NIS2 · Cyberbeveiligingswet
Demonstrate your NIS2 posture. With evidence, not assertions.
NIS2 asks in-scope organizations to assess their security posture, put measures in place, and be able to prove it. PAA produces that proof for your Azure, Microsoft 365 and Zero Trust estate — an attestation with control mapping and evidence, kept current as your environment changes. Without a €15,000 consultant.
Read-only access · €99 Day Pass · Liever in het Nederlands? Lees de NIS2-uitleg →
The obligation
What NIS2 actually asks of you
For organizations in scope, NIS2 turns security from good practice into a legal duty of care. In broad strokes, it expects four things.
Assess your risk
A documented view of where your security posture stands — not a feeling, an assessment.
Put measures in place
Technical and organizational controls appropriate to the risk, actually implemented and maintained.
Register
In-scope entities register with the relevant supervisory authority.
Report incidents
A duty to notify significant incidents within tight deadlines (the meldplicht).
In scope means, roughly: a medium or large organization (about 50+ staff or more than €10M turnover) operating in one of the NIS2 Annex I or II sectors. If that’s you, the duty of care applies.
Not sure where you stand? Take the 10-point NIS2 readiness self-assessment →
Where the deadline stands
The dates, told straight
Netherlands
NIS2 is being transposed as the Cyberbeveiligingswet (Cbw). It is expected to enter into force during 2026, after approval by both the Tweede Kamer and Eerste Kamer. The exact date is not yet fixed — it is still in the parliamentary process. Anyone telling you a precise day is guessing. Entering into force does not mean instant fines; it means the duty to assess your posture and have measures in place becomes real.
Belgium
Already in force since October 2024. The first conformity self-assessment — using CyberFundamentals or ISO 27001 — was due 18 April 2026, with full certification due 18 April 2027.
The point of preparing now isn’t the date. It’s that demonstrating posture takes evidence you either have or you don’t — and gathering it after the deadline is the expensive way to do it.
What PAA produces
The evidence, generated and kept current
PAA doesn’t make you compliant — that’s organizational. It produces the technical proof that your posture is where you say it is, and keeps that proof from going stale.
Attestation with control mapping. Your Azure, M365 and Zero Trust configuration mapped against NIS2 expectations, with each control backed by what was actually observed.
A guided wizard. Walks you through the attestation rather than leaving you to interpret a framework cold.
A board-ready PDF. Export the attestation as a document you can hand a regulator, an auditor, or your board.
Drift re-checking. A scheduled job re-runs the attestation over time, so the evidence reflects your environment today — not the day you first ran it.
A certificate is a snapshot. Posture isn’t.
Environments change every week — a new service principal, an opened port, a disabled policy. A one-off audit is true the day it’s signed and decaying the day after. NIS2 expects measures to be in place and maintained, which is why PAA treats attestation as something that runs continuously, not once.
Managing clients in scope?
If you’re a Microsoft partner, NIS2 is your whole book.
Every essential and important entity you manage carries this duty. PAA lets you deliver NIS2 attestation across your portfolio, white-label, and resell it at margin.
See the partner program →NIS2 questions, answered honestly
Is NIS2 in force in the Netherlands yet?
NIS2 is being transposed into Dutch law as the Cyberbeveiligingswet (Cbw). It is expected to enter into force during 2026, after approval by both the Tweede Kamer and Eerste Kamer — the exact date is not yet fixed. The obligation is to demonstrate that you have assessed your security posture and have measures in place, which is worth preparing for before the deadline is loud.
Does NIS2 apply to my organization?
If you are a medium or large organization operating in one of the NIS2 Annex I or II sectors — roughly 50 or more staff, or more than €10M turnover — you are likely in scope and will carry a duty of care: assess risk, put measures in place, register, and report incidents.
Does PAA make us NIS2 compliant?
No tool makes an organization compliant on its own. Compliance is organizational. What PAA does is produce the technical evidence: an attestation, control mapping, and findings that demonstrate the state of your Azure, M365 and Zero Trust posture against NIS2 expectations — and keep that evidence current as your environment changes.
How is this different from a one-off audit?
An audit is a snapshot in time. PAA re-checks your attestation on a schedule and detects drift, so when a regulator, auditor or board asks, your evidence reflects your environment today — not the way it looked last quarter.
What about NIS2 in Belgium?
NIS2 is already in force in Belgium (since October 2024). The first conformity self-assessment, using CyberFundamentals or ISO 27001, was due 18 April 2026, with full certification due 18 April 2027.
Everything we've written on NIS2 and Azure
16 technical write-ups, from the Dutch Cyberbeveiligingswet to article-by-article Azure control mapping.
In het Nederlands
- Wie stelt uw eerste Cbw-vraag? Waarschijnlijk uw grootste klant
De Cyberbeveiligingswet geldt sinds 15 augustus 2026. Er is nog geen toezichtpraktijk, maar ketenrisicobeheer zorgt dat de eerste vraag over uw zorgplicht uit de inkoopafdeling van uw klant komt, niet van een toezichthouder. Wat u op Azure en Microsoft 365 moet kunnen aantonen voordat die vragenlijst binnenkomt.
- Vier authenticatiebypasses in één week, allemaal in de beheerlaag
Tussen 27 juli en 3 augustus 2026 publiceerde het NCSC vier adviezen over authenticatiebypass, telkens in software die andere systemen beheert. Op 15 augustus treedt de Cyberbeveiligingswet in werking. Voor Nederlandse beheerpartijen op Azure verandert daarmee de vraag die gesteld wordt.
- Cyberbeveiligingswet treedt op 15 augustus 2026 in werking — wat verandert er?
De Rijksoverheid heeft bevestigd: de Cyberbeveiligingswet en de Wet weerbaarheid kritieke entiteiten treden op 15 augustus 2026 in werking. Vanaf die datum gelden NCSC-registratie, zorgplicht, meldplicht, aantoonbare bestuurderskennis en ketenrisicobeheer. Voor Nederlandse bestuurders en Cloud Architects op Azure.
- Vijf NCSC-adviezen in één week: weet u of uw Azure-architectuur is blootgesteld?
Het NCSC publiceerde in één week vijf adviezen over veelgebruikte platformtooling. NIS2 Artikel 21 vereist kwetsbaarhedenbeheer. De vraag is of u binnen minuten kunt zeggen of uw Azure-omgeving is blootgesteld - of dat het dagen kost. Voor IT-risicomanagers en platformteams.
- NIS2-meldplicht voor Azure-omgevingen: wat u binnen 24 en 72 uur moet rapporteren
NIS2-meldplicht voor Azure: vroege waarschuwing binnen 24 uur, melding binnen 72 uur, eindrapport binnen een maand. Detecteren met Microsoft Sentinel. Voor Nederlandse CISO's.
- Wat NIS2 betekent voor uw Azure-omgeving: een praktische gids voor Nederlandse organisaties
NIS2 Artikel 21 stelt concrete eisen aan uw Azure-configuratie. Deze gids vertaalt de tien technische maatregelen naar specifieke Azure-services en instellingen — voor IT-risicomanagers en compliance-professionals bij Nederlandse organisaties.
In English
- The Best NIS2 Compliance Tools for Azure in 2026
A category-by-category comparison of NIS2 compliance tooling for Azure in 2026: GRC automation, CSPM, Azure-native services, and architecture assessment. Written for Dutch buyers who have to evidence NIS2.
- NIS2 vs ISO 27001 on Azure: What Overlaps, What Doesn't
NIS2 vs ISO 27001 on Azure: a control-by-control map of Article 21 to Annex A, plus the three gaps certification doesn't close. For compliance leads and CISOs.
- NIS2 Incident Reporting on Azure: The 24-Hour and 72-Hour Obligations
NIS2 incident reporting on Azure means a 24-hour early warning, 72-hour notification, and one-month final report. Build the capability in Microsoft Sentinel. For SecOps leads.
- Zero Trust Isn't a Product You Buy. It's an Architecture You Document - and Keep From Drifting.
Zero trust on Azure is an architecture you have to document and maintain, not a product you switch on. The evidence a NIS2 supervisor wants is the design rationale - and it drifts. For Azure architects and compliance leads.
- CNAPP and Azure Architecture: Where Runtime Risk Detection Stops and Design Review Begins
A CNAPP tells you which resources are exploitable right now. It does not tell you whether your architecture should have been built that way. This is where runtime detection ends and design-time assessment begins.
- Can You Answer 'Are We Exposed to Anything on the KEV List?' From Your Azure Architecture - in Minutes?
CISA updated its Known Exploited Vulnerabilities catalogue twice in one week. NIS2 Article 21 requires vulnerability handling. The question is whether your Azure architecture can answer 'are we exposed' in minutes or in a week. For SecOps and compliance leads.
- Microsoft Defender for Cloud and NIS2/DORA: What the Compliance Dashboard Covers — and Where the Gaps Are
A fair read on Microsoft Defender for Cloud NIS2 compliance: strong first-party standards, real gating and scope limits. For security leads. With a coverage table.
- NIS2 Supply Chain Security for Azure and Microsoft 365
NIS2 supply chain security on Azure means governing OAuth apps, service principals, and SaaS dependencies under Article 21(2)(d). What to configure and evidence. For CISOs.
- The Cyberbeveiligingswet Duty of Care Lands on the Board — and a Scanner Can't Evidence It
The Cyberbeveiligingswet takes effect on 15 August 2026. Its hardest obligation is a board-level duty of care — personal, continuous, non-delegable — that vulnerability scanners cannot evidence. For directors and Cloud Architects at Dutch regulated organisations.
- NIS2 Article 21 Requirements for Azure Infrastructure: A Technical Control Mapping
NIS2 Article 21 requires demonstrable Azure configuration evidence across ten security measure domains. This post maps each domain to specific Azure services and configuration settings. For Platform Engineers and Cloud Architects at Dutch regulated organisations.
Know where your NIS2 posture stands.
Start with a €99 Day Pass and run a compliance assessment. Read-only access, results in hours, no consultant required.