NIS2 / Cbw Compliance

NIS2 Quick Scan
Core Domains

In 10 minutes, discover where your organization stands on the 10 core domains of the NIS2 directive and the Dutch Cybersecurity Act (Cyberbeveiligingswet / Cbw). Receive an instant, clear report with priorities and recommendations.

Quick Scan Mitigation Matrix
⚠️

NIS2 / Cbw is not optional — it is an obligation

The European NIS2 directive is in force, and the Dutch Cybersecurity Act (Cyberbeveiligingswet / Cbw) — the national implementation — was adopted by the Dutch House of Representatives on 15 April 2026. The intended entry into force is 1 July 2026 (Q2 2026), subject to review by the Senate. Essential entities face fines up to €10 million or 2% of global turnover (important entities up to €7 million or 1.4%). Directors are personally liable — including fines or penalty payments for individual board members. From entry into force, the duty of care, registration obligation (via mijn.ncsc.nl) and notification obligation (24h / 72h / 1 month) apply immediately.

📋

What is this Quick Scan?

A self-assessment on the 10 core domains of the NIS2 directive (EU 2022/2555, Art. 21) and the Dutch Cybersecurity Act (Cbw). You answer 30 targeted questions and receive an instant, clear report with your compliance level, priorities and concrete recommendations — aligned to the Cbw obligations from 1 July 2026.

⏱️

How do you complete the scan?

Each domain has 3 questions. For each question, pick the answer that best fits your current situation — from "Not present" to "Fully implemented". Be honest: a realistic picture yields the most valuable recommendations. Estimated time: ±10 minutes.

💡

Extra help available

Each domain has an i button. Click it for a detailed explanation of the domain, the relevant NIS2 and Cbw articles, and — where available — a free sample document you can download as a starting point for your own policy.

NIS2 and the Cybersecurity Act state: if you are not prepared, you are responsible. Start your scan now and find out where you stand before the Cbw takes effect on 1 July 2026.

Progress 0%
0 of 0 questions answered Estimated time: 10 minutes

📊 Your NIS2 Quick Scan Result

Scores per domain

⚠️ Disclaimer

This NIS2 / Cbw Quick Scan is an indicative self-assessment and does not replace a formal audit, legal advice or official compliance review. Results are based on your own estimate and may differ from the actual situation.

The NIS2 directive (Directive (EU) 2022/2555) entered into force on 16 January 2023 and had to be transposed into national law by 17 October 2024 at the latest. The Netherlands missed this deadline. The Dutch implementation act — the Cybersecurity Act (Cyberbeveiligingswet / Cbw) — was adopted by the House of Representatives on 15 April 2026 and is now with the Senate (review starting 21 April 2026). The intended entry into force is 1 July 2026 (Q2 2026), simultaneously with the Critical Entities Resilience Act (Wwke). The Cbw replaces the current Network and Information Systems Security Act (Wbni).

For a full NIS2 and Cbw assessment, we recommend engaging a qualified cybersecurity advisor or legal specialist. SOC Continu can support you with a detailed GAP analysis and implementation guidance.

Sources: Directive (EU) 2022/2555 (NIS2), EUR-Lex, ENISA NIS2 guidance, Rijksoverheid.nl (press release 15-04-2026), Senate file 36.764 Cybersecurity Act, RDI (Dutch Digital Infrastructure Inspectorate), NCSC, NCTV.

← Cyber Threats — NIS2 Mitigation Matrix

Hover over a threat or domain to see the mitigation links