Evaluate

    NIS2 and Cyberbeveiligingswet readiness

    We establish whether NIS2 applies to you, what it requires of your organisation and of your board personally, and what closing the distance costs. In the Netherlands the Cyberbeveiligingswet has been in force since 15 August 2026 with no transition period.

    Duration

    2–4 weeks

    Built on

    NIS2 Directive · Cyberbeveiligingswet · ISO/IEC 27001:2022

    Indicative price

    €8,500–19,000 per engagement

    Who this is for

    • Board member or managing director

      Is now personally accountable, and the accountability is not delegable.

    • CISO

      Has to translate a directive into a control set and an incident clock.

    • General counsel or compliance

      Needs the in-scope determination documented before someone asks for it.

    • Supplier to an essential entity

      Is being passed the obligations through a contract.

    The law is already in force, and the clock on your board started with it

    The Cyberbeveiligingswet entered into force on 15 August 2026. There is no transition period and no grace period. Around eight thousand Dutch organisations fall within it, and a significant share of them have not yet established that they do — the directive reaches well beyond critical infrastructure into manufacturing, food production, digital providers, waste, postal services and parts of healthcare.

    For an entity in scope it means four things at once. Registration with the NCSC. A duty of care — appropriate and proportionate technical, operational and organisational measures, based on a risk assessment. An incident reporting obligation on a strict clock: an early warning within 24 hours of becoming aware of a significant incident, a notification within 72 hours, and a final report within one month. And management-body accountability: the board approves the measures and supervises their implementation.

    That last obligation is the one most boards underestimate. Management is personally answerable, with an administrative fine of up to 25,000 euros where the required knowledge and skills are absent, and board members have two years to demonstrably acquire that knowledge. For the organisation itself the exposure is up to 10 million euros or 2% of global annual turnover for essential entities, and 7 million or 1.4% for important entities.

    Scope is assessed at the level of the legal entity, not the group. This catches people out in both directions — a group that assumed one obligation may have several, and a subsidiary that assumed it was covered by the parent may be exposed on its own.

    The determination itself is not a project. It is the first hour of the assessment. What takes weeks is the duty of care, and the fastest route through it is ISO/IEC 27001, because it produces the risk process, the control set and the evidence the law expects, in a form your clients also recognise.

    How we do it

    1. 01

      In-scope determination

      1 day

      Sector, size and entity structure tested against the criteria, per legal entity. The output is a written memo — because the question will be asked again, by a regulator, an insurer or a client, and you want the reasoning on file.

    2. 02

      Registration support

      1–2 days

      The NCSC registration, the information it requires, and the eHerkenning access needed to complete it.

    3. 03

      Duty of care assessment

      1–2 weeks

      Your current measures against what the law expects, using ISO/IEC 27001 as the control framework because it is the one the supervisory authorities recognise. Findings with effort and cost attached.

    4. 04

      Incident reporting readiness

      3–5 days

      The 24-hour, 72-hour and one-month obligations turned into a playbook with named roles and decision thresholds — then tested in a tabletop, because 24 hours is short when nobody knows who calls.

    5. 05

      Board accountability briefing

      half a day

      What the management body is now answerable for, what approving the measures actually means, and how the knowledge requirement is evidenced. Held as a working session, with an attendance record.

    6. 06

      Costed roadmap

      3–5 days

      Sequenced, owned, and priced — separating what must be done now from what can follow.

    Named artefacts

    What you receive

    • In-scope determination memo per legal entity, with the reasoning
    • Essential or important entity classification, and what follows from it
    • NCSC registration checklist and support through submission
    • Duty of care gap assessment against ISO/IEC 27001 controls
    • Incident reporting playbook with the 24 / 72 hour and one month clock, roles and thresholds
    • Tabletop exercise report
    • Board accountability briefing, with attendance evidence for the knowledge requirement
    • Costed and sequenced remediation roadmap

    What we need from you

    • Your legal entity structure, turnover and headcount per entity. Scope turns on these.
    • The board, for half a day. This is the one session that cannot be delegated to IT.
    • Existing security documentation, incident records and supplier contracts.
    • Clarity on which entity signs what, because the obligations attach to the entity.

    What changes

    1. 01You know which of your entities are in scope, and you can show your reasoning.
    2. 02You are registered, and you know what you registered as.
    3. 03Your incident process meets the 24-hour clock because it has been rehearsed, not merely written.
    4. 04Your board can evidence the knowledge requirement rather than assert it.
    5. 05One control set answers NIS2, your ISO/IEC 27001 programme and your clients' questionnaires.

    What it costs

    €8,500–19,000 per engagement

    All prices exclude VAT.

    Questions

    How do we know if we are in scope?

    It turns on your sector, your size and the transposition in the member state where the entity is established — and it is assessed per legal entity, not per group. That determination is the first hour of the assessment, not a project in itself, and we give it to you in writing.

    We are a supplier to an essential entity. Does it reach us?

    Often, by contract rather than by law. NIS2 obliges in-scope entities to manage supply chain security, which they do by passing requirements down. You may not be directly regulated and still be contractually held to much of the same standard.

    Does ISO/IEC 27001 certification make us compliant?

    No — certification is not compliance, and the law does not mention the standard. But it builds most of what the duty of care requires, in a form supervisory authorities recognise, so it is usually the cheapest route. The obligations the certificate does not cover are registration, incident reporting and board accountability.

    What is the real exposure for our directors?

    Management bodies must approve the cybersecurity measures and supervise their implementation, and must have adequate knowledge to do so. An administrative fine of up to 25,000 euros applies to board members where that knowledge is absent, with two years to acquire it. Organisational fines reach 10 million euros or 2% of global turnover for essential entities.

    Leave with your top three risks documented

    Thirty minutes with a senior practitioner. No slideware, no sales engineer.