NIS2 website checklist
Since 15 August 2026 the Dutch Cybersecurity Act is in force: the Dutch implementation of the European NIS2 directive. Companies in eighteen designated sectors, from energy and transport to digital infrastructure and healthcare, must take demonstrable cybersecurity measures. Your website is often the first surface an attacker sees. This checklist translates the NIS2 requirements into concrete points you can check today. Every control can be run for free in sixty seconds by a scan.
Last checked
Lees deze pagina in het Nederlands
Run free auditWhat NIS2 requires of your website
The Cybersecurity Act follows the European NIS2 directive: organisations in essential and important sectors must run risk management and comply with reporting duties. For the external side of your web application that means concretely: vulnerability management, securing network and information systems, and access control. The website itself is both asset and gateway.
Important to know: NIS2 applies at the organisation level, not to individual web pages. But during an audit or an incident, your web application is examined. Anyone who can already show the basics are in order (TLS, headers, no leaked keys, email security) spends less time on the real obligations: risk analysis, process and accountability.
The 15-minute checklist
Seven controls that together cover your website's external surface. Each control notes whether the free scan already runs it.
- TLS in order: https everywhere, no expired or weak certificate (check this for free)
- Security headers present and correct: HSTS, X-Content-Type-Options, Referrer-Policy, frame-ancestors (check this for free)
- No secrets in your JavaScript bundle: API keys, tokens and passwords don't belong client-side (check this for free)
- Configuration files shielded: .env, .git, backups and dumps not publicly retrievable (check this for free)
- Email security: SPF, DKIM and DMARC configured against domain spoofing (check this for free)
- Cookie banner and privacy statement present and GDPR-compliant (check this for free)
- Accessibility: WCAG 2.2 level AA as the yardstick (check this for free, the measurable subset)
Reporting duty and management liability
NIS2 includes a three-step reporting duty: an early warning within 24 hours, a full report within 72 hours and a final report within one month of the first report. Reports go through the central intake at MijnNCSC, which reaches both your sectoral CSIRT and your supervisor in one go. Additionally, under NIS2 directors are personally liable for serious negligence in cybersecurity. 'The IT department will handle it' is no longer a defence: management must be able to demonstrate risk management took place.
For your website that means: know what you run, know what is exposed, and have a plan for when things go wrong. A periodic scan with evidence per finding is exactly the kind of artefact that makes this demonstrable: not as a replacement for a risk analysis, but as part of one.
Does your organisation fall under the Act?
The Cybersecurity Act distinguishes essential and important entities across eighteen sectors, including energy, transport, banking, healthcare and digital infrastructure. Size thresholds apply in most sectors, but even below those thresholds, procurement or supply-chain obligations can still bind you to the requirements: clients increasingly fix NIS2 requirements contractually for their suppliers.
If you doubt whether the Act applies to you, the Dutch government offers an official self-assessment (in Dutch). That question is legal, not technical; this page is about what you can do to your website whatever the outcome.
From checklist to evidence
A tick on a checklist is not evidence. In an audit, a client questionnaire or an incident, you want to show which control was run when and what it found. A scan report with the violated measure, the evidence and the severity band per finding is exactly that document.
The free scan covers the externally measurable controls from the checklist above. Deeper tiers add a crawl across multiple pages and infrastructure checks, with export for your vulnerability register.
Frequently asked questions
- Since when does the Cybersecurity Act apply?
- The Act took effect on 15 August 2026 as the Dutch implementation of the European NIS2 directive. Organisations falling under it must comply from that moment; supervision and enforcement build up afterwards.
- Is an NIS2 scan mandatory?
- No, the law does not prescribe a scan; it demands risk management and accountability. An automated scan is the cheapest way to run the external part of that periodically and with evidence.
- What does an NIS2 audit cost?
- A manual NIS2 or security audit typically starts in the thousands of euros. The external website controls from this checklist you run for free; the deeper scan packages cost a fraction of a manual audit.
- Does NIS2 apply to small businesses?
- Size thresholds apply in most sectors, but small organisations can still be bound to NIS2 requirements through procurement and supply-chain agreements. The government self-assessment gives a verdict for your situation.
- How often should I scan?
- There is no statutory frequency. In practice: after every release, and otherwise at least monthly; vulnerabilities mostly arise because something on the site changed.
Curious what is on your own site? Paste a URL and you have a report within a minute.
Run free audit