• The duty of care is set out in Article 21 of the Cbw (the ten points a to j from NIS2) and elaborated in Articles 6 to 18 of the Cyberbeveiligingsbesluit (Cbb).
  • According to its explanatory memorandum, the Cbb was drafted with ISO 27001 and NEN 7510 as the starting point. The overlap is large, but not complete.
  • Healthcare must demonstrably meet NEN 7510, ISO 27001/27002 or an equivalent level; government must apply ISO 27001 and at least the relevant controls from BIO2 v1.3.
  • A certificate helps you demonstrate compliance, but is not proof that you comply with the law.

Many organisations that fall under the Dutch Cyberbeveiligingswet (Cbw) already have an ISMS: ISO 27001 in business, NEN 7510 in healthcare, the BIO in government. The question then isn't "what do we need to build" but "what is still missing". This page puts the Cbb articles next to the three frameworks. First the structure and the main differences; then the full, filterable crosswalk.

How the duty of care is structured

Article 21(3) Cbw lists the minimum topics (identical to Art. 21(2) NIS2): a) risk analysis and security policy, b) incident handling, c) business continuity and crisis management, d) supply chain, e) acquisition, development and maintenance including vulnerabilities, f) assessing effectiveness, g) cyber hygiene and training, h) cryptography, i) human resources, access and assets, j) MFA and secured (emergency) communication. Article 5 Cbb says that entities take "at least" the measures in Articles 6 to 18.

Cbb articleSubjectCbw Art. 21(3)
Art. 6Policy for the security of network and information systems, roles, management systema
Art. 7Risk managementa
Art. 8Incident handling and loggingb
Art. 9Business continuity, backups, recovery and crisis planc
Art. 10Supply chaind
Art. 11Acquisition, development, maintenancee
Art. 12Cyber hygiene and trainingg
Art. 13Cryptographyh
Art. 14-16Human resources, access policy, assetsi
Art. 17Alerts, advisories and threat intelligence(para. 1)
Art. 18Evaluating effectivenessf

Two caveats. For DNS service providers, TLD registries, cloud and data centre providers, CDNs, MSPs, MSSPs, online marketplaces, search engines, social networks and trust services, Articles 6 to 18 Cbb do not apply; the technical requirements of Implementing Regulation (EU) 2024/2690 apply to them instead (Art. 4 Cbb). And the duties of the management body (approval and training) are in Article 24 Cbw and Articles 20 to 22 Cbb.

What the sector regulations prescribe

Healthcare: NEN 7510 or ISO 27001/27002

The Cyberbeveiligingsregeling voor de zorg (Staatscourant 2026, 28763) provides in Article 2.1 that measures must demonstrably meet NEN 7510, NEN-ISO/IEC 27001 and 27002, or demonstrably provide an equivalent level of protection. The explanatory notes are clear on certification: "Obtaining a certification shows that an entity meets the standard, but is not a requirement in this respect." Also important: the Cbw duty of care applies to all network and information systems, including HR systems for example, while the existing NEN 7510 duty under the Wabvpz only covers healthcare information systems and exchange systems. Where the regulation refers to NEN 7510, it means NEN 7510-1 and NEN 7510-2 together.

Government: ISO 27001, ISO 27002 and BIO2

The Cyberbeveiligingsregeling sector overheid (Staatscourant 2026, 27679) requires essential entities in the government sector (except water authorities) to apply NEN-EN-ISO/IEC 27001:2023 to their management system (Art. 3) and to use at least the controls from ISO 27002:2022 and the relevant government controls from BIO2 version 1.3, with the exception of 5.32 and 5.34 (intellectual property and privacy, which fall outside the Cbw) (Art. 5). Replacing them with an equivalent framework is allowed if you demonstrate the necessity and equivalence. More on this in BIO versus BIO2.

Other sectors

For most other sectors the law does not prescribe a standard. The explanatory memorandum to the Cbb: "With the Cbw and the Cbb, entities keep the freedom to continue using their existing framework, but they must ensure that the measures in the Cbb are covered." ISO 27001 is then the logical backbone.

Where ISO 27001 is not automatically enough

The crosswalk shows five places where a working ISO 27001 ISMS often still lacks something:

  1. Reporting deadlines. ISO 27001 asks for incident management (A.5.24-5.28), but not for 24 hours, 72 hours and one month. Your procedure must include the statutory deadlines, sector thresholds and the MijnNCSC reporting point.
  2. Crisis plan and emergency communication. The Cbb asks for a tested and exercised crisis management plan with means of communication and, where appropriate, secured emergency communication (Art. 9(5)). ISO 27001 Annex A only has information security during disruption and ICT readiness (A.5.29, A.5.30).
  3. Board training with a certificate. Every board member needs a training certificate within two years, with name, dates, topics and provider (Art. 24 Cbw, Art. 22 Cbb).
  4. Recording targeted alerts. You assess every targeted warning from a CSIRT, authority or supplier and record the outcome in writing (Art. 17 Cbb).
  5. Scope. An ISMS with a narrow certificate scope (for example one product or one site) does not automatically cover all the network and information systems you use for your services.

NEN 7510:2024 covers several of these points better: according to Kiwa, the healthcare-specific controls include communication in emergencies, external incident reporting, management training and zero trust principles.

Certification is not automatically compliance

This misunderstanding costs organisations money. Three official sources say it in their own words:

  • NCSC (FAQ): "Certification marks, however, have no independent status in relation to meeting the legal requirements. It is up to the supervisory authority to assess whether a party complies with the law."
  • RDI, in the explanatory notes to the government regulation: certification is given "often on the basis of a snapshot"; "A certification for this ISO standard therefore does not necessarily demonstrate that the level of security is sufficient."
  • BIO2: "The BIO does not require NEN-EN-ISO/IEC 27001 certification. Certification does, however, help simplify accountability."

So use your certificate as evidence, not as the finish line. Check whether the scope covers the systems that fall under the Cbw, whether your Statement of Applicability covers the Cbb requirements, and whether the Cbw-specific points above are demonstrably in place.

How to use the crosswalk

  1. Download the CSV and set your current status per row (in place, partial, missing).
  2. Link your existing ISMS documents and evidence to each row.
  3. Turn the "Watch out" column into concrete tasks with an owner and a deadline.
  4. Present the result to the management body: it must approve the measures (Art. 24 Cbw).

Note: the numbers in the columns are signposts. The ISO and NEN texts are protected by copyright and not reproduced here. According to the BIO2, government entities can access ISO 27001 and 27002 free of charge via NEN Connect, and according to the healthcare regulation anyone can view NEN 7510 free of charge.

Sources

As of 1 October 2026. This page is general information, not legal advice. Laws, regulations and sector rules can change; always check the current source.