• Jump to main content
  • Jump to main navigation
  • Jump to widget bar
  • Jump to footer
  • Newsletter
  • About us
  • Contact
  • Nederlands

Digital Government

For Caribbean and international professionals working on government digitalisation

Logo Rijksoverheid, to the homepage

Digital Government

  • Home
  • Topics
  • All News
  • Caribbean News
Home›Topics›NIS2 Directive (Cyberbeveiligingswet, Cbw)›Tooling for the Cyberbeveiligingswet

Tooling for the Cyberbeveiligingswet

Under the Cyberbeveiligingswet (Cbw), the public sector is considered a separate entity. Are you looking to prepare your public sector organisation for the implementation of the Cyberbeveiligingswet? Or do you work in a different sector, and would you like to check whether this law applies to your organisation? Browse the guidance and tools provided below.

(How) does the Cbw affect you organisation?

  • NIS2 Self-Assessment NL (Dutch): Is the NIS2 directive applicable to your organisation? Is your organisation Essential or Important? Does it fall under Dutch supervision?
  • Overview page Cyberbeveiligingswet (Dutch): Includes a decision tree (doorverwijsboom), checklists and information sheets.

Prepare your organisation

  • Getting started – where to begin? (Dutch): An NCSC overview of tools, pages, and resources to help prepare for the Cyberbeveiligingswet.
  • Cbw (NIS2) Control Framework (Dutch): Helps organisations assess their compliance with the Cyberbeveiligingswet and the underlying Cyberbeveiligingsbesluit. Developed in collaboration with the Audit Service of the Kingdom (ADR) and the Dutch IT Auditors Association (NOREA).
  • Mapping: Created with experts to clarify which NIS2 measures are mandatory, optional, or situational, and how they relate to NEN-EN-ISO/IEC 27002 and the current BIO.
  • ICO-wizard (Dutch): Select requirement packages tailored to different types of products and/or services to be procured. The wizard includes privacy requirements and standards from the Police Data Act (WPG).
  • Basisbeveiliging.nl (English and Dutch) shows whether key organisations have their digital baseline security in order. Essential for the availability, integrity, and confidentiality of online services.
  • Risk management for digital resilience of cross-departmental chains (Dutch): 3 supporting documents:
    • Policy on risk management for digital resilience of cross-departmental chains.
    • Guidance on risk management for digital resilience of cross-departmental chains
    • Implementation framework for risk management of cross-departmental chains.
  • Various tools and services provided by the Centre for Information Security and Privacy Protection (CIP) (Dutch).
  • Government Internet Domain Policy 1.0 (Dutch): One of the obligations under the Cbw is the registration of all internet domains for which an organisation is responsible. At the start of 2026, the Dutch central government established its internet domain policy, outlining the requirements for government internet domains. Other government bodies may also adopt this policy.
  • Guidance on Risk Management in Operational Technology (OT) (Dutch): A practical approach to risk management in Operational Technology to identify and reduce cybersecurity risks to an acceptable level. The document also includes frameworks with international case studies, practical examples, tips, and key considerations.
  • Securing the Supply Chain – Good Practices (Dutch): How to approach supply chain security in practice? 6 CISOs and ISOs share their experiences.
  • PQC Migration Handbook (2024)
  • Make your organisation quantum safe (Dutch) (2023)
  • Develop AI systems securely (Dutch) (2023)
  • Enhanced Threats in a World of Artificial Intelligence (Dutch) – An analysis of AI’s impact on national security (2024)
  • Generative AI: A Transformative Impact on Cybersecurity (Dutch) (2024)
  • How to create a defendable network? (Dutch) (2024)
  • Cybercheck: Supply Chain Risks Affect You Too! (Dutch)
  • BIO-Self Assessment (BIO-SA) (Dutch): A tool to help you gradually comply with BIO2.
  • BIO practices (Dutch): Practical guides and tools to support the implementation and use of BIO2.
  • BIO Thematic Elaborations (Dutch): Guidance for implementing and applying BIO2 in government organisations.
  • Guidance ‘The Administrator’s Role’ (Dutch): Administrators are ultimately responsible for information security, determining risk appetite, and accepting residual risk. This guide provides a practical framework for fulfilling this responsibility.
  • ​​Podcast series on BIO2 (Dutch).

Guidance for adminstrators

Cybersecurity guidance for directors and business owners: For administrators, business owners, and members of supervisory boards in all organisations.

Practicing and testing

  • Test your website: Check whether a website supports modern internet standards.
  • Red Teaming Toolkit (Dutch): A red teaming test is an advanced security assessment that simulates a cyberattack on one or more critical functions of an organisation, based on real-world threats. The findings can be used to develop improvement plans to enhance the organisation’s digital resilience.

Knowledge and proficiency

  • BIO2 Factsheet Information Security and the Line Manager (Dutch)
  • Conversation cards to help municipal secretaries with basic knowledge and asking the right questions (Dutch)
  • Factsheet for Councillors (Dutch): Designed to guide councillors on digital security matters.

In addition: operational knowledge products (Dutch) on:

  • Security policy
  • Organising information security
  • Secure personnel
  • Asset management
  • Access control
  • Cryptography
  • Physical and environmental security
  • Operational security
  • Communications security
  • Acquisition, development, and maintenance of information systems
  • Supplier relationships
  • Information security incident management
  • Information security aspects of business continuity management
  • Backup and recovery
  • Compliance

The Cyberbeveiligingswet (Cbw) is the Dutch transposition of the European NIS2 directive. The legislation focuses on improving cybersecurity and cyber resilience. For more information on what it entails, visit our Cyberbeveiligingswet (NIS2 Directive) overview page.

This field is for validation purposes and should be left unchanged.
Was this page helpful?
Your feedback is greatly appreciated.

Share this post
  •  Share via email
  •  Share on X
  •  Share on LinkedIn

Widgetruimte algemeen

NIS2 Directive (Cyberbeveiligingswet, Cbw)

  • NIS2 Directive (Cyberbeveiligingswet, Cbw)
  • Tooling for the Cyberbeveiligingswet
  • How did the Cyberbeveiligingswet come about?
  • Which government organisations are subject to the Cyberbeveiligingswet?
  • How can organisations prepare for the Cyberbeveiligingswet?

Last modified on: 14 July 2026.

Got a query, thought, comment, or suggestion?

If you're working on digitalising the government and got something on your mind, please share your thoughts with us.

  • Link DigiD Help Desk digid.nl/en/help
  • Link MijnOverheid / Message Box mijn.overheid.nl/about-mijnoverheid
  • Link eHerkenning Help Desk eherkenning.nl/en/contact
  • Link Message Box for Businesses english.rvo.nl/topics/contact/form

Digital Government

For Caribbean and international professionals working on government digitalisation

Stay Connected

  • Follow us on LinkedIn
  • Follow us on Mastodon
  • Follow us on X (Twitter)
  • Sign up to our Newsletter
  • Activate our RSS Feed

Nederlands

  • Deze site in het Nederlands

About this Website

  • About us
  • Contact
  • Archive
  • Copyright
  • Privacy Statement
  • Accessibility Statement
  • Report a Vulnerability
  • Sitemap