Home Cybersecurity Cybersecurity Act

Cybersecurity Act (NIS2) Compliance Check

Do you know the extent to which your organisation complies with the Cybersecurity Act (NIS2)?

The Cyber Security Act, the implementation of the NIS2 directive, sets higher standards for the digital resilience of organisations that provide essential or important services. The act entails obligations in the areas of risk management, incident notification, managerial accountability and demonstrable compliance.
A simple online scan can give an initial indication of the possible applicability of the legislation. However, that does not indicate to an organisation whether the required measures have actually been put in place, are being carried out, and are demonstrably effective.
Would you like to brainstorm about the implications of the Cybersecurity Act for your organisation? Schedule a no-obligation session with our experts to discuss your situation, areas for attention and explore whether a NIS2 Compliance Check is right for you
Schedule a session

We do not believe in a quick ‘NIS2 assessment’ that determines how compliant an organisation is while only using 5 to 10 questions.

Such an assessment is overly simplistic. Compliance is not just about giving the right answer. It is more about whether processes, responsibilities and measures have actually been put in place and whether there is sufficient evidence to prove it.

That is why Sphere IT takes a thorough and practical approach to compliance assessment. Read here about our Cybersecurity Act Compliance Check.

What is the Dutch Cybersecurity Act (NIS2)?

Organisations covered by NIS2 will be subject to, amongst other things, four key requirements:

1. Duty of care

Organisations must take appropriate and proportionate technical and organisational measures to manage risks to the security of network and information systems. In doing so, consideration may be given to risk assessments, policy measures, access security, continuity, resilience and supply chains, among other things.

2. Reporting obligation

Significant incidents with a substantial impact must be reported to the competent authority within the statutory deadlines. This requires clear procedures for detection, assessment, escalation and reporting.

3. Management accountability

Executive management and the board are ultimately accountable for compliance with the Dutch Cybersecurity Act. They must understand the organisation’s cyber risks, oversee the implementation of security measures and be able to demonstrate accountability.

4. Monitoring and enforcement

Regulators can conduct investigations and take enforcement action in the event of violations. This may lead to administrative measures, fines and, in certain cases, public disclosure.

Why a quick online scan is not enough

Many NIS2 compliance checks consist of only a limited number of overly general questions. For example:
  • Is there an information security policy?
  • Are risk assessments carried out?
  • Is there an incident response plan?
  • Are suppliers evaluated?
  • Is the board involved?
Based on the answers, a compliance percentage is then automatically generated.

The problem is that such scans usually do not determine:
  • whether the mentioned policy is current and approved;
  • whether responsibilities have been formally assigned;
  • whether processes are actually carried out;
  • whether employees are familiar with the procedures;
  • whether measures are demonstrably monitored;
  • incidents and deviations are followed up;
  • whether reports are available;
  • and whether the burden of proof aligns with what is stated during the scan.
For example, an organisation may state that a risk analysis is in place. However, without a substantive assessment, it remains unclear whether this analysis is complete, up to date and applicable across the entire organisation, and whether the results have actually been translated into concrete control measures.
Therefore, we do not only assess what an organisation claims to have put in place, but also what is demonstrably present and operational.

Our Cybersecurity Act (NIS2) Compliance Check

With Sphere IT's Cybersecurity Act Compliance Check, your organisation will get a realistic picture of its current level of compliance regarding NIS2 within about half a day to one full working day.

The time required depends, among other things, on:
The size and complexity of the organisation;
The number of stakeholders involved;
The availability of policy, procedures and records;
The maturity of current information security;
And the scale of the available evidence.
The assessment is carried out by means of interviews, documentation and demonstrable evidence. This prevents the outcome from being based solely on assumptions or subjective answers. This gives you a rigorous picture of your organisation's NIS2 compliance.
  • Maroche Delnoy
    Cybersecurity Specialist
  • Steven Van Hal
    IT-security Consultant
  • Fleur Verheij
    IT-security Consultant

Our approach

First, we map out the organisation, relevant activities, and potential applicability of the Cybersecurity Act.

We determine, amongst other things:
  • which parts of the organisation fall within the scope;
  • which stakeholders should be involved in the assessment;
  • what documents and records are available;
  • and which legal obligations are relevant.
It can also be assessed whether the organisation is active in a designated sector, meets the size criteria, or falls under an exception. Our NIS2 infographic demonstrate that smaller organisations can also, under certain circumstances, fall within the scope, for example due to the nature of their services or their role within a critical chain.
During the interviews, we will discuss how the organisation fulfils its obligations under the Cybersecurity Act.

Depending on the organisation, we might speak with, for example:
  • management or board;
  • IT managers;
  • information security or CISO;
  • privacy, legal or compliance;
  • risk management;
  • supplier management;
  • business continuity;
  • and process owners.
The interviews are not intended as a theoretical test. We are mainly investigating how processes work in practice, who is responsible for what and how the organisation can demonstrate that measures are being implemented.
Next, we assess the available evidence.

Consider things like:
  • policies and procedures;
  • risk analyses;
  • authorisation matrices;
  • incident logs;
  • business continuity and recovery plans;
  • supplier evaluations;
  • management reports;
  • training and awareness records;
  • technical reports;
  • audit findings;
  • and improvement plans.
Not every document needs to be fully developed to provide a meaningful assessment. However, sufficient information must be available to determine which measures have been demonstrably implemented and where gaps remain.
The information from the interviews and the evidence is substantively assessed against the relevant obligations under the Cyber Security Act.

In doing so, we look not only at the presence of measures, but also at:
  • the level of implementation;
  • the division of responsibilities;
  • embedding within standard processes;
  • the demonstrability;
  • monitoring and evaluation;
  • and the practical effectiveness.
Afterwards, the organisation will receive a clear report containing the main findings.

More about the Compliance Check

  • Applicability of the law: We provide a reasoned indication as to whether the organisation falls under the Cybersecurity Act and which circumstances are relevant in that regard.
  • Current compliance position: You gain insight into the extent to which the organisation has demonstrably structured the relevant obligations. The score is not a random percentage based on a few answers, but an assessment based on interviews, available documentation and evidence.
  • Adulthood and resilience: We assess not only whether a measure exists, but also the extent to which it is structurally embedded, implemented, evaluated and improved.
  • Key risks and shortcomings: The report makes clear where the greatest risks, vulnerabilities and compliance gaps lie.
The Compliance Check is suitable, among other things, for organisations that:
  • want to know if the Cybersecurity Act applies;
  • wishing to carry out an initial substantive baseline measurement;
  • preparing for oversight or an audit;
  • wanting to give their management board insight into the current position;
  • wish to test existing NIS2 or compliance initiatives;
  • having insufficient overview of available evidence;
  • or need a practical improvement plan.
Organisations that already work with ISO 27001, NEN 7510, the NIST Cybersecurity Framework or another standards framework can also use the assessment to determine where additional actions for the Cybersecurity Act are required.
Our goal is not solely to establish that documents are missing.

We want to make it clear:
  • what risk arises as a result;
  • why a measure is relevant;
  • what must be set up as a minimum;
  • what evidence is required;
  • who within the organisation can be made responsible;
  • and which next step should be carried out first.
This translates the Cybersecurity Act into concrete actions that align with the organisation, its services and its risk profile.

Do you want to know what the Cybersecurity Act means for your organisation?

Schedule a short, no-obligation session with Sphere IT. We will discuss the key implications of the act for your organisation. Leave your email address and we will look together at whether and how a Compliance Check can be scheduled. Completely without obligation and with no further commitments.

I agree with the privacy statement and give Sphere IT permission to schedule a brief, no-obligation session by email.