Disclaimer: This scan is an initial checklist. No rights can be derived from the checklist and/or the outcome.

This checklist is the property of Lexent. Reproduction, distribution, publication, or presentation as your own work is not permitted without prior written consent. Use for internal purposes within your own organisation is permitted.

Cyber Security NIS2 Compliance Scan

Part 1 - Applicability

Q: Are you active in one of the sectors covered by NIS2?

NIS2 applies to eighteen designated sectors, including energy, transport, healthcare, drinking water, digital infrastructure, financial services and government. If you are not directly in scope, you may still be indirectly affected: organisations in those sectors are increasingly imposing cybersecurity requirements on their suppliers and subcontractors. Supply chain pressure is therefore a real factor for non-obligated organisations as well.

This is indicative. The exact criteria are more complex.

Q: Does your organisation have more than 50 employees or an annual turnover and balance sheet total exceeding €10 million, or do you supply organisations that meet those thresholds?

Above those thresholds, you automatically fall under NIS2 as an essential or important entity. Smaller organisations are generally out of scope, but may still be designated if they fulfil a critical role in a supply chain. Public sector bodies are subject to NIS2 regardless of size. Even without a direct obligation: if your clients fall under NIS2, they will increasingly hold you accountable as a supplier for your cybersecurity posture.

This is indicative. The exact criteria are more complex.

Part 2 - Being Prepared

Q: Has your organisation registered with the competent national authority, or are you preparing for the registration obligation?

NIS2 requires essential and important entities to register with the designated national authority. In the Netherlands this is the NCSC. Voluntary registration is already possible and provides access to sector-specific threat intelligence. Organisations in other member states should check the registration requirements applicable in their jurisdiction.

Q: Do you have a documented risk assessment covering your network and information systems?

The duty of care under NIS2 requires that all measures are based on a demonstrable risk analysis. An existing ISO 27001 framework, NEN 7510 implementation or BIO implementation (in Dutch public sector) can serve as a basis, but does not fully substitute for a dedicated risk assessment.

Q: Have you implemented demonstrable measures across the ten duty-of-care areas required by NIS2?

NIS2 prescribes ten mandatory areas, including access control, encryption, backup policy, patch management, supply chain security and incident response [complete list here]. Exemption for individual areas is not possible; you must be able to demonstrate something in each area. The precise scope is risk-based and depends on your sector and size. If you process personal data, Article 32 GDPR additionally requires appropriate technical and organisational security measures, independently of NIS2. The two obligations are substantively close, but rest on different legal bases and fall under different supervisory authorities.

Q: Have you set cybersecurity requirements for your suppliers and do you monitor compliance?

Supply chain security is an explicit obligation under NIS2/Cbw. An incident at a supplier can trigger your own reporting obligation. Conversely, if your clients fall under NIS2/Cbw, they will hold you contractually accountable for your security posture as a subcontractor. This makes supply chain security relevant for virtually any organisation operating in or around designated sectors.

Q: Do you know when you are required to report a cyber incident, to whom, and within what timeframes?

Significant incidents must be reported in layers: an early warning within 24 hours, followed by a formal notification within 72 hours and a final report within one month. This regime currently applies under the Network and Information Systems Security Act (Wbni). The Cybersecurity Act (Cbw) anchors these timeframes more explicitly in statute and substantially widens the scope: where the Wbni applied only to individually designated essential service providers, the Cbw applies automatically to all essential and important entities across eighteen designated sectors.

For many organisations, the reporting obligation will be an entirely new requirement (check the Cbw list).

Where a cyber incident also involves personal data, you must report in two places: an early warning to the NCSC within 24 hours under the Wbni (future: Cbw), and a formal data breach notification to the Dutch Data Protection Authority within 72 hours under the GDPR. Both notifications carry their own threshold criteria and their own formats. A joint internal protocol prevents either one from being missed.

Q: Is your board demonstrably involved in cybersecurity decisions, and does it possess the required knowledge?

The Cbw places explicit responsibility for cyber resilience with the board. Board members must approve security measures, oversee their implementation, and maintain sufficient knowledge to make informed risk decisions. This entails a statutory obligation to acquire and keep that knowledge current. In cases of gross negligence, board members may be held personally liable, in addition to any sanctions imposed on the organisation.

Transitional note: under the current Wbni, the duty of care rests on the organisation as a whole; the board is not separately addressed and personal liability is not statutorily established. This obligation takes effect with the Cbw. A "No" answer here therefore does not represent a current breach, but a foreseeable obligation that warrants timely preparation.

Part 3 - Sector Obligations

Q: Are you a financial entity or a critical ICT provider to financial institutions?

DORA (Digital Operational Resilience Act) has been in force since January 2025 and sets additional requirements for digital operational resilience, ICT risk management, incident reporting and third-party oversight. For financial entities, DORA applies alongside NIS2. ICT providers designated as critical also fall under DORA supervision, regardless of whether they are themselves financial institutions.

Q: Are you a Dutch public sector organisation and do you apply the BIO as the basis for your duty of care?

The Baseline Informatiebeveiliging Overheid (BIO) is the designated standard for Dutch public sector organisations under the Cbw. A BIO 2.0 implementation forms the recognised basis for the duty of care within the public sector, but does not replace all NIS2 obligations. Organisations outside the Dutch public sector may skip this question.