SAIG Academy
Self-scanProductsLog in

Free self-scan

NIS2 / Cyberbeveiligingswet Self-Scan

This free self-scan shows you in about 5 minutes where you stand in relation to the Cyberbeveiligingswet, the Dutch NIS2 implementation act, passed by the Dutch Senate on 7 July 2026 and in force from 15 August 2026. You answer 20 questions on scope, governance, risk management, suppliers, basic hygiene and the reporting obligation, and you see your result immediately. No account needed; your answers remain yours.

Scope and registration duty

Do you know whether your organisation falls under the Cyberbeveiligingswet, and are you ready for registration in the entity register?

Have you used the NIS2 Self-evaluation on regelhulpenvoorbedrijven.nl to determine whether your organisation falls under the Cyberbeveiligingswet, and whether you are an essential or important entity?

1/20Have you used the NIS2 Self-evaluation on regelhulpenvoorbedrijven.nl to determine whether your organisation falls under the Cyberbeveiligingswet, and whether you are an essential or important entity?

The Dutch government offers a free self-evaluation that determines, based on your sector, services and size, whether the act applies to you. The outcome also determines whether you fall under proactive or regular supervision.

Do you know whether your organisation meets the size criteria of the act: 50 or more FTE, or an annual turnover and balance sheet total that both exceed 10 million euros?

2/20Do you know whether your organisation meets the size criteria of the act: 50 or more FTE, or an annual turnover and balance sheet total that both exceed 10 million euros?

In the designated sectors, the Cyberbeveiligingswet applies to medium-sized and large organisations. Some types of organisations, such as DNS service providers and trust service providers, fall under it regardless of their size.

Are you registered in the entity register, or have you prepared the registration so that you can complete it as soon as the act enters into force on 15 August 2026?

3/20Are you registered in the entity register, or have you prepared the registration so that you can complete it as soon as the act enters into force on 15 August 2026?

The Cyberbeveiligingswet includes a registration duty: organisations that fall under the act must submit their details for the entity register. Registration runs via the NCSC; for the digital sector, the RDI, the Dutch Authority for Digital Infrastructure, is the supervisory authority.

Board and governance

Has your board approved the cybersecurity measures, does it oversee them, and has it been trained itself?

Has your board or management formally approved the cybersecurity risk management measures, and does it demonstrably oversee their implementation?

4/20Has your board or management formally approved the cybersecurity risk management measures, and does it demonstrably oversee their implementation?

The act places responsibility explicitly with the board: it must approve the risk management measures and oversee their implementation, and it can be held liable in the event of negligence.

Have your board members completed education or training that enables them to adequately assess cyber risks and risk management measures?

5/20Have your board members completed education or training that enables them to adequately assess cyber risks and risk management measures?

Under the act, board members are required to follow training so that they have sufficient knowledge to assess risks and measures. Employees must also be offered similar training on a periodic basis.

Are the roles and responsibilities for information security in your organisation clearly assigned and recorded in writing?

6/20Are the roles and responsibilities for information security in your organisation clearly assigned and recorded in writing?

Without assigned responsibilities, security remains a matter of good intentions. Supervisory authorities expect it to be clear who is responsible for what, from policy to incident handling.

Risk management and core processes

Are the core duty-of-care measures in place: risk analysis, incident handling, continuity and secure systems?

Do you have an up-to-date risk analysis of your network and information systems and a security policy based on it?

7/20Do you have an up-to-date risk analysis of your network and information systems and a security policy based on it?

A policy on risk analysis and information system security is the first of the ten duty-of-care measures in the act (Article 21(2) NIS2). Risk management is the foundation from which all other measures follow.

Do you have a documented process for incident handling: recognising, analysing, prioritising and resolving security incidents?

8/20Do you have a documented process for incident handling: recognising, analysing, prioritising and resolving security incidents?

Incident handling is a mandatory duty-of-care measure. It covers the entire process from first signal to closure, including learning from incidents, and it underpins the legal reporting obligation.

Have you arranged business continuity with tested backups, recovery plans and crisis management arrangements?

9/20Have you arranged business continuity with tested backups, recovery plans and crisis management arrangements?

The duty of care requires business continuity measures, such as backup management, recovery plans and crisis management. A backup that has never been restored is not a backup but a hope.

Do you safeguard the security of network and information systems during acquisition, development and maintenance, including a vulnerability management process?

10/20Do you safeguard the security of network and information systems during acquisition, development and maintenance, including a vulnerability management process?

The duty of care covers security in the acquisition, development and maintenance of systems, with the handling and disclosure of vulnerabilities as an explicit component.

Supply chain and suppliers

Do you have visibility of your supply chain security and have you arranged it contractually?

Do you have an up-to-date overview of your suppliers and service providers that have access to your systems or data, or on which your services depend?

11/20Do you have an up-to-date overview of your suppliers and service providers that have access to your systems or data, or on which your services depend?

Supply chain security is a mandatory duty-of-care measure. Without an overview of who is in your chain, you cannot manage supply chain risks.

Do you have contractual security arrangements with your critical suppliers, such as security requirements, incident notification and audit rights?

12/20Do you have contractual security arrangements with your critical suppliers, such as security requirements, incident notification and audit rights?

The act expects you to address security-related aspects in the relationship with your direct suppliers. Clients who fall under the act will impose these kinds of requirements on you as an IT service provider as well.

Do you periodically assess the security risks of your suppliers, for example based on their certifications, reports or incident history?

13/20Do you periodically assess the security risks of your suppliers, for example based on their certifications, reports or incident history?

Supply chain security is not a one-off contract clause but an ongoing process. The vulnerabilities of each supplier and the quality of their security practices belong in your risk assessment.

Basic hygiene and technology

Are training, cryptography, access management, asset management and MFA in order?

Do your employees apply basic cyber hygiene practices, and do they periodically receive education or training in cybersecurity?

14/20Do your employees apply basic cyber hygiene practices, and do they periodically receive education or training in cybersecurity?

Basic cyber hygiene practices and training together form one of the ten duty-of-care measures. Think of strong passwords, updates, recognising phishing and handling data safely.

Do you have policies and procedures for the use of cryptography and encryption, such as encryption of data traffic, storage and devices?

15/20Do you have policies and procedures for the use of cryptography and encryption, such as encryption of data traffic, storage and devices?

Policies and procedures on the use of cryptography and, where applicable, encryption are a mandatory duty-of-care measure. It is about deliberate choices: what you encrypt, with what, and how you manage keys.

Do you have personnel security, access policy and asset management in order: role-based access, a working onboarding and offboarding process, and an up-to-date overview of hardware and software?

16/20Do you have personnel security, access policy and asset management in order: role-based access, a working onboarding and offboarding process, and an up-to-date overview of hardware and software?

Security aspects relating to personnel, access policy and asset management are one of the ten duty-of-care measures. Former employees with working accounts and unknown devices are classic gaps.

Do you use multi-factor authentication on all important accounts, and secured communication tools for sensitive information?

17/20Do you use multi-factor authentication on all important accounts, and secured communication tools for sensitive information?

The use of multi-factor authentication or continuous authentication solutions and secured communications is an explicit duty-of-care measure. MFA is one of the most effective measures against account takeover.

Reporting obligation and detection

Can you detect significant incidents and report them to the NCSC, the Dutch national cyber security centre, within 24 hours, 72 hours and 1 month?

Can you detect security incidents in your systems in a timely manner, and do you retain log files that allow you to investigate an incident afterwards?

18/20Can you detect security incidents in your systems in a timely manner, and do you retain log files that allow you to investigate an incident afterwards?

Without detection and logging you cannot meet the act's reporting deadlines or reconstruct an incident. The 24-hour deadline starts as soon as you become aware of a significant incident.

Is your reporting process for significant incidents documented and rehearsed, with the legal deadlines of 24 hours (early warning), 72 hours (follow-up notification) and 1 month (final report)?

19/20Is your reporting process for significant incidents documented and rehearsed, with the legal deadlines of 24 hours (early warning), 72 hours (follow-up notification) and 1 month (final report)?

The reporting obligation has three steps: an early warning within 24 hours of becoming aware, a follow-up notification with an initial assessment within 72 hours, and a final report no later than 1 month after the notification.

Are your contact details up to date and is access to the NCSC's central reporting portal prepared, so that you can report immediately in the event of an incident?

20/20Are your contact details up to date and is access to the NCSC's central reporting portal prepared, so that you can report immediately in the event of an incident?

Reporting is done via the NCSC's central reporting portal (mijn.ncsc.nl), which forwards the report in one go to the CSIRT and the supervisory authority. During an incident you do not want to have to set up an account first.

0 of 20 questions answered