NIS2 self-assessment · Dutch Cybersecurity Act

Where do you stand on NIS2?

Ten questions on what the Dutch Cybersecurity Act asks of your organisation. You see your result straight away, with a next step for every open point. It takes about five minutes. We don't ask for your email address and we don't store your answers.

This self-assessment calculates your result in your own browser and needs JavaScript to do so. Turn JavaScript on and reload the page. Nothing is sent or stored.

Rather go through the questions with someone? Book a call

How to read your result

The result is a first impression based on your own answers. It is not legal advice and not an audit.

The Dutch Cybersecurity Act (Cyberbeveiligingswet), which implements NIS2, has applied since 15 August 2026. Organisations in scope have a duty of care, a duty to register and a duty to report incidents. The questions follow the ten duty-of-care measures listed by the NCSC, plus registering and reporting.

Not every question carries the same weight. The weighting is our own judgement: whatever the other measures depend on counts most.

CountsQuestions
3 ×Board, Risk assessment
2 ×Access, Second factor, Training, Incident reporting, Backups and recovery
1 ×In scope, Policy, Suppliers

If you are out of scope, the test is still useful. If you supply an organisation that is in scope, it will ask you to show the same measures.

Your answers stay in your browser. Nothing is sent or stored, and they are gone when you close the page.

Try it with your own team for 30 days

You won't need payment details. Rather talk first? Pick a time that suits you.

Try it free for 30 daysNo payment details. It stops by itself if you don’t choose to continue.
Book a call30 minutes, at a time that suits you.