NIS2

Download our NIS2 checklist!

Legislation
Implementation
NIS2
Verplicht

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

The Cyber Security Act comes into effect on August 15, 2026. This is the Dutch implementation of the European NIS2 directive. There is no transition period; you are responsible from day one. Use this NIS2 checklist to review all your legal obligations. By answering a few questions for each requirement, you will know exactly where you stand in just fifteen minutes. What remains is your action plan.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

This article was last updated on
30.07.2026
Written by
Ruben
Rentenaar
Marketing Specialist

What is in the checklist (only available in Dutch)?

The checklist follows the law. Five sections, 27 questions that you answer with yes or no.

 

1. Registration obligation

Do you know if you are an essential or an important entity? Is your registration with the NCSC ready? And who is responsible within your organization?

 

2. Duty of care

Twelve questions about the measures you must take. From your risk analysis and security policy to your backups, suppliers, patch management, awareness program, and access control.

 

3. Reporting obligation

Can you report a serious incident within 24 hours? And do you know who does what in the 72 hours and the month that follow?

 

4. Management responsibility and governance

Has your management approved the measures, are they completing the mandatory training, and is cyber risk truly on the agenda?

 

5. Supervision and enforcement

Are your documents ready if the regulator calls tomorrow? And do you know which regulator that is?

 

Can't check everything off? Then you know exactly where you need to focus your efforts.

Who is this checklist for?

More than 8,000 organizations fall directly under the Cyber Security Act (Cbw). This checklist was created for that group. You are an essential entity if you operate in one of the more critical sectors. Think of energy, drinking water, healthcare, transport, and digital infrastructure. The regulator can visit you without any specific reason.

 

You are an important entity if you work in sectors such as postal and courier services, waste management, chemicals, food, or digital services. For you, the regulator only steps in if something happens. Do you not fall under the law yourself? Read on anyway. Your clients who do fall under it must have their entire supply chain in order. There is a good chance they will soon come knocking with questions about your security (which you will also find in our checklist). In our NIS2 Supply Chain article, you can read how to respond to that effectively.

 

Still not sure if you fall under the law? Then take the NIS2 quickscanfirst. In a few minutes, you will know whether you are an essential or an important entity. Still in doubt? In NIS2 for SMEs we explain the boundaries.

The obligations of the Cybersecurity Act at a glance

Do you want to know exactly what is required of you first? Below, we have outlined the five obligations.

 

1. Registration obligation

You register your organization with the NCSC via mijn.ncsc.nl. You can do this now, and it takes very little time. You provide details about who you are, which sector you operate in, and who the point of contact is on your behalf.

Don't wait until August to do this. It is the easiest step you can take, and it is the very first thing a regulator will look at.

 

2. Duty of care

The law does not mandate specific brands or products. You determine which measures suit your risks based on an up-to-date risk analysis. What the law does require is that you are able to justify your choices.

 

In practice, this concerns your information security policy, incident response process, backups and recovery plans, supplier agreements, patch management, encryption, access control, and multi-factor authentication for your critical systems. It also includes training, so your colleagues know what is expected of them.

 

Your suppliers deserve extra attention. You are responsible for the risks that enter through your supply chain. A list of names is not enough; you must assess the risks for each supplier and document agreements accordingly.

 

3. Reporting obligation

If you experience a significant incident, you must report it within 24 hours an initial report to the CSIRT or the NCSC. The clock starts ticking the moment you discover the incident. Within 72 hours a more detailed report follows, including an initial assessment and classification. Within one month you must submit a final report.

 

You will only meet these deadlines if you have pre-determined who will make the report, what information it must contain, and how someone on the work floor can report an incident to that person. Practice this once a year using a realistic scenario. That way, you will know if it actually works.

 

4. Management responsibility

The board approves risk mitigation measures and is personally liable for them. Board members are required to undergo cybersecurity training. Furthermore, cyber risks and incidents must be periodically added to the board's agenda, supported by a meaningful overview. This is the part that is most often underestimated. Your IT department cannot answer half of the questions in the checklist on its own.

 

5. Supervision and enforcement

If you are an essential entity, the regulator can audit you proactively. If you are an important entity, this happens following a report or an incident. Ensure that your policy documents, risk analyses, and incident logs are ready at all times. Appoint someone to coordinate questions from the regulator. Also, find out which regulator applies to your sector, as this varies.

What if you do not comply with the Cbw?

The fines are substantial. For essential entities, they can reach up to 10 million euros or 2% of global annual turnover. For important entities, up to 7 million euros or 1.4%. In addition, board members can be held personally liable.

 

Stay calm, but get started. A regulator will not immediately issue a fine to an organization that is demonstrably taking action. If you can show that you have conducted a risk analysis, planned measures, and that your board is actively involved, you have a solid case. If you have nothing in place, the risk of enforcement is significantly higher. Getting started is therefore more important than being perfect.

 

We explain why this law exists and what is at stake in Why NIS2 is important for organizations in the Netherlands.

How to use the NIS2 checklist

 

  • Check it off digitally. Or print it out, whatever you prefer.
  • Go through it with the right people. IT, compliance, and someone from the board. Only together can you reach an honest answer.
  • Turn every checkmark into an action. Assign a name and a date to it. Then you'll have a plan ready in just fifteen minutes.

Would you like someone to take a look with you?

Even after you have checked everything off, it is smart to get a fresh perspective. Thinking you are compliant is different from being able to prove it, and the latter is what the regulator requires of you. Therefore, schedule a complimentary NIS2 check . In half an hour, we will determine together if your assessment is accurate and what still needs to be done.

Want to know more about how we guide organizations toward NIS2 compliance? Or about outsourcing your information security to a CISO as a ServiceWe would love to tell you more about it.

Frequently asked questions about the NIS2 checklist

 

When does the Cybersecurity Act take effect?

On August 15, 2026. There is no transition period, so your obligations apply from that day forward.

 

Which companies are subject to NIS2?

Organizations in eighteen designated sectors with at least 50 employees or an annual turnover exceeding 10 million euros. There are exceptions in both directions, so always check using the quick scan or the self-assessment tool provided by the national government.

 

What is the difference between an essential and an important entity?

Essential entities operate in the most critical sectors and are subject to proactive supervision. Important entities are subject to reactive supervision, occurring only after an incident. The obligations are largely the same; the supervision and maximum fines differ.

 

Is the NIS2 checklist free?

Yes. Simply provide your email address and you will receive the checklist directly in your inbox.

 

What are the main obligations under NIS2?

Registration, duty of care, and reporting obligations. Add to that the responsibility of the board, plus the requirement that you must be able to demonstrate everything to the regulator.

 

How do I report an incident?

You must make an initial report to the CSIRT or NCSC within 24 hours of discovery. A more detailed report follows within 72 hours, and the final report within a month.

 

Do I fall under NIS2 if I have fewer than 50 employees?

Usually not, but there are exceptions for certain digital infrastructure providers. And through your clients, you may still have to deal with the requirements.

 

Is ISO 27001 enough to comply with NIS2?

It saves you a tremendous amount of work and covers a large part of the duty of care. However, it does not cover everything. NIS2 also requires reporting processes, board training, and attention to your operational technology. Read here more.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

How many people participate?

Request now

Thanks!
Oops! The form could not be submitted. Please try again.

More resources

Legislation

Does the Cyber Security Act (NIS2) apply to me?

thru
Mathijs
Download
Implementation

Transition to NEN 7510:2024? Download our handy mapping

thru
Gijs
Download
News

New partnership: Fendix x Buro KLiX — Together for better care

thru
Kilian
Blog