Use this checklist as a fast readiness scan with the CISO, information manager and (where relevant) board stakeholders. Mark each item: in place, partial or open. No fake score — clear follow-up questions.
Tip: print or export to PDF via your browser (Ctrl/Cmd+P).
Readiness checklist (12 items)
Scope & entity type under NIS2/CBW
Is it documented whether (parts of) your organisation fall under the Cyberbeveiligingswet / NIS2, and who confirmed that at board level?
Hint: scope note + decision record — not an IT assumption alone.Board accountability
Is it clear that the governing body is ultimately accountable and the CISO advises — with documented reporting lines?
Hint: board agenda, mandate, escalation path.Current risk picture
Is there a current, board-readable cyber risk picture (threat × impact × controls), not only a technical backlog?
Policy & ISMS baseline
Are security policy, roles and processes demonstrable (BIO/BIO2, ENSIA context for municipalities, ISO 27001 thinking) and maintained?
Incident response & notification duty
Is there a practised incident process, including who decides on (legal) notification and communication?
Hint: roles, contact list, exercise notes — not only a file on a drive.Supply chain & vendors
Are critical suppliers and chain dependencies mapped, with requirements in contracts / GIBIT context where applicable?
BCM for critical processes
Are critical processes named, with continuity arrangements and testable recovery paths (ISO 22301 thinking)?
Identity & access management
Is access management (joiner/mover/leaver, privilege, MFA where needed) demonstrable and periodically reviewed?
Awareness programme
Is there a structural awareness programme (not only an annual e-learning), with measurable staff reach?
Logging, monitoring & detection
Is it agreed what you monitor, who alerts, and how long logs remain available for forensic / compliance use?
Vulnerabilities & patch policy
Is there a working vulnerability management process (prioritisation, exceptions, OT/IT separation questions where relevant)?
Evidence & board planning
Can you show in one board note: what is in place, what is open, cost per phase, and what you will do in the next 90 days?
Hint: phased awards avoid big-bang and keep CISO + board in control.Done scanning? Book a 15-minute intake
Send your top-3 open items — we help turn them into a board-ready, phased next step. No pitch deck; practical sparring.
Frequently asked questions
Short, citation-friendly answers — no jargon.
Who is this NIS2/CBW checklist for?
CISOs, information managers and board stakeholders at Dutch ministries, provinces, municipalities and collaborating public bodies who want a readiness scan without a big-bang programme.
Does this checklist replace a gap analysis?
No. It is a fast readiness scan to surface blind spots and board questions. A full gap analysis and measures plan follow afterwards, phased.
What is CBW?
The Cyberbeveiligingswet is the Dutch transposition of NIS2. CISO Ally helps public-sector organisations prepare phase by phase.
How do I book a 15-minute intake?
Email mvdd@cisoally.com with subject “15-min intake NIS2/CBW” or use the contact page. Availability: 07:00–22:00; 24×7 on request.