NIS2 Quickscan
Compact understanding of applicability, key obligations and logical follow-up.
View the NIS2 Quickscan →
NIS2 and the Dutch Cybersecurity Act
Bring together applicability, board-level responsibility, duty of care, reporting obligations and chain risks in one feasible approach. This overview combines explanation, research, implementation and independent review.
Translate liabilities into control
The Dutch Cybersecurity Act has been in force since 15 August 2026 and forms the Dutch elaboration of NIS2. Organisations governed by the law are faced with registration, risk management, incident reporting and explicit management responsibility. A useful approach starts with the right scope and then makes it clear which measures have been chosen, implemented and tested.
NIS2 services
The correct route depends on the certainty you need: an initial indication, a substantiated difference, assistance in carrying out or independent review of the operation.
Compact understanding of applicability, key obligations and logical follow-up.
View the NIS2 Quickscan →Actual assessment of obligations, existing control, missing evidence and improvement priorities.
View the NIS2 GAP analysis →Evidence-based research into the demonstrable effect of agreed NIS2 measures.
View the NIS2 audit →Guidance in governance, measures, ownership, proof and board-level reporting.
View advice and implementation →Research into scenarios, impact, existing control and board-level risk choices.
View the risk analysis →Focused training on responsibility, decision-making, oversight and demonstrable follow-up.
Check out the NIS2 training →From initial overview to demonstrable operation
Map legal entities, activities, size, sector and critical chain relationships.
Examine the relevant digital risks and the evidence supporting the current measures.
Link actions to risk, owner, time limit, means and proof that arises during execution.
Review periodically whether measures work and translate findings into decisions, residual risk and follow-up.
Connecting Governance and Implementation
Board members should approve cyber risk management measures and monitor implementation. IT, process owners, supplier board members and the management team each provide a part of the control. Clear responsibilities and useful evidence connect those roles.
7 articles
Practical explanation about obligations, governance, chain risks, digital resilience and oversight.
Official source
The precise applicability depends on, inter alia, sector, size, legal entity and possible designation. Use current public sector information and have a concrete situation legally assessed when there is uncertainty.
View the current information of the NCTV →Put your problem, your current approach and your desired security. Then we determine which research or implementation route fits.
Schedule an introductory call →Frequently Asked Questions
No. Applicability depends, inter alia, on sector, activities, size, legal entity and special designation grounds. Organisations must be careful about this themselves.
The Quickscan gives compact an initial indication. A GAP analysis will examine obligations, existing control and evidence more systematically and will provide a substantiated improvement plan.
ISO 27001 can provide a strong management framework, but does not automatically prove that all legal obligations for your organisation have been fulfilled. A targeted mapping and assessment will remain necessary.
The board must approve cyber risk management measures, oversee their implementation and have sufficient knowledge to assess risks and measures.

NIS2 becomes manageable when obligations are linked to concrete risks, ownership, execution and proof operation.