NIS2 self-assessment · Dutch Cybersecurity Act
Where do you stand on NIS2?
Ten questions on what the Dutch Cybersecurity Act asks of your organisation. You see your result straight away, with a next step for every open point. It takes about five minutes. We don't ask for your email address and we don't store your answers.
This self-assessment calculates your result in your own browser and needs JavaScript to do so. Turn JavaScript on and reload the page. Nothing is sent or stored.
Rather go through the questions with someone? Book a callYour result
out of 100
Partly in placeOpenIn scope
Check on ncsc.nl/NIS2 whether your organisation is in scope. If it is, register it through mijn.ncsc.nl.
Partly in placeOpenBoard
Have your board formally approve the measures, agree how often it reviews progress, and schedule training for the directors.
Partly in placeOpenRisk assessment
List your most important systems and data. For each risk, write down who owns it, how serious it is and what you do about it.
RiskCompass is a risk register for exactly this: an owner, an assessment and a plan per risk. Explore RiskCompass
Partly in placeOpenPolicy
Write a policy of a few pages: what you protect, who is responsible for what and which encryption you use. Have your board approve it.
Partly in placeOpenAccess
List every account with administrator rights and check each quarter whether everyone on that list still needs them.
Do you run a Windows network with Active Directory? The Active Directory assessment shows which accounts and rights an attacker could abuse. It says nothing about other systems. See how the assessment works
Partly in placeOpenSecond factor
Turn on a second factor for email and for administrator accounts. Start with the accounts that have the most rights.
Partly in placeOpenTraining
Schedule training for everyone on phishing, passwords and reporting incidents, and keep track of who has completed what.
Awareness trains your employees and shows per person which training is complete. It covers this point, not the other nine. Explore Awareness
Partly in placeOpenIncident reporting
Write down on one page who does what during an incident, who decides and who reports. Practise it once with your board.
Partly in placeOpenBackups and recovery
Keep one backup separate from your network. Restore one system this month as an exercise and write down how long it took.
Partly in placeOpenSuppliers
List the suppliers with access to your systems or data. Ask the most important ones how they handle security and record their answers.
This is a first impression based on your own answers, not legal advice. Whether and how the Act applies to your organisation depends on your sector and size.
How to read your result
The result is a first impression based on your own answers. It is not legal advice and not an audit.
Sources (in Dutch)
- NCSC, Infosheet Cyberbeveiligingswet: Zorgplicht, version September 2025.
- NCSC, Meld incidenten onder de Cyberbeveiligingswet (meldplicht).
- KvK, Cyberbeveiligingswet: zorg dat je er klaar voor bent.
Consulted on 6 October 2026.
The Dutch Cybersecurity Act (Cyberbeveiligingswet), which implements NIS2, has applied since 15 August 2026. Organisations in scope have a duty of care, a duty to register and a duty to report incidents. The questions follow the ten duty-of-care measures listed by the NCSC, plus registering and reporting.
Not every question carries the same weight. The weighting is our own judgement: whatever the other measures depend on counts most.
| Counts | Questions |
|---|---|
| 3 × | Board, Risk assessment |
| 2 × | Access, Second factor, Training, Incident reporting, Backups and recovery |
| 1 × | In scope, Policy, Suppliers |
If you are out of scope, the test is still useful. If you supply an organisation that is in scope, it will ask you to show the same measures.
Your answers stay in your browser. Nothing is sent or stored, and they are gone when you close the page.
Try it with your own team for 30 days
You won't need payment details. Rather talk first? Pick a time that suits you.