Start with scope, not with tooling
The Dutch Cyberbeveiligingswet, the national transposition of the EU's NIS2 directive, took effect on 1 July 2026. It pulls in a much wider group of organisations than the original NIS directive did: mid-sized companies in sectors like energy, healthcare, transport, digital infrastructure, and manufacturing now carry obligations that used to apply only to critical infrastructure operators. If you haven't confirmed whether your organisation is in scope, that's the first task, not the checklist below.
This isn't legal advice. Scope determination and the exact obligations that follow from it depend on your sector and size, and that's a conversation for your legal counsel. What follows is the practical, testing-and-security side: the things a QA or security team can actually check, run, and document.
The checklist
- Risk assessment on file. A documented, current assessment of the risks to your network and information systems, not one from three years ago.
- Incident detection and response tested, not just written down. A response plan that has never been rehearsed is a document, not a capability. Run a tabletop exercise or a simulated incident and see what actually breaks.
- 72-hour reporting path confirmed. Know who in your organisation notifies the relevant authority, and how fast that decision actually gets made internally, not just on paper.
- Supply chain risk reviewed. NIS2 extends accountability to your suppliers and service providers. Know which of your vendors would put you in breach if they had an incident.
- Vulnerability management with a real cadence. Regular penetration testing and vulnerability scanning, with findings that get triaged and fixed, not filed.
- Business continuity plan that's been stress-tested. Backup and recovery procedures that have actually been restored from, at least once, recently.
- Access control and multi-factor authentication enforced. Not recommended. Enforced, and checked.
- Board-level accountability documented. Management can be held personally liable for compliance failures under NIS2. Make sure the people responsible know that, and know what they're accountable for.
Where testing fits
Most of the items above fail quietly. A backup that hasn't been restored in eighteen months looks fine until the day it doesn't work. A response plan reads well until the tabletop exercise reveals nobody knows who has authority to take a system offline. That's the gap security and resilience testing closes: it turns "we have a policy for that" into "we know it works, because we tried it."
If you're not sure where your organisation stands against this list, that's usually the sign to run an assessment before an auditor, or an incident, does it for you.