The Cyberbeveiligingswet is in force. Three duties, no transition period.
Since 15 August 2026, essential and important entities must register with the NCSC, meet a duty of care with ten elements, and report significant incidents within 24 hours. We set up those three duties and keep the evidence current. ISO 27001 is a voluntary standard alongside it, which we set up the same way.
The obligations, and what we take on
Four obligations from the Cyberbeveiligingswet. Each states what we deliver.
- Registration duty, Articles 43 and 44 Cbw
- Registration in the national entity register at the NCSC, using your eHerkenning. We determine applicability and prepare the registration.Source: wetten.overheid.nl
- Duty of care, Article 21 Cbw
- Ten elements, items (a) to (j). We implement each element and document it in its own file, with the date of the last test.Source: wetten.overheid.nl
- Reporting duty, Articles 25 to 29 Cbw
- Early warning within 24 hours, notification within 72 hours, final report within one month. We monitor and file the notifications on your behalf, under your responsibility.Source: wetten.overheid.nl
- Management body, Article 24 Cbw
- Approval, the knowledge requirement and final responsibility stay with the board. We prepare the approval and the training.Source: wetten.overheid.nl
Two frameworks, one delivery model
NIS2 and ISO 27001 ask for overlapping evidence of the same controls. Run them as two separate projects and you pay twice for one set of documents. CRaaS builds the evidence once and keeps it current.
Not sure which one applies to you? That is what the free check is for. Many need both.
What is known about you outside your network, every day
An audit is a snapshot. Both frameworks ask for more than that: NIS2 requires policies to assess the effectiveness of measures, and ISO 27001 makes threat intelligence a control in its own right. That is why we continuously search the dark web, criminal chat channels, ransomware leak sites, paste sites and public code repositories for what has surfaced about your organisation.
What is watched
- Leaked credentials
- Passwords and session cookies of your staff harvested by infostealer malware and traded in criminal channels, validated against your identity provider.
- Leak sites and criminal forums
- Mentions of your organisation, your domains and your suppliers on ransomware leak sites, in dark web forums and in criminal chat channels.
- Secrets in public code
- API keys, tokens and passwords that ended up by accident in public repositories, package registries or container images.
- Lookalike domains
- Newly registered domains that resemble yours, and previously flagged domains that suddenly become active.
- Exposure in the supply chain
- Known suppliers appearing in ransomware data leaks, as continuous evidence for the supplier assessment.
What we do with it
Our monitoring collects and alerts in near real time. We assess every alert, rate its severity and turn it into the action the framework requires: a password reset, revoking sessions, a notification within the deadline or a correction in the file. Every finding and every follow-up is recorded with a date, so the effectiveness review is not a once-a-year exercise but is substantiated continuously.
Where it lands in the framework
NIS2Art. 21(2)(a), (b), (d) and (f)
Risk analysis, incident handling, supply chain security and the assessment of the effectiveness of measures.
ISO 27001Annex A 5.7, 5.19 to 5.22 and 8.16
Threat intelligence, supplier relationships and monitoring activities.
What it is not
This monitoring is not a security operations centre. It looks at what has leaked about you outside your network, not at the traffic inside it. Detection in your own environment and incident response are a separate agreement.
NIS2 and ISO 27001 compared
Two frameworks that are regularly confused. One is law, the other a standard you choose. This table sets out what each one is, who it binds, and what it asks you to be able to demonstrate.
What it is
- NIS2
- EU directive, implemented in Dutch law as the Cyberbeveiligingswet (Cbw).
- ISO 27001
- A standard for an information security management system, an ISMS.
Who it applies to
- NIS2
- Essential and important entities in 18 sectors. More than 8,000 Dutch organisations.
- ISO 27001
- Any organisation, of any type or size, that chooses to adopt it.
Mandatory or voluntary
- NIS2
- Mandatory. Registration, duty of care and incident reporting, all from day one.
- ISO 27001
- Voluntary. One exception: essential entities in the government sector must apply it.
Applies since
- NIS2
- 15 August 2026, when the Cyberbeveiligingswet entered into force.
- ISO 27001
- Current edition published 25 October 2022, with a climate amendment added in 2024.
Supervisor or issuing body
- NIS2
- Sector inspectorates: RDI, ILT, DNB, AFM, IGJ, NVWA. The NCSC runs the reporting portal.
- ISO 27001
- An accredited certification body, in the Netherlands accredited by the RvA.
| Criterion | NIS2EU directive, Dutch Cbw | ISO 27001Voluntary international standard |
|---|---|---|
| What it is | EU directive, implemented in Dutch law as the Cyberbeveiligingswet (Cbw). | A standard for an information security management system, an ISMS. |
| Who it applies to | Essential and important entities in 18 sectors. More than 8,000 Dutch organisations. | Any organisation, of any type or size, that chooses to adopt it. |
| Mandatory or voluntary | Mandatory. Registration, duty of care and incident reporting, all from day one. | Voluntary. One exception: essential entities in the government sector must apply it. |
| Applies since | 15 August 2026, when the Cyberbeveiligingswet entered into force. | Current edition published 25 October 2022, with a climate amendment added in 2024. |
| Supervisor or issuing body | Sector inspectorates: RDI, ILT, DNB, AFM, IGJ, NVWA. The NCSC runs the reporting portal. | An accredited certification body, in the Netherlands accredited by the RvA. |
Position as at September 2026. The Cyberbeveiligingswet entered into force on 15 August 2026 and the sector thresholds that define a reportable incident are still being completed in ministerial regulations. Determining which framework applies to your organisation remains your own legal responsibility, and this table is a summary rather than advice.
Applicability check
Complete the form. Within 24 hours you receive, in writing: whether and how your organisation falls under the Cbw (essential or important), which supervisory authority and which CSIRT apply to your sector, and which of the three duties comes first. The RDI self-assessment remains the official test; our analysis is the explanation alongside it and the starting point for the baseline assessment. There is no charge, and a conversation follows only if you ask for one.
Applicability check