
Download our NIS2 checklist!
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript

What is in the checklist (only available in Dutch)?
The checklist follows the law. Five sections, 27 questions that you answer with yes or no.
1. Registration obligation
Do you know if you are an essential or an important entity? Is your registration with the NCSC ready? And who is responsible within your organization?
2. Duty of care
Twelve questions about the measures you must take. From your risk analysis and security policy to your backups, suppliers, patch management, awareness program, and access control.
3. Reporting obligation
Can you report a serious incident within 24 hours? And do you know who does what in the 72 hours and the month that follow?
4. Management responsibility and governance
Has your management approved the measures, are they completing the mandatory training, and is cyber risk truly on the agenda?
5. Supervision and enforcement
Are your documents ready if the regulator calls tomorrow? And do you know which regulator that is?
Can't check everything off? Then you know exactly where you need to focus your efforts.
Who is this checklist for?
More than 8,000 organizations fall directly under the Cyber Security Act (Cbw). This checklist was created for that group. You are an essential entity if you operate in one of the more critical sectors. Think of energy, drinking water, healthcare, transport, and digital infrastructure. The regulator can visit you without any specific reason.
You are an important entity if you work in sectors such as postal and courier services, waste management, chemicals, food, or digital services. For you, the regulator only steps in if something happens. Do you not fall under the law yourself? Read on anyway. Your clients who do fall under it must have their entire supply chain in order. There is a good chance they will soon come knocking with questions about your security (which you will also find in our checklist). In our NIS2 Supply Chain article, you can read how to respond to that effectively.
Still not sure if you fall under the law? Then take the NIS2 quickscanfirst. In a few minutes, you will know whether you are an essential or an important entity. Still in doubt? In NIS2 for SMEs we explain the boundaries.
The obligations of the Cybersecurity Act at a glance
Do you want to know exactly what is required of you first? Below, we have outlined the five obligations.
1. Registration obligation
You register your organization with the NCSC via mijn.ncsc.nl. You can do this now, and it takes very little time. You provide details about who you are, which sector you operate in, and who the point of contact is on your behalf.
Don't wait until August to do this. It is the easiest step you can take, and it is the very first thing a regulator will look at.
2. Duty of care
The law does not mandate specific brands or products. You determine which measures suit your risks based on an up-to-date risk analysis. What the law does require is that you are able to justify your choices.
In practice, this concerns your information security policy, incident response process, backups and recovery plans, supplier agreements, patch management, encryption, access control, and multi-factor authentication for your critical systems. It also includes training, so your colleagues know what is expected of them.
Your suppliers deserve extra attention. You are responsible for the risks that enter through your supply chain. A list of names is not enough; you must assess the risks for each supplier and document agreements accordingly.
3. Reporting obligation
If you experience a significant incident, you must report it within 24 hours an initial report to the CSIRT or the NCSC. The clock starts ticking the moment you discover the incident. Within 72 hours a more detailed report follows, including an initial assessment and classification. Within one month you must submit a final report.
You will only meet these deadlines if you have pre-determined who will make the report, what information it must contain, and how someone on the work floor can report an incident to that person. Practice this once a year using a realistic scenario. That way, you will know if it actually works.
4. Management responsibility
The board approves risk mitigation measures and is personally liable for them. Board members are required to undergo cybersecurity training. Furthermore, cyber risks and incidents must be periodically added to the board's agenda, supported by a meaningful overview. This is the part that is most often underestimated. Your IT department cannot answer half of the questions in the checklist on its own.
5. Supervision and enforcement
If you are an essential entity, the regulator can audit you proactively. If you are an important entity, this happens following a report or an incident. Ensure that your policy documents, risk analyses, and incident logs are ready at all times. Appoint someone to coordinate questions from the regulator. Also, find out which regulator applies to your sector, as this varies.
What if you do not comply with the Cbw?
The fines are substantial. For essential entities, they can reach up to 10 million euros or 2% of global annual turnover. For important entities, up to 7 million euros or 1.4%. In addition, board members can be held personally liable.
Stay calm, but get started. A regulator will not immediately issue a fine to an organization that is demonstrably taking action. If you can show that you have conducted a risk analysis, planned measures, and that your board is actively involved, you have a solid case. If you have nothing in place, the risk of enforcement is significantly higher. Getting started is therefore more important than being perfect.
We explain why this law exists and what is at stake in Why NIS2 is important for organizations in the Netherlands.
How to use the NIS2 checklist
- Check it off digitally. Or print it out, whatever you prefer.
- Go through it with the right people. IT, compliance, and someone from the board. Only together can you reach an honest answer.
- Turn every checkmark into an action. Assign a name and a date to it. Then you'll have a plan ready in just fifteen minutes.
Would you like someone to take a look with you?
Even after you have checked everything off, it is smart to get a fresh perspective. Thinking you are compliant is different from being able to prove it, and the latter is what the regulator requires of you. Therefore, schedule a complimentary NIS2 check . In half an hour, we will determine together if your assessment is accurate and what still needs to be done.
Want to know more about how we guide organizations toward NIS2 compliance? Or about outsourcing your information security to a CISO as a ServiceWe would love to tell you more about it.
Frequently asked questions about the NIS2 checklist
When does the Cybersecurity Act take effect?
On August 15, 2026. There is no transition period, so your obligations apply from that day forward.
Which companies are subject to NIS2?
Organizations in eighteen designated sectors with at least 50 employees or an annual turnover exceeding 10 million euros. There are exceptions in both directions, so always check using the quick scan or the self-assessment tool provided by the national government.
What is the difference between an essential and an important entity?
Essential entities operate in the most critical sectors and are subject to proactive supervision. Important entities are subject to reactive supervision, occurring only after an incident. The obligations are largely the same; the supervision and maximum fines differ.
Is the NIS2 checklist free?
Yes. Simply provide your email address and you will receive the checklist directly in your inbox.
What are the main obligations under NIS2?
Registration, duty of care, and reporting obligations. Add to that the responsibility of the board, plus the requirement that you must be able to demonstrate everything to the regulator.
How do I report an incident?
You must make an initial report to the CSIRT or NCSC within 24 hours of discovery. A more detailed report follows within 72 hours, and the final report within a month.
Do I fall under NIS2 if I have fewer than 50 employees?
Usually not, but there are exceptions for certain digital infrastructure providers. And through your clients, you may still have to deal with the requirements.
Is ISO 27001 enough to comply with NIS2?
It saves you a tremendous amount of work and covers a large part of the duty of care. However, it does not cover everything. NIS2 also requires reporting processes, board training, and attention to your operational technology. Read here more.






















