Netherlands NIS2 — Cyberbeveiligingswet

How to Implement NIS2 Compliance in the Netherlands (Cyberbeveiligingswet) with Kordon

Kordon GRC platform is as easy to use as a spreadsheet but built for implementing frameworks like the Cyberbeveiligingswet, the Dutch law that transposes the EU NIS2 Directive into national obligations.

Implementation process

Cyberbeveiligingswet Implementation Process with Kordon

The Cyberbeveiligingswet (Cbw) entered into force on 15 August 2026, transposing the EU NIS2 Directive into Dutch law. Registration, the duty of care, and incident reporting all apply from day one — there is no grace period.

  1. 01

    Determine scope and entity classification

    Establish whether the organisation falls within an Annex I or II NIS2 sector and meets the medium/large size thresholds (broadly 50+ staff, or turnover and balance sheet above €10 million). Classify the organisation as essential (proactive supervision) or important (reactive supervision), and register with the NCSC via mijn.ncsc.nl.

  2. 02

    Documenting assets, business processes, and risks

    Map the organisation's assets, information supply chain, and business processes, and assess the associated risks — the foundation the Cyberbeveiligingswet's duty of care (zorgplicht) is built on.

  3. 03

    Implementing the duty-of-care security measures

    Design and implement the controls covering the Cbw's minimum measures: risk analysis and information security policy, incident handling, business continuity, supply chain security, secure system acquisition and maintenance, MFA and access control, cryptography, and HR security.

  4. 04

    Continuous management and incident-reporting readiness

    Run the recurring work that keeps controls effective, and be ready to meet the Cbw's incident-reporting clock: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within one month of a significant incident.

  5. 05

    Board-level accountability and regular audits

    Under the Cbw, board members are ultimately accountable for compliance and must have adequate knowledge of information security risk management. Regular internal and external audits — including RDI or sector-regulator supervision — surface gaps and improvement opportunities.

Why Kordon

Experience the Kordon GRC platform advantage

With Kordon, you're not just ticking boxes — you're building a robust security program with daily visibility into where your company stands against Cyberbeveiligingswet obligations.

Goodbye Excel chaos

Centralise scoping, risk assessment, controls, and incident-reporting readiness in one intuitive platform, eliminating scattered spreadsheets and last-minute scrambles before an RDI or sector-regulator audit.

Big picture

Get real-time insight into how your security program covers NIS2 requirements and discover the next most impactful action to strengthen your security posture.

Focus on actual security, not busywork

Free up your team's time to concentrate on strategic improvements rather than administrative tasks or chasing evidence across departments.

Time-saving automation

Reduce compliance workload by up to 80% through evidence collection and task automation — freeing up time for the incident-response readiness the Cbw actually demands.

Faster audits

As read-only users, auditors and regulators can get everything they need from the app. No more sending documents back and forth.

Proactive compliance

Shift from reactive audit preparation to continuous compliance, with automated collection of evidence supporting the duty of care and board-level reporting.

Packed with features

Everything you need to implement the Cyberbeveiligingswet

Control Management

Work with the controls you already have in place or use Kordon's templates as a starting point. Connect controls to NIS2 requirements and reduce duplication of effort across frameworks.

Risk Management

Go beyond just documenting risks and gain live insight into how well your risk management and controls are working — the core of the Cbw's duty of care. Kordon links risks to dynamic controls to effectively monitor and reduce threats.

Risk Management

Vendor Management

Supply chain security is one of the Cbw's explicit minimum measures. Track suppliers and service providers, assess their risk, and connect them to the controls and requirements they affect.

Vendor Management

Policy Management

Take control over your information security policy process from drafting and reviewing to employee acceptance. Start with one of our 20+ policy templates or bring your own.

Policy Management
Under the hood

Built for serious security teams

Automated Evidence Collection

Reduce compliance workload by up to 80% through automated task assignments and reminders, keeping evidence ready ahead of RDI or sector-regulator supervision.

Powerful API

Extend the capabilities of Kordon using the powerful API. Automate workflows further by integrating Kordon with your other systems.

Advanced Permissions

With our flexible visibility and permission system, everyone — including board members who need oversight of Cbw compliance — can see and do exactly what they need, not more, not less.

FAQ

Frequently Asked Questions

What is the Cyberbeveiligingswet and how does it relate to NIS2?
The Cyberbeveiligingswet (Cbw) is the Dutch law that transposes the EU NIS2 Directive into national legislation. It entered into force on 15 August 2026, and from that date the registration obligation, the duty of care, and incident-reporting obligations all apply — there is no general grace period. A related law, the Wet weerbaarheid kritieke entiteiten (implementing the EU's Critical Entities Resilience Directive), also entered into force the same day and covers physical and organisational resilience for critical entities.
Which organisations in the Netherlands fall under the Cyberbeveiligingswet?
Organisations operating in an Annex I or II NIS2 sector that are medium-sized or large (broadly 50+ staff, or turnover and balance sheet above €10 million) fall in scope, alongside certain high-risk entities regardless of size and all government bodies, including municipalities, provinces, and water authorities. In-scope organisations are classified as essential entities (proactive supervision) or important entities (reactive supervision) — in Annex I sectors, organisations exceeding 250 employees, €50 million turnover, or €43 million balance sheet qualify as essential.
What are the Cyberbeveiligingswet's incident-reporting deadlines?
A significant incident requires an early warning within 24 hours, a fuller incident notification within 72 hours, and a final report within one month. Kordon's task and evidence model helps teams document the incident-response steps and evidence needed to meet each deadline.
Is ISO 27001 certification sufficient to comply with the Cyberbeveiligingswet?
No. ISO 27001 certification covers a large part of the Cbw's duty of care and can be used as supporting evidence, but it is not sufficient on its own — the Cbw adds legal requirements ISO 27001 does not cover by itself, including the 24-hour reporting duty, mandatory NCSC registration, explicit supply chain obligations, and personal management liability. See more on the Framework Management page for running NIS2 alongside ISO 27001 in one connected system.
What does board-level accountability mean under the Cyberbeveiligingswet?
Board members are ultimately responsible for compliance with Cbw obligations and must have adequate knowledge and skills in information security risk management, with personal fines of up to €25,000 possible for failing this requirement. Kordon's permission system gives board members direct, read-only oversight of the organisation's security posture without adding administrative work for the team maintaining it.
How does Kordon integrate with other IT systems for a seamless Cyberbeveiligingswet implementation?
Kordon can integrate effortlessly with existing IT systems through its REST API and native integration with automation platforms like Zapier. This integration capability ensures that data flows seamlessly between Kordon and other platforms, maintaining up-to-date and accurate information across systems, including for the asset and supply-chain data the duty of care depends on.