NIS2/CBW checklist for Dutch government

Twelve practical questions to see where you stand — for ministries, provinces and municipalities. Printable, board-ready, no buzzwords.

Use this checklist as a fast readiness scan with the CISO, information manager and (where relevant) board stakeholders. Mark each item: in place, partial or open. No fake score — clear follow-up questions.

CISO Ally B.V. · mvdd@cisoally.com · 07:00–22:00 · 24×7 on request

Readiness checklist (12 items)

1

Scope & entity type under NIS2/CBW

Is it documented whether (parts of) your organisation fall under the Cyberbeveiligingswet / NIS2, and who confirmed that at board level?

Hint: scope note + decision record — not an IT assumption alone.
2

Board accountability

Is it clear that the governing body is ultimately accountable and the CISO advises — with documented reporting lines?

Hint: board agenda, mandate, escalation path.
3

Current risk picture

Is there a current, board-readable cyber risk picture (threat × impact × controls), not only a technical backlog?

4

Policy & ISMS baseline

Are security policy, roles and processes demonstrable (BIO/BIO2, ENSIA context for municipalities, ISO 27001 thinking) and maintained?

5

Incident response & notification duty

Is there a practised incident process, including who decides on (legal) notification and communication?

Hint: roles, contact list, exercise notes — not only a file on a drive.
6

Supply chain & vendors

Are critical suppliers and chain dependencies mapped, with requirements in contracts / GIBIT context where applicable?

7

BCM for critical processes

Are critical processes named, with continuity arrangements and testable recovery paths (ISO 22301 thinking)?

8

Identity & access management

Is access management (joiner/mover/leaver, privilege, MFA where needed) demonstrable and periodically reviewed?

9

Awareness programme

Is there a structural awareness programme (not only an annual e-learning), with measurable staff reach?

10

Logging, monitoring & detection

Is it agreed what you monitor, who alerts, and how long logs remain available for forensic / compliance use?

11

Vulnerabilities & patch policy

Is there a working vulnerability management process (prioritisation, exceptions, OT/IT separation questions where relevant)?

12

Evidence & board planning

Can you show in one board note: what is in place, what is open, cost per phase, and what you will do in the next 90 days?

Hint: phased awards avoid big-bang and keep CISO + board in control.

Done scanning? Book a 15-minute intake

Send your top-3 open items — we help turn them into a board-ready, phased next step. No pitch deck; practical sparring.

Frequently asked questions

Short, citation-friendly answers — no jargon.

Who is this NIS2/CBW checklist for?

CISOs, information managers and board stakeholders at Dutch ministries, provinces, municipalities and collaborating public bodies who want a readiness scan without a big-bang programme.

Does this checklist replace a gap analysis?

No. It is a fast readiness scan to surface blind spots and board questions. A full gap analysis and measures plan follow afterwards, phased.

What is CBW?

The Cyberbeveiligingswet is the Dutch transposition of NIS2. CISO Ally helps public-sector organisations prepare phase by phase.

How do I book a 15-minute intake?

Email mvdd@cisoally.com with subject “15-min intake NIS2/CBW” or use the contact page. Availability: 07:00–22:00; 24×7 on request.