Netherlands · Updated 28 August 2026

Dutch NIS2 × ISO 27001

Where Dutch NIS2 work fits
into ISO 27001.

The Dutch Cyberbeveiligingswet entered into force on 15 August 2026. More than 8,000 organisations across 18 sectors now face new duties covering registration, cyber-risk management, incident reporting and board oversight.

ISO/IEC 27001 does not make an organisation NIS2-compliant, but it provides much of the management structure needed to organise the work.

8,000+ organisations · 18 sectors · 10 care measures ·24-hour early warning

What changed in the Netherlands?

The Cyberbeveiligingswet, or Cbw, implements the European NIS2 Directive in Dutch law. In-scope organisations must now:

  1. Register with the NCSC.

  2. Take appropriate and proportionate cybersecurity measures.

  3. Report significant incidents within the required deadlines.

  4. Give the board responsibility for approving and overseeing those measures.

  5. Prepare for supervision and enforcement.

The law applies across sectors including energy, transport, healthcare, drinking water, digital infrastructure, public administration and certain digital services. Organisations are responsible for assessing whether they fall within scope.

Official sourceThe Dutch government’s summary of the Cyberbeveiligingswet explains the main duties and affected sectors.

ISO 27001 and NIS2 are not interchangeable

ISO/IEC 27001 is a voluntary standard for establishing and maintaining an information security management system (ISMS), whereas the Cbw imposes legal duties on organisations within its scope.

An ISO 27001 certificate will not register your organisation, submit an incident report or confirm that every Dutch requirement has been met.

ISO 27001 supports much of the Cbw duty of care by requiring an organisation to define its scope, assign responsibility, assess risks, select controls, review performance and correct weaknesses.

The NCSC itself recommends using an ISMS to manage security controls and evaluate their effectiveness. Risk management is also described as the basis of the ten Cbw duty-of-care measures.

ISO 27001 provides a management system that can support the legal duties set by the Cbw.

Where the work overlaps

The following summary groups the NCSC’s ten duty-of-care measures against relevant ISO/IEC 27001:2022 requirements. It draws on the ISO 27001 control mapping published by DataGuard and the official Dutch measures.

Risk analysis and governance

ISO starting pointClauses 4–6, 8 and 9

ISMS scope, responsibilities, risk method, risk register, treatment plan, Statement of Applicability and management reviews

Incident response

ISO starting pointAnnex A 5.24–5.28, 6.8 and 8.15–8.17

Incident plan, event classification, escalation paths, logging, evidence collection and post-incident review

Continuity, recovery and backups

ISO starting pointAnnex A 5.29–5.30 and 8.13–8.14

Business continuity plans, recovery procedures, backup rules, restore tests and crisis exercises

Supply-chain security

ISO starting pointAnnex A 5.19–5.23 and 8.30

Supplier inventory, risk assessments, security clauses, service reviews and outsourced-development controls

Secure systems and vulnerability management

ISO starting pointAnnex A 8.8–8.9, 8.20, 8.22, 8.25, 8.29 and 8.32

Vulnerability handling, patching, configuration standards, network security, secure development and change control

People, assets, access and cryptography

ISO starting pointClauses 7.2–7.3; Annex A 5.9, 5.15–5.18, 6.1–6.5, 8.2, 8.5 and 8.24

Asset inventory, access reviews, joiner and leaver processes, training, screening, MFA and encryption rules

Testing and improvement

ISO starting pointClauses 9.1–9.3 and 10.1; Annex A 5.35–5.36

Control testing, security metrics, internal audits, management review and corrective actions

This correspondence is useful, but it is not a declaration of equivalence. The organisation still has to select, adapt, operate and evidence the ISO controls according to its Cbw scope, risks and sector requirements.

What ISO 27001 does not finish

Several Cbw duties need separate treatment.

Registration and legal scope

An organisation must determine whether it is an essential or important entity and complete the required NCSC registration because ISO 27001 does not answer that legal question.

Statutory incident reporting

Significant incidents require an early warning within 24 hours, an incident notification within 72 hours and, in normal circumstances, a final report within one month. Sector-specific rules determine when an incident is considered significant.

These deadlines require a reporting procedure that connects technical detection with management, legal review and the competent Dutch authorities. ENISA provides a concise explanation of the NIS2 reporting timetable.

Board duties

The board must approve the organisation’s cybersecurity risk-management measures and oversee their implementation. Board members must also obtain and maintain enough knowledge to assess cyber risks and the measures used to manage them.

Board accountability has to be visible in decisions, approvals, training and follow-up, not just an information security policy added to the board pack.

Dutch and sector-specific requirements

The Cbw, the Cyberbeveiligingsbesluit and ministerial regulations add details that can differ by sector. Applicable thresholds, supervisory arrangements and mandatory frameworks must therefore be checked separately.

ISO certification does not replace that assessment.

Three sensible first moves

  1. Confirm scope and register.

    Identify the relevant legal entity, services, sector, size criteria and competent authority, then complete the NCSC registration if the organisation is in scope.

  2. Run one combined risk and gap assessment.

    Compare current practices against the ten Cbw duty-of-care measures and the relevant ISO 27001 clauses and controls, and record missing owners, procedures, technical measures and evidence.

  3. Test the reporting route.

    Use a short incident exercise to check who determines significance, who contacts the CSIRT and supervisor, what can be assembled within 24 and 72 hours, and who approves the submission.

A policy that has never been used is weak evidence. The same applies to an untested backup, an outdated supplier list or an access review with no recorded decisions.

The practical starting point

Build the ISO 27001 foundation first.

ClausePass27001 is built for teams that want to handle more of the ISO 27001 implementation in-house.

The toolkit provides more than 130 editable resources, practical guidance and worked examples for scope, governance, risk management, the Statement of Applicability, policies, procedures, registers, plans, evidence, internal audit and management review.

This gives your NIS2 work a defined starting point before your team adds the Cbw registration, reporting workflow and sector-specific requirements that sit outside ISO 27001.

Preview 26 pages from the toolkit

As an ISO/IEC 27001 implementation toolkit, ClausePass27001 does not provide legal advice, determine whether an organisation falls within the Cyberbeveiligingswet, guarantee compliance or replace certification and regulatory assessments.