Skip to content
Valystrum - AI-powered intelligence for continuous security and compliance.

Framework

Cyberbeveiligingswet (CBW)

Assess Cyberbeveiligingswet with Valystrum using 39 controls, evidence collection, gap analysis, remediation tracking, and audit-ready reporting.

The Cyberbeveiligingswet is the Dutch implementation of NIS2, effective 15 August 2026, and provides a practical framework for organizations that must manage cyber risk with structure, evidence, and repeatability. It defines how Dutch organizations should organize governance, risk management, incident reporting, supply‑chain oversight, registration, and supervision readiness.

Valystrum translates the CBW framework into operational assessment controls, evidence workflows, gap analysis, remediation tracking, and continuous monitoring that scale with your organization.

Turn NIS2-aligned Dutch cyber obligations into an operational control program.

The Cyberbeveiligingswet converts NIS2 expectations into concrete Dutch requirements for cyber governance, risk management, incident handling, entity registration, and supervisory oversight.
Organizations use the framework to determine whether management accountability, supply‑chain controls, security measures, and reporting processes are ready for regulatory scrutiny.

While the CBW defines what good security and resilience should look like, many organizations struggle to determine whether their policies, controls, owners, documentation, and evidence actually meet expectations.
Valystrum removes that uncertainty by turning CBW into a structured assessment that shows where you stand, what needs attention, and how to improve.

What is Cyberbeveiligingswet?

The Cyberbeveiligingswet provides a structured, legally grounded way to organize requirements, responsibilities, controls, evidence, and continuous improvement activities.
It is not just a checklist, it creates a shared language for teams that must align governance, operational execution, and assurance reporting under Dutch NIS2 obligations.

Valystrum keeps CBW practical by focusing on implementation evidence, control ownership, gaps, residual risk, remediation status, and repeatable monitoring rather than static policy statements alone.

How Valystrum helps

Valystrum converts the Cyberbeveiligingswet into a guided assessment that helps teams:

  • Evaluate implementation
  • Collect evidence
  • Identify gaps
  • Prioritize remediation
  • Report maturity in a format leadership, customers, auditors, and regulators can understand

Our assessment includes:

  • 39 assessment controls
  • 118 structured assessment questions
  • Evidence collection for every applicable control
  • Gap identification and remediation tracking
  • Continuous compliance monitoring
  • Executive dashboards and audit‑ready reporting

What we assess

The assessment evaluates whether your organization has implemented effective controls across the CBW scope, including:

  • Scope, Classification, and Register Readiness
  • Governance and Duty of Care (zorgplicht)
  • Cybersecurity Risk‑Management Measures
  • Incident Reporting and Crisis Communication
  • Supply Chain and ICT Service Providers
  • Business Continuity and Crisis Management
  • Documentation, Supervision, and Improvement
  • Privacy and Sectoral Overlap

Assessment outputs

  • Overall readiness or compliance score
  • Control‑by‑control assessment view
  • Evidence register linked to each control
  • Gap analysis with risk‑based prioritization
  • Remediation roadmap with owners and due dates
  • Executive summary for leadership and customers
  • Audit‑ready reporting and continuous monitoring view

Why choose Valystrum?

Valystrum helps you answer practical assurance questions, including:

  • Where do we stand today
  • Which controls are missing or weak
  • What evidence do we need to prove implementation
  • Which risks and gaps should be prioritized first
  • Are we ready for customer, auditor, regulator, or board review

Who is this for?

This assessment is designed for security teams, GRC teams, IT operations, risk owners, leadership, suppliers, service providers, and organizations that must demonstrate cyber assurance under CBW/NIS2.

Assess your security and resilience maturity

Run a structured assessment, identify gaps, collect evidence, and receive a prioritized roadmap for improving readiness.

See how it works against your estate.

A 30-minute walkthrough against a sandbox of your scale, with one of our governance engineers.

Related