
- Suppliers & supply chain
- Incident response & reporting obligation
- Continuity & Recovery (BC/DR)
- Monitoring, audit & evaluation
- Awareness & Training
- Technical Measures & Network Security
- oversight, compliance & reporting
NIS2 Scope determination
Actions
- Determine whether your organisation is NIS2 (essential or important entity).
- Capture Scope: services, systems, processes and locations under NIS2.
- Provide registration/notification to the competent authority.
Evidence (Annexes)
- Scope document, list of critical processes/systems, registration files.
- Organisation profile (size, sector, chain position) and criteria supporting.
Governance & Governance
Actions
- Assign and record board-level responsibility (management body).
- Provide periodic reporting to governance on risks, KPIs and incidents.
- Provide governance of NIS2 knowledge demonstrated (training/briefing).
Evidence (Annexes)
- Board decisions, risk analyses, meeting documentation, management reviews.
- Training overviews and attendance certificates for board members.
Remarks
- NIS2 explicitly imposes responsibility on the management; Governance must be demonstrable.
Risk management
Actions
- Perform periodic risk analyses (threats, vulnerabilities, impact/probability).
- Link measures to risks (policy, technical, organisational).
- Emphasise chain and supplier risks explicitly.
Evidence (Annexes)
- Risk matrix, register of owners, evaluation reports and improvement plans.
Remarks
- Risk-based work is the basis of NIS2; follow measures from identifiable risks.
Cyber hygiene & basic measures
Actions
- Regular patch and vulnerabilities management (including justification for delay).
- Standard safe configurations, hardening and endpoint security.
- Logging and log retention for forensic analysis.
Evidence (Annexes)
- Patch overviews, CVE reports, config Baselines, AV/EDR overviews.
Remarks
- Basic hygiene prevents most incidents and reduces recovery time and costs.
Authentication & Access Management
Actions
- At least implement MFA/strong authentication for administrators and preferably for all online accessible data/sites.
- Apply least-privilege and periodic recertification of rights.
- Segment networks and separate administrative accounts/tenants.
Evidence (Annexes)
- Access policy, role/right matrix, reports, segmentation scheme.
Remarks
- Strong access management prevents malicious access and limits lateral movement and reduces the impact of potential compromise.
Encryption & Backups
Actions
- Encrypt sensitive data at rest and during transport; Manage keys securely.
- Maintenance isolated, periodically tested backups (3-2-1 line). air-gapped backups provide greater recovery opportunities.
Evidence (Annexes)
- Encryption policy, key management procedures, recovery reports, backup logs.
Suppliers & supply chain
Actions
- Perform security assessments from suppliers/service providers (pre- and periodic).
- Provide contractual security requirements, audits and incident reporting.
- Compliance Monitor (reports, independent attestations/certifications).
Evidence (Annexes)
- DPIA's where relevant, due-diligence files, contract clauses, audit reports.
Remarks
- Chain incidents are often disruptive; security requirements established in the contract and the view of compliance in the supply chain.
Incident response & reporting obligation
Actions
- Describe and test an incident response process (detection, triage, response, recovery).
- Deposit notification obligations (terms, channels, criteria) and contact points.
- Practice scenario scripts (ransomware, data breach, DDoS, vendor failure).
Evidence (Annexes)
- Incident Response Plan, schematics, incident reports etc.
Continuity & Recovery (BC/DR)
Actions
- Define RTO/RPO, emergency facilities and fallback processes for critical services.
- Regularly test for different scenarios (site failure, cloud failure, OT failure).
Evidence (Annexes)
- BC/DR plans, test reports, lessons-learning, investment decisions on redundancy.
Remarks
- Continuity is a core outcome of NIS2: faster recovery reduces business and social impact.
Monitoring, audit & evaluation
Actions
- Implement monitoring/telemetry, SIEM/SOC where appropriate, and thresholds.
- Plan internal audits and management reviews; Capture improvement actions and follow them up.
Evidence (Annexes)
- Logs, audit reports, KPI/KRI dashboards, status improvement registry.
Remarks
- Showability Showability is essential: without measuring points and reviews compliance is difficult to prove.
Awareness & Training
Actions
- Roll a continuous security awareness program from (staff and board).
- Simulate relevant threats (phishing, social engineering) with feedback and repetition.
Evidence (Annexes)
- Training calendar, content, participation registrations, simulation results and enhancement actions.
Remarks
- People remain crucial in resilience; training significantly reduces the risk of incidents.
Technical Measures & Network Security
Actions
- Apply network segmentation, firewalls, IDS/IPS, EDR and email security where appropriate.
- Management of vulnerabilities (scans, prioritisation, remedy) and security audits in accordance with policy.
Evidence (Annexes)
- Network diagrams, changelogs, scan reports, audit reports, acceptance criteria.
Remarks
- Technical controls shall be demonstrated to be compatible with risk performance and operating targets.
oversight, compliance & reporting
Actions
- Align processes to the Dutch Cybersecurity Act, applicable lower regulation and sectoral guidance.
- Prepare reporting to supervisors (formats, deadlines, responsibilities).
- Determine your route to detection (e.g. ISO 27001/ISAE/SOC as a supporting framework) and test this against your NIS2 compliance checklist.
Evidence (Annexes)
- Compliance register, mapping NIS2→controls, reporting templates, certificates/attestations.


