NIS2 and the Dutch Cybersecurity Act

NIS2 and the Dutch Cybersecurity Act: what should your organisation arrange?

Bring together applicability, board-level responsibility, duty of care, reporting obligations and chain risks in one feasible approach. This overview combines explanation, research, implementation and independent review.

Translate liabilities into control

What do NIS2 and the Dutch Cybersecurity Act of your organisation require?

The Dutch Cybersecurity Act has been in force since 15 August 2026 and forms the Dutch elaboration of NIS2. Organisations governed by the law are faced with registration, risk management, incident reporting and explicit management responsibility. A useful approach starts with the right scope and then makes it clear which measures have been chosen, implemented and tested.

NIS2 services

Choose the approach that suits your decision question

The correct route depends on the certainty you need: an initial indication, a substantiated difference, assistance in carrying out or independent review of the operation.

Initial indication

NIS2 Quickscan

Compact understanding of applicability, key obligations and logical follow-up.

View the NIS2 Quickscan
Difference

NIS2 GAP Analysis

Actual assessment of obligations, existing control, missing evidence and improvement priorities.

View the NIS2 GAP analysis
Independent tests

NIS2 audit

Evidence-based research into the demonstrable effect of agreed NIS2 measures.

View the NIS2 audit
Risk-driven

Information security risk assessment

Research into scenarios, impact, existing control and board-level risk choices.

View the risk analysis
Boards and supervisory boards

NIS2 training

Focused training on responsibility, decision-making, oversight and demonstrable follow-up.

Check out the NIS2 training

From initial overview to demonstrable operation

From applicability to demonstrable control

  1. 01

    Determine applicability and chain position

    Map legal entities, activities, size, sector and critical chain relationships.

  2. 02

    Assess risks and existing control

    Examine the relevant digital risks and the evidence supporting the current measures.

  3. 03

    Prioritize and perform improvements

    Link actions to risk, owner, time limit, means and proof that arises during execution.

  4. 04

    Test effectiveness and report to the board

    Review periodically whether measures work and translate findings into decisions, residual risk and follow-up.

Connecting Governance and Implementation

NIS2 is an board-level task with both technical and organisational implementation

Board members should approve cyber risk management measures and monitor implementation. IT, process owners, supplier board members and the management team each provide a part of the control. Clear responsibilities and useful evidence connect those roles.

7 articles

NIS2 and the Dutch Cybersecurity Act

Practical explanation about obligations, governance, chain risks, digital resilience and oversight.

Official source

Check applicability and obligations at source

The precise applicability depends on, inter alia, sector, size, legal entity and possible designation. Use current public sector information and have a concrete situation legally assessed when there is uncertainty.

View the current information of the NCTV
NIS2 in your organisationDiscuss where your organisation is with NIS2

Put your problem, your current approach and your desired security. Then we determine which research or implementation route fits.

Schedule an introductory call

Frequently Asked Questions

Practical answers on NIS2 and the Dutch Cybersecurity Act

Does every organisation fall under the Dutch Cybersecurity Act?

No. Applicability depends, inter alia, on sector, activities, size, legal entity and special designation grounds. Organisations must be careful about this themselves.

What is the difference between a NIS2 Quickscan and GAP analysis?

The Quickscan gives compact an initial indication. A GAP analysis will examine obligations, existing control and evidence more systematically and will provide a substantiated improvement plan.

Is ISO 27001 certification sufficient for NIS2?

ISO 27001 can provide a strong management framework, but does not automatically prove that all legal obligations for your organisation have been fulfilled. A targeted mapping and assessment will remain necessary.

What role does the board play in NIS2?

The board must approve cyber risk management measures, oversee their implementation and have sufficient knowledge to assess risks and measures.

Wouter Parent

NIS2 becomes manageable when obligations are linked to concrete risks, ownership, execution and proof operation.

Current
WebinarFree webinars on NIS2, cyber risk management and oversight

Choose a live session for the board, executive team, supervisory board or board of trustees and register directly.

View webinars and dates