NIS2 Scanner
On 15 August 2026 the Dutch Cybersecurity Act (Cbw) enters into force, with no transition period. The NIS2 Scanner shows you within ten minutes whether your organisation falls under it and where your largest gaps are. Free, and without having to bring in a consultant first.
The challenge
15 August 2026, and no transition period
The Dutch Senate adopted the Cybersecurity Act on 7 July 2026. From 15 August the duty of care, the reporting duty and the registration duty apply immediately, to an estimated eight thousand Dutch organisations. This is what stands in their way, and what the Scanner does about it.
The law has no transition period
The obligations apply from day one, while an advisory project takes weeks. The Scanner gives you a first substantiated picture within ten minutes so you can start.
Unclear whether it applies to you
Whether you are an essential or an important entity depends on sector and size. The Scanner determines your indicative position on exactly those two inputs.
The board carries final responsibility
Approving measures, supervising implementation and following training themselves: the Act places that with the board, not with IT. The Scanner's output is written to be discussed at board level.
Many organisations have no framework yet
Most organisations in scope do not work with ISO 27001, BIO or NEN 7510. For them there is a twelve-question quick scan that assumes no existing framework.
Elsewhere you start over, despite ISO or BIO
Anyone who has already implemented ISO 27001, BIO2 or NEN 7510 does not want to start over. The Scanner derives from that existing framework what is already covered.
Coverage percentages with false precision
A hard coverage percentage suggests a precision the underlying comparison cannot deliver. The Scanner therefore shows coverage as a range, labelled indicative.
What the Scanner offers
An honest first picture, not a disguised quote
The diagnosis is free and complete. Only what you do with the outcome afterwards is paid.
Diagnosis free, prescription paid
You see your gaps and all underlying links for free, after registering with a magic link. The step-by-step plan per gap, the follow-up and the management report are paid. The line is drawn up front, not halfway.
Coverage as a range
An independent validation of the crosswalk showed fixed coverage percentages came out roughly twice too high. The Scanner therefore reports a range labelled indicative, never a single hard figure.
Deterministic gap analysis
Gaps follow from validated crosswalk mappings, not from an AI estimate. For each measure it states concretely what is missing, traceable to the underlying controls.
Works with and without an existing framework
If you have ISO 27001, BIO2 or NEN 7510, the Scanner derives your coverage from it. If you have nothing yet, you start with a twelve-question quick scan.
The same control engine as the rest of the suite
The Scanner runs on the CRAFT control library. Your NIS2 picture uses the same controls and links as an ISO or BIO exercise, so the work connects up.
Data sovereignty, built in the EU
Your data sits on European servers, stored separately per organisation. No US cloud.
How it works
Five steps
From sector and size to a list of gaps you can act on, in five steps.
Determine your scope
Choose sector and size. You immediately see whether you are indicatively an essential entity, an important entity or out of scope.
Choose your starting point
If you already work with ISO 27001, BIO2 or NEN 7510, the Scanner derives your coverage from it. If not, you start with the twelve-question quick scan.
Work through the measures
The ten categories from article 21, worked out in the Scanner into 27 concrete measures. You can stop at any point and continue later.
See your gaps
For each measure it states what is concretely missing, with coverage shown as a range rather than a falsely precise percentage.
From gap to action
In the paid layer every gap gets a step-by-step plan with owner, deadline, status and evidence, plus a management report for the board and the regulator.
The law in brief
NIS2, Cbw, CER and Wwke: untangled
Four names used interchangeably, while they are different things. This is the distinction.
NIS2 (European directive)
The European directive on digital resilience. A directive has no direct effect: each member state transposes it into national law.
Cybersecurity Act (Dutch law)
The Dutch transposition of NIS2. It sets out a duty of care, a reporting duty and a registration duty for essential and important entities.
CER (European directive)
The European directive on the physical resilience of critical entities, the counterpart to NIS2 on the physical side.
Wwke (Dutch law)
The Critical Entities Resilience Act, the Dutch transposition of CER. It affects roughly 500 organisations and enters into force together with the Cbw.
In figures
What is at stake
The hard facts behind the Dutch Cybersecurity Act and the Scanner.
15 August 2026
The Cbw and the Wwke enter into force together, with no transition period.
Around 8,000 organisations
This is the estimated number of Dutch organisations covered by the duty of care.
10 categories, 27 measures
The ten categories of article 21, worked out in the Scanner into 27 testable measures.
12 questions
The quick scan for organisations that do not yet have ISO 27001, BIO2 or NEN 7510.
Diagnosis free
The self-assessment and your full gap picture cost nothing. Only the follow-up is paid.
Who it is for
For organisations that fall under the law themselves
The Scanner is built for the organisation that has to meet the duty of care, and for the people inside that organisation who are responsible for it.
Organisations in scope
Essential and important entities that must meet the duty of care, the reporting duty and the registration duty from 15 August 2026. You first determine whether it applies to you, then see where you stand.
Those who have to implement the measures
Security, IT and compliance see per measure what is concretely missing, with an outcome that can be discussed at board level. The board, after all, carries final responsibility.
The outcome is an indicative self-assessment, not a legal or formal audit opinion; that disclaimer is also included in the report. Prices for the paid layer have not been set yet: that route currently runs through contact. To see the control library the Scanner runs on, look at CRAFT.
Know within ten minutes where you stand
The scan is free and you do not need a consultant to begin. Intended for organisations that fall under the Dutch Cybersecurity Act themselves.