19 DAYS UNTIL CBW IN FORCE

Test it before
the regulator does.

The Cyberbeveiligingswet takes effect 15 August 2026. If your organisation is in NIS2 scope, the gap between where you are and where you need to be is your risk to carry. We help you find it, document it, and close it, before an auditor or attacker does it for you.

scope

Are you in scope?

The Dutch Cyberbeveiligingswet (Cbw) implements NIS2. It covers two categories of entity. If your organisation fits either profile, compliance is not optional.

Essential entities

Essential sectors

Energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, and space.

250+ employees OR €50M+ turnover / €43M+ balance sheet
Important entities

Important sectors

Postal services, waste management, chemicals, food, manufacturing, digital providers (search engines, online marketplaces, cloud), and research organisations.

50–249 employees OR €10M–€50M turnover
Supply chain

Supplier obligations

Article 21(2)(d) requires in-scope entities to impose security requirements on their suppliers. If you supply to a NIS2-obligated organisation, expect security clauses in your contracts.

No size threshold — contractual obligation from client
Municipalities

All 380 Dutch gemeenten

All Dutch municipalities fall within NIS2 scope under the public administration sector. Compliance is mandatory regardless of size.

All 380 municipalities — no threshold applies
Not sure if you're in scope? When in doubt, assume yes. The penalties for non-compliance reach up to 2% of annual global turnover for essential entities, making conservative scoping the financially rational choice.

article 21

What compliance actually requires

Article 21 defines ten mandatory security measures. Each one needs evidence, not just a policy document, but proof that the measure is operational.

21.2a
Risk management policies: Documented risk analysis covering all relevant threat vectors, reviewed at least annually.
21.2b
Incident handling: Documented response plan with NCSC reporting chain: early warning 24h, formal notification 72h, full report 1 month.
21.2c
Business continuity: Tested BCP with defined RTO/RPO targets. Backup and recovery procedures documented and verified.
21.2d
Supply chain security: Supplier security requirements documented. Security clauses in contracts. Supplier incident notification obligations.
21.2e
Vulnerability management: Documented patch management with severity SLAs. Regular scanning. Periodic penetration testing.
21.2f
Effectiveness assessment: Evidence that controls are working, not just described. Auditable records of testing, remediation, and review cycles.
21.2g
Cyber hygiene & training: Annual security awareness training for all staff. Documented attendance records. Hygiene baseline enforced.
21.2h
Cryptography policy: Encryption requirements for data at rest and in transit. Key management procedures defined and documented.
21.2i
Access control & asset management: Complete asset register including SaaS and cloud. Formal access policy with onboarding and offboarding procedures.
21.2j
Multi-factor authentication: MFA enforced across all systems. Verification evidence per user. No exceptions without documented risk acceptance.

how we help

How we support your compliance effort

Article 21 requires proof that your controls work, not a policy that says they should. Our penetration testing produces that proof, mapped to the ten obligations your auditor will check.

PEN TESTING · EXTERNAL

External & Web Application Testing

Where an attacker gets a first foothold

  • Internet-facing infrastructure, VPNs, and remote access points
  • Web applications and APIs, tested by OSCP and OSWE certified specialists
  • CVSS-scored findings, prioritised by business impact
  • A full retest once fixes are in place
PEN TESTING · INTERNAL

Internal Network & Infrastructure

What happens once the perimeter gives way

  • Lateral movement and privilege escalation testing
  • Active Directory and network segmentation review
  • Evidence for Article 21.2e (vulnerability management) and 21.2i (access control)
  • Findings written for your IT team and your management board
PEN TESTING · REPORTING

Article 21 Evidence Pack

Proof your controls were actually tested

  • Findings mapped to the ten Article 21.2 requirements
  • RAG status per area, so gaps are visible immediately
  • Plain-language reporting your board can sign off on
  • A record you can hand to an auditor or the NCSC

why us

Why a testing firm for NIS2?

NIS2 is a testing problem

Article 21 does not just require policies to exist: they must be tested and evidenced. Penetration testing, incident response exercises, MFA verification: these are testing deliverables, not legal documents. That is exactly what we do.

We work inside your team

We do not arrive with a 200-page framework and leave. Senior specialists join your process, work in your tools, and produce evidence that is specific to your actual systems, not generic templates with your logo on them.

Plain language throughout

Every gap assessment report, every evidence checklist, every recommendation is written so your management team can understand and act on it, not just your IT team. That matters when board sign-off is required.

15 years of security testing

Application pen testing, vulnerability management, and compliance testing have been part of our offering since 2019. NIS2 is a natural extension of work we already do for enterprise clients across the Netherlands.

spriteCloud NIS2 Gap Assessment — excerpt
# Article 21 Status — Example Organisation
# spriteCloud Readiness Scan v1.0

ASSESSMENT RESULTS
21.2a  risk_policies      AMBER
21.2b  incident_handling  AMBER
21.2c  business_continuity GREEN
21.2d  supply_chain       AMBER
21.2e  vulnerability_mgmt AMBER
21.2f  effectiveness      AMBER
21.2g  cyber_hygiene      GREEN
21.2h  cryptography       AMBER
21.2i  access_control     GREEN
21.2j  mfa_enforcement    AMBER

# Summary
GREEN  3/10 areas
AMBER  7/10 areas: remediation required

# Recommended next step
service   Compliance Sprint
duration  3 weeks
est_cost  €12,000 – €15,000

contact

Not sure where to start?
That's what the first call is for.

A 30-minute discovery call is free. We ask about your sector, your current security posture, and your timeline. You leave with a clear picture of what engagement makes sense and what it will cost, with no obligation.