Cyber Resilience as a Service

The Cyberbeveiligingswet is in force. Three duties, no transition period.

Since 15 August 2026, essential and important entities must register with the NCSC, meet a duty of care with ten elements, and report significant incidents within 24 hours. We set up those three duties and keep the evidence current. ISO 27001 is a voluntary standard alongside it, which we set up the same way.

Expertise
Notification duty and incident responseSupervision and enforcementAudit-ready dossiersCyber resilience

The obligations, and what we take on

Four obligations from the Cyberbeveiligingswet. Each states what we deliver.

Registration duty, Articles 43 and 44 Cbw
Registration in the national entity register at the NCSC, using your eHerkenning. We determine applicability and prepare the registration.Source: wetten.overheid.nl
Duty of care, Article 21 Cbw
Ten elements, items (a) to (j). We implement each element and document it in its own file, with the date of the last test.Source: wetten.overheid.nl
Reporting duty, Articles 25 to 29 Cbw
Early warning within 24 hours, notification within 72 hours, final report within one month. We monitor and file the notifications on your behalf, under your responsibility.Source: wetten.overheid.nl
Management body, Article 24 Cbw
Approval, the knowledge requirement and final responsibility stay with the board. We prepare the approval and the training.Source: wetten.overheid.nl

What is known about you outside your network, every day

An audit is a snapshot. Both frameworks ask for more than that: NIS2 requires policies to assess the effectiveness of measures, and ISO 27001 makes threat intelligence a control in its own right. That is why we continuously search the dark web, criminal chat channels, ransomware leak sites, paste sites and public code repositories for what has surfaced about your organisation.

What is watched

Leaked credentials
Passwords and session cookies of your staff harvested by infostealer malware and traded in criminal channels, validated against your identity provider.
Leak sites and criminal forums
Mentions of your organisation, your domains and your suppliers on ransomware leak sites, in dark web forums and in criminal chat channels.
Secrets in public code
API keys, tokens and passwords that ended up by accident in public repositories, package registries or container images.
Lookalike domains
Newly registered domains that resemble yours, and previously flagged domains that suddenly become active.
Exposure in the supply chain
Known suppliers appearing in ransomware data leaks, as continuous evidence for the supplier assessment.

What we do with it

Our monitoring collects and alerts in near real time. We assess every alert, rate its severity and turn it into the action the framework requires: a password reset, revoking sessions, a notification within the deadline or a correction in the file. Every finding and every follow-up is recorded with a date, so the effectiveness review is not a once-a-year exercise but is substantiated continuously.

Where it lands in the framework

  • NIS2Art. 21(2)(a), (b), (d) and (f)

    Risk analysis, incident handling, supply chain security and the assessment of the effectiveness of measures.

  • ISO 27001Annex A 5.7, 5.19 to 5.22 and 8.16

    Threat intelligence, supplier relationships and monitoring activities.

What it is not

This monitoring is not a security operations centre. It looks at what has leaked about you outside your network, not at the traffic inside it. Detection in your own environment and incident response are a separate agreement.

NIS2 and ISO 27001 compared

Two frameworks that are regularly confused. One is law, the other a standard you choose. This table sets out what each one is, who it binds, and what it asks you to be able to demonstrate.

  • What it is

    NIS2
    EU directive, implemented in Dutch law as the Cyberbeveiligingswet (Cbw).
    ISO 27001
    A standard for an information security management system, an ISMS.
  • Who it applies to

    NIS2
    Essential and important entities in 18 sectors. More than 8,000 Dutch organisations.
    ISO 27001
    Any organisation, of any type or size, that chooses to adopt it.
  • Mandatory or voluntary

    NIS2
    Mandatory. Registration, duty of care and incident reporting, all from day one.
    ISO 27001
    Voluntary. One exception: essential entities in the government sector must apply it.
  • Applies since

    NIS2
    15 August 2026, when the Cyberbeveiligingswet entered into force.
    ISO 27001
    Current edition published 25 October 2022, with a climate amendment added in 2024.
  • Supervisor or issuing body

    NIS2
    Sector inspectorates: RDI, ILT, DNB, AFM, IGJ, NVWA. The NCSC runs the reporting portal.
    ISO 27001
    An accredited certification body, in the Netherlands accredited by the RvA.

Position as at September 2026. The Cyberbeveiligingswet entered into force on 15 August 2026 and the sector thresholds that define a reportable incident are still being completed in ministerial regulations. Determining which framework applies to your organisation remains your own legal responsibility, and this table is a summary rather than advice.

Applicability check

Complete the form. Within 24 hours you receive, in writing: whether and how your organisation falls under the Cbw (essential or important), which supervisory authority and which CSIRT apply to your sector, and which of the three duties comes first. The RDI self-assessment remains the official test; our analysis is the explanation alongside it and the starting point for the baseline assessment. There is no charge, and a conversation follows only if you ask for one.

Applicability check