Standards & legislation

NIS2 and the Dutch Cybersecurity Act

NIS2 (Directive (EU) 2022/2555) obliges essential and important entities to a duty of care, incident reporting and board-level accountability for cybersecurity. In the Netherlands, NIS2 is implemented through the Cyberbeveiligingswet.

NIS2 and the Dutch Cybersecurity Act in brief

NIS2 affects far more organisations than its predecessor: from energy and healthcare to digital service providers and suppliers. The core is a duty of care (appropriate risk management measures), an obligation to report significant incidents and personal accountability of the board.

The Audirium library links the NIS2 articles to concrete controls, so you can navigate from statutory article to measure. With the free NIS2 Scanner you assess where your organisation stands in fifteen minutes.

Verified counts

Framework

27 controls

Cyberbeveiligingswet (NIS2) Control Framework 2025 (version V1.2 (2026-07-01)).

Legislation

46 articles

Richtlijn (EU) 2022/2555 - Network and Information Security Directive.

Links

48 legislation-to-control links

Direct references from statutory articles to concrete controls in the library.

Cross-references

50 links

To 28 shared controls, the bridge to other frameworks.

Library

41 frameworks

This standard does not stand alone: the library counts 1,807 controls and 2,224 cross-references.

Domains in NOREA NIS2/Cbw Control Framework

  • Verwerven, ontwikkelen en onderhouden van informatiesystemen (3)
  • Beveiliging van de toeleveringsketen (3)
  • Bedrijfscontinuïteit en crisisbeheer (3)
  • Incidentenbehandeling (2)
  • Eisen aan de training, de trainer en het certificaat en doel van de training (2)
  • Cyberhygiëne en opleidingen (2)
  • Beveiligingsaspecten t.a.v. beheer van assets (2)
  • Vroegtijdige waarschuwing (1)
  • Nadere regels over meldingen (1)
  • Meldplicht significante incidenten (1)

Get started with NIS2 and the Dutch Cybersecurity Act

Request a demo or see how NIS2 Scanner supports this standard.

Frequently asked questions

Who does NIS2 apply to?

NIS2 applies to essential and important entities in sectors such as energy, transport, healthcare, digital infrastructure, government and food, and to many of their suppliers. Medium-sized organisations (from 50 employees or 10 million euro turnover) in those sectors are also in scope.

What do I need to arrange for NIS2?

The core: a duty of care with appropriate risk management measures (from policy and incident handling to supply chain security and encryption), an obligation to report significant incidents, and demonstrable board involvement. The Dutch Cyberbeveiligingswet implements this for the Netherlands.

How do I know where my organisation stands?

With Audirium's free NIS2 Scanner you complete a self-assessment on the NIS2 themes and immediately see the biggest gaps. The underlying library links every NIS2 article to concrete controls, so the next step is clear straight away.