Dutch Cybersecurity Act · Article 21
Where do you stand on the ten measures of Article 21?
The Dutch Cybersecurity Act (Cyberbeveiligingswet, Cbw), the national implementation of NIS2, entered into force on 15 August 2026. Article 21 prescribes ten measures. Most checklists ask whether they exist. This check also asks whether they work.
Developed by practitioners
This Article 21 check was developed and validated by senior cybersecurity and GRC architects. Based on the ten measures of Article 21, translated into concrete questions on governance, risk and technology.
Our architect team collectively holds certifications including:
Two axes, ten measures
Formally documented and tested in practice. After ten questions, every measure sits in one of these four boxes.
Want to know first whether the law applies to your organisation? Use the
Dutch government’s NIS2 self-assessment
Start with your sector
The sector determines the proportionality test of the law. That is why this is step one.
Want to know first whether the law applies to your organisation? Use the
Dutch government’s NIS2 self-assessment
Trusted by organisations including
Ten questions · six minutes
Where all ten measures sit
Two axes per measure: formally documented and tested in practice. The result appears on screen, no email required.
Per measure needing attention
Evidence and first step
Not a twenty-page report. Per measure: what it is about, what evidence a regulator wants to see, and the step to start with.
Made to forward
A summary for your leadership
One page, written for someone who did not fill in the check themselves. Sent to your inbox on request.
Staatsblad 2026, 187
What does Article 21 say?
Article 21 of the Cbw obliges essential and important entities to take appropriate and proportionate technical, operational and organisational measures. The third paragraph makes explicit what that means at minimum: ten measures, from risk analysis to emergency communications.
The ten measures are not a technical list. They are ten functions that must stand in the organisation, with board ownership, periodic testing and evidence that they work. Article 24 of the Cbw requires the board to approve those measures itself, and sets knowledge requirements for each individual board member.
Legal text: Cyberbeveiligingswet (Cbw), Staatsblad 2026, 187, Article 21. In force since 15 August 2026.
aRisk analysis and security policy
“policies on risk analysis and information system security”
This is the measure that gives the other nine their direction: which risks the organisation runs, which you cover and which you consciously accept. Without that decision, every security expense is a guess.
What counts as evidenceAn adopted policy plus a decision on risk acceptance no older than twelve months.
bIncident handling
“incident handling”
The law does not ask you to prevent incidents; it asks you to demonstrably learn from them. Detect, escalate, recover and evaluate, with a trail showing that happened.
What counts as evidenceA populated incident log with, per incident, an evaluation and who picked up the lesson.
cBusiness continuity and crisis management
“business continuity, such as backup management and disaster recovery, and crisis management”
A backup only truly exists once it has been restored. This measure asks for proven recovery of critical systems and a crisis organisation that has rehearsed.
What counts as evidenceA report of a recovery test from backup and a rehearsed crisis scenario, both less than twelve months old.
dSupply chain security
“supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers”
Your security is as strong as that of the suppliers who can reach your systems. The law places the responsibility for that with you, not with them.
What counts as evidenceA list of critical suppliers with security terms in the contract and a verification from the past year.
eSecurity in acquisition, development and maintenance
“security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure”
Everything you buy, build and operate brings vulnerabilities with it. The law asks for one working process from report to fix, with a lead time you can show.
What counts as evidenceAn overview of reported vulnerabilities with, for each one, the lead time from report to fix.
fAssessing effectiveness
“policies and procedures to assess the effectiveness of cybersecurity risk-management measures”
This is the measure that guards the other nine: someone periodically tests whether they work, and the outcome leads to adjustment. Without this function, every other measure ages unnoticed.
What counts as evidenceA review or audit report from the past year with an adjustment that actually happened.
gCyber hygiene and training
“basic cyber hygiene practices and cybersecurity training”
The daily basics: patches, secure settings, tidy access and people who know what to look out for. Training is part of it, up to and including the top.
What counts as evidenceA current patch overview and a training register with dates, in which the executives themselves also appear.
hCryptography and encryption
“policies and procedures regarding the use of cryptography and, where appropriate, encryption”
Encryption only protects once you know what you encrypt, why, and who can reach the keys. Whoever holds the key holds the data.
What counts as evidenceA policy substantiating the choice per type of data, plus a current overview of who manages keys.
iPersonnel, access policy and assets
“human resources security, access control policies and asset management”
Who can reach which systems and data, is access revoked on departure, and is there a current overview of what you manage. Access and assets are the ledger of your security.
What counts as evidenceAn access review of the critical systems and an asset register, both from this year.
jMFA, secured communications and emergency communications
“the use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the entity, where appropriate”
Two provisions for your worst day: sign-in that does not lean on a single password, and a channel through which the crisis team can reach each other when mail and telephony are gone.
What counts as evidenceAn overview of where MFA is on and a documented emergency channel that was tried once in the past year.
Frequently asked questions
What are the ten measures of Article 21?
Article 21(3) of the Dutch Cybersecurity Act lists: risk analysis and security policy, incident handling, business continuity and crisis management, supply chain security, security in acquisition and development, assessing the effectiveness of measures, cyber hygiene and training, cryptography, personnel and access policy, and multi-factor authentication with secured emergency communications.
Who does Article 21 apply to?
To essential and important entities under the Dutch Cybersecurity Act (Cyberbeveiligingswet), the national implementation of the NIS2 directive. The law entered into force on 15 August 2026 and affects around 8,000 organisations across 18 sectors. Whether your organisation falls under it can be tested with the Dutch government’s NIS2 self-assessment.
Is ISO 27001 certification enough for Article 21?
Not automatically. Much of what ISO 27001 delivers counts, but the law asks for a broader spectrum, with explicit continuity, chain and board functions, and a different test of demonstrability. A certificate demonstrates a management system, not that every measure actually works.
What if a measure exists on paper but does not work?
Regulators do not ask what happened, but what stands now, when it was last tested, and what the board thinks of it. A continuity plan untested for two years meets the formal bar but not the practical one. That difference is exactly what this check makes visible.
Prefer a conversation first?







