Articles 71 & 72 of the Dutch CBW

why a penetration test is no longer a luxury, but a necessary security assessment

The digital threat landscape for organizations is growing every day. Ransomware, data breaches, and attacks on business-critical systems are no longer theoretical risks. Organizations that rely on digital systems must take demonstrable measures to improve their cyber resilience.

With the introduction of the Cybersecurity Act (CBW), based on the European NIS2 Directive, organizations covered by the legislation face stricter requirements regarding information security, risk management, and supervision.

An important part of this are Articles 71 and 72 of the Cybersecurity Act. These articles give the competent authority powers to supervise the digital resilience of organizations. This includes the ability to perform security assessments or require an organization to commission an independent investigation into compliance with the legal security requirements.

But what does this mean for your organization in practice?





How strong is your security really?

The question is not only whether your security is being tested, but whether you actually know how strong it is.
Many organizations invest in firewalls, antivirus software, monitoring solutions, and security policies.
Yet one essential question often remains unanswered:

How likely is it that an attacker could actually gain access to our systems?

Documented security measures do not automatically mean that an organization is truly secure. A misconfiguration, outdated software, unused accounts, excessive access rights, or insufficiently secured connections with suppliers can still provide an entry point for attackers.

A professional penetration test (pentest) provides insight into this reality. A pentest does not only verify whether security measures are present, but also assesses whether they can withstand realistic attack techniques.

What do Articles 71 and 72 mean for your organization?

For organizations covered by the Cybersecurity Act, this means they must take active supervision of their digital security into account.

An organization must be able to demonstrate that it:

  • systematically identifies cyber risks;
  • applies appropriate technical and organizational security measures;
  • assesses the effectiveness of these measures;
  • discovers and resolves vulnerabilities in a timely manner;
  • is prepared for potential cyber incidents.

The law does not require every organization to perform an annual pentest by default. However, a security assessment may form part of regulatory supervision, and a penetration test can be used to evaluate the actual security level and vulnerabilities of systems.

For your organization, this means that you must not only be able to demonstrate which security measures are in place, but also that you understand whether these measures are effective.

What does a security assessment under Article 71 involve?

A security assessment is intended to provide insight into an organization’s resilience. This may include reviewing:

  • technical vulnerabilities in systems and applications;
  • the security of network components;
  • access rights and user accounts;
  • configuration errors;
  • exposed systems;
  • the possibility of an attacker gaining access;
  • the effectiveness of existing security measures.

A penetration test is one of the methods that can be used as part of such a security assessment. It examines how an attacker could realistically approach an organization and what impact a successful attack could have.

What happens if your organization is investigated?

When your organization becomes subject to a security assessment or audit by the authorities, you must provide insight into your security level and demonstrate which measures have been implemented.

An investigation may result in:

  • insight into vulnerabilities within your IT environment;
  • recommendations to reduce risks;
  • additional measures required to comply with legal requirements;
  • improvements related to policies, processes, and technology.

The goal is not merely compliance monitoring, but primarily strengthening the digital resilience of the Netherlands.

Why perform a pentest yourself?

By having an independent pentest performed periodically, you remain in control of the process.
You discover vulnerabilities before they are identified by a regulator or exploited by a malicious attacker.

A professional pentest helps your organization to:

1. Discover vulnerabilities at an early stage Security weaknesses become visible before they can be exploited.

2. Demonstrate control over cyber risks You can show that cybersecurity is actively managed and that risks are being assessed.

3. Set priorities Not every vulnerability presents the same level of risk. A pentest clarifies which issues require immediate attention.

4. Protect business continuity By identifying weaknesses in advance, you reduce the likelihood of disruption caused by cyber incidents.

A pentest is more than an automated scan

An automated vulnerability scan can provide valuable information, but often only offers a limited view.

An experienced penetration tester investigates how vulnerabilities can be combined and approaches the environment from an attacker’s perspective:

  • Which systems are accessible?
  • Where can access be obtained?
  • What privileges could an attacker gain?
  • Which data or processes could be affected?
  • What would the actual impact be?

The result is not simply a long list of technical findings, but a practical report containing risks, impact assessments, and concrete improvement recommendations.

Prepare your organization before an incident occurs

The Cybersecurity Act changes the way organizations must approach cybersecurity. Digital security is no longer only about implementing technical security tools, but about demonstrable risk management and continuously improving resilience.

A pentest provides your organization with insight into its actual security posture and helps implement targeted improvements.

Does every organization fall under the Cybersecurity Act?

Not every organization automatically falls under the new Cybersecurity Act. The legislation primarily focuses on organizations that play an important role in society or the economy and where disruption could have significant consequences.

The Cybersecurity Act mainly applies to so-called essential entities and important entities. These are organizations operating in sectors where digital disruption or a cyberattack could have major societal or economic impact.

Examples include organizations within:

  • energy and drinking water;
  • transport;
  • digital infrastructure;
  • healthcare;
  • financial services;
  • government services;
  • certain manufacturing and distribution chains;
  • providers of digital services.

Whether your organization falls under the legislation depends not only on the sector in which you operate. Factors such as the size of your organization, the nature of your services, and the societal impact of your activities may also determine applicability.

For some organizations, the law applies directly. Others may fall outside its scope, for example because they do not operate in a designated sector or do not meet the legal criteria.

The Dutch government has created a useful self-assessment tool to help organizations determine whether they are covered. You can find it here: https://regelhulpenvoorbedrijven.nl/NIS-2-NL/

Why is it still important to assess this?

Even if your organization is not covered by the Cybersecurity Act, this does not mean cybersecurity should be ignored. Cyberattacks do not distinguish between organizations that are and are not subject to legislation.

Many companies depend on digital systems, suppliers, cloud platforms, and customer data. A security incident can therefore also affect organizations outside the scope of the law, resulting in:

  • business disruption;
  • data loss;
  • financial damage;
  • reputational damage;
  • loss of trust among customers and partners.

In addition, organizations that are not directly covered by the Cybersecurity Act may still face stricter security requirements from customers, insurers, or business partners.

A good first step is therefore to determine whether your organization falls under the Cybersecurity Act and what level of security is appropriate for your risk profile.

An independent security assessment or pentest can help with this. Not because every organization is legally required to perform a pentest, but because understanding your actual digital resilience is essential for managing risks effectively.

Conclusion

Articles 71 and 72 of the Cybersecurity Act do not mean that every organization is automatically required to perform a pentest. However, organizations covered by the legislation may face security assessments, audits, and supervision regarding how they manage their cyber risks.

By not waiting until a regulator or attacker tests your security, you remain in control. An independent pentest provides insight into vulnerabilities, identifies where improvements are needed, and helps your organization demonstrate preparedness for the requirements of the Cybersecurity Act.

Cybersecurity does not begin with responding to an incident, but with understanding your risks beforehand. Therefore, test your digital resilience before someone else does.

Need help?

Cybersecurity can be a complex subject, especially when you don't know where or how to begin, or which risks are most important for your organisation. Luckily, you aren't alone in this.

Do you wish to better protect your organisation and gain a better understanding of your cyber risks? Contact us now! Together, we can identify your weak spots and take steps to strengthen your security.

Jeremy Melis
31-07-2026