Goodbye Excel chaos
Centralise scoping, risk assessment, controls, and incident-reporting readiness in one intuitive platform, eliminating scattered spreadsheets and last-minute scrambles before an RDI or sector-regulator audit.
Kordon GRC platform is as easy to use as a spreadsheet but built for implementing frameworks like the Cyberbeveiligingswet, the Dutch law that transposes the EU NIS2 Directive into national obligations.
The Cyberbeveiligingswet (Cbw) entered into force on 15 August 2026, transposing the EU NIS2 Directive into Dutch law. Registration, the duty of care, and incident reporting all apply from day one — there is no grace period.
Establish whether the organisation falls within an Annex I or II NIS2 sector and meets the medium/large size thresholds (broadly 50+ staff, or turnover and balance sheet above €10 million). Classify the organisation as essential (proactive supervision) or important (reactive supervision), and register with the NCSC via mijn.ncsc.nl.
Map the organisation's assets, information supply chain, and business processes, and assess the associated risks — the foundation the Cyberbeveiligingswet's duty of care (zorgplicht) is built on.
Design and implement the controls covering the Cbw's minimum measures: risk analysis and information security policy, incident handling, business continuity, supply chain security, secure system acquisition and maintenance, MFA and access control, cryptography, and HR security.
Run the recurring work that keeps controls effective, and be ready to meet the Cbw's incident-reporting clock: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within one month of a significant incident.
Under the Cbw, board members are ultimately accountable for compliance and must have adequate knowledge of information security risk management. Regular internal and external audits — including RDI or sector-regulator supervision — surface gaps and improvement opportunities.
With Kordon, you're not just ticking boxes — you're building a robust security program with daily visibility into where your company stands against Cyberbeveiligingswet obligations.
Centralise scoping, risk assessment, controls, and incident-reporting readiness in one intuitive platform, eliminating scattered spreadsheets and last-minute scrambles before an RDI or sector-regulator audit.
Get real-time insight into how your security program covers NIS2 requirements and discover the next most impactful action to strengthen your security posture.
Free up your team's time to concentrate on strategic improvements rather than administrative tasks or chasing evidence across departments.
Reduce compliance workload by up to 80% through evidence collection and task automation — freeing up time for the incident-response readiness the Cbw actually demands.
As read-only users, auditors and regulators can get everything they need from the app. No more sending documents back and forth.
Shift from reactive audit preparation to continuous compliance, with automated collection of evidence supporting the duty of care and board-level reporting.
Work with the controls you already have in place or use Kordon's templates as a starting point. Connect controls to NIS2 requirements and reduce duplication of effort across frameworks.
Go beyond just documenting risks and gain live insight into how well your risk management and controls are working — the core of the Cbw's duty of care. Kordon links risks to dynamic controls to effectively monitor and reduce threats.
Risk ManagementSupply chain security is one of the Cbw's explicit minimum measures. Track suppliers and service providers, assess their risk, and connect them to the controls and requirements they affect.
Vendor ManagementTake control over your information security policy process from drafting and reviewing to employee acceptance. Start with one of our 20+ policy templates or bring your own.
Policy ManagementReduce compliance workload by up to 80% through automated task assignments and reminders, keeping evidence ready ahead of RDI or sector-regulator supervision.
Extend the capabilities of Kordon using the powerful API. Automate workflows further by integrating Kordon with your other systems.
With our flexible visibility and permission system, everyone — including board members who need oversight of Cbw compliance — can see and do exactly what they need, not more, not less.