Free self-scan
NIS2 / Cyberbeveiligingswet Self-Scan
This free self-scan shows you in about 5 minutes where you stand in relation to the Cyberbeveiligingswet, the Dutch NIS2 implementation act, passed by the Dutch Senate on 7 July 2026 and in force from 15 August 2026. You answer 20 questions on scope, governance, risk management, suppliers, basic hygiene and the reporting obligation, and you see your result immediately. No account needed; your answers remain yours.
Scope and registration duty
Do you know whether your organisation falls under the Cyberbeveiligingswet, and are you ready for registration in the entity register?
Board and governance
Has your board approved the cybersecurity measures, does it oversee them, and has it been trained itself?
Risk management and core processes
Are the core duty-of-care measures in place: risk analysis, incident handling, continuity and secure systems?
Supply chain and suppliers
Do you have visibility of your supply chain security and have you arranged it contractually?
Basic hygiene and technology
Are training, cryptography, access management, asset management and MFA in order?
Reporting obligation and detection
Can you detect significant incidents and report them to the NCSC, the Dutch national cyber security centre, within 24 hours, 72 hours and 1 month?
0 of 20 questions answered