NIS2 · Dutch Cybersecurity Act

NIS2 Scanner

On 15 August 2026 the Dutch Cybersecurity Act (Cbw) enters into force, with no transition period. The NIS2 Scanner shows you within ten minutes whether your organisation falls under it and where your largest gaps are. Free, and without having to bring in a consultant first.

15 August 2026, and no transition period

The Dutch Senate adopted the Cybersecurity Act on 7 July 2026. From 15 August the duty of care, the reporting duty and the registration duty apply immediately, to an estimated eight thousand Dutch organisations. This is what stands in their way, and what the Scanner does about it.

The law has no transition period

The obligations apply from day one, while an advisory project takes weeks. The Scanner gives you a first substantiated picture within ten minutes so you can start.

Unclear whether it applies to you

Whether you are an essential or an important entity depends on sector and size. The Scanner determines your indicative position on exactly those two inputs.

The board carries final responsibility

Approving measures, supervising implementation and following training themselves: the Act places that with the board, not with IT. The Scanner's output is written to be discussed at board level.

Many organisations have no framework yet

Most organisations in scope do not work with ISO 27001, BIO or NEN 7510. For them there is a twelve-question quick scan that assumes no existing framework.

Elsewhere you start over, despite ISO or BIO

Anyone who has already implemented ISO 27001, BIO2 or NEN 7510 does not want to start over. The Scanner derives from that existing framework what is already covered.

Coverage percentages with false precision

A hard coverage percentage suggests a precision the underlying comparison cannot deliver. The Scanner therefore shows coverage as a range, labelled indicative.

An honest first picture, not a disguised quote

The diagnosis is free and complete. Only what you do with the outcome afterwards is paid.

Diagnosis free, prescription paid

You see your gaps and all underlying links for free, after registering with a magic link. The step-by-step plan per gap, the follow-up and the management report are paid. The line is drawn up front, not halfway.

Coverage as a range

An independent validation of the crosswalk showed fixed coverage percentages came out roughly twice too high. The Scanner therefore reports a range labelled indicative, never a single hard figure.

Deterministic gap analysis

Gaps follow from validated crosswalk mappings, not from an AI estimate. For each measure it states concretely what is missing, traceable to the underlying controls.

Works with and without an existing framework

If you have ISO 27001, BIO2 or NEN 7510, the Scanner derives your coverage from it. If you have nothing yet, you start with a twelve-question quick scan.

The same control engine as the rest of the suite

The Scanner runs on the CRAFT control library. Your NIS2 picture uses the same controls and links as an ISO or BIO exercise, so the work connects up.

Data sovereignty, built in the EU

Your data sits on European servers, stored separately per organisation. No US cloud.

Five steps

From sector and size to a list of gaps you can act on, in five steps.

1

Determine your scope

Choose sector and size. You immediately see whether you are indicatively an essential entity, an important entity or out of scope.

2

Choose your starting point

If you already work with ISO 27001, BIO2 or NEN 7510, the Scanner derives your coverage from it. If not, you start with the twelve-question quick scan.

3

Work through the measures

The ten categories from article 21, worked out in the Scanner into 27 concrete measures. You can stop at any point and continue later.

4

See your gaps

For each measure it states what is concretely missing, with coverage shown as a range rather than a falsely precise percentage.

5

From gap to action

In the paid layer every gap gets a step-by-step plan with owner, deadline, status and evidence, plus a management report for the board and the regulator.

NIS2, Cbw, CER and Wwke: untangled

Four names used interchangeably, while they are different things. This is the distinction.

NIS2 (European directive)

The European directive on digital resilience. A directive has no direct effect: each member state transposes it into national law.

Cybersecurity Act (Dutch law)

The Dutch transposition of NIS2. It sets out a duty of care, a reporting duty and a registration duty for essential and important entities.

CER (European directive)

The European directive on the physical resilience of critical entities, the counterpart to NIS2 on the physical side.

Wwke (Dutch law)

The Critical Entities Resilience Act, the Dutch transposition of CER. It affects roughly 500 organisations and enters into force together with the Cbw.

What is at stake

The hard facts behind the Dutch Cybersecurity Act and the Scanner.

In force

15 August 2026

The Cbw and the Wwke enter into force together, with no transition period.

Scope

Around 8,000 organisations

This is the estimated number of Dutch organisations covered by the duty of care.

Duty of care

10 categories, 27 measures

The ten categories of article 21, worked out in the Scanner into 27 testable measures.

Without a framework

12 questions

The quick scan for organisations that do not yet have ISO 27001, BIO2 or NEN 7510.

Price

Diagnosis free

The self-assessment and your full gap picture cost nothing. Only the follow-up is paid.

For organisations that fall under the law themselves

The Scanner is built for the organisation that has to meet the duty of care, and for the people inside that organisation who are responsible for it.

Organisations in scope

Essential and important entities that must meet the duty of care, the reporting duty and the registration duty from 15 August 2026. You first determine whether it applies to you, then see where you stand.

Those who have to implement the measures

Security, IT and compliance see per measure what is concretely missing, with an outcome that can be discussed at board level. The board, after all, carries final responsibility.

The outcome is an indicative self-assessment, not a legal or formal audit opinion; that disclaimer is also included in the report. Prices for the paid layer have not been set yet: that route currently runs through contact. To see the control library the Scanner runs on, look at CRAFT.

Know within ten minutes where you stand

The scan is free and you do not need a consultant to begin. Intended for organisations that fall under the Dutch Cybersecurity Act themselves.