Risk Analysis in Accordance with the Cybersecurity Act (Cbw)

CBW Risk Analysis

Demonstrate that you are fulfilling your duty of care and avoid penalties of up to €10 million.

The Cybersecurity Act (Cbw) transposes the European NIS2 Directive into Dutch law and has been in effect since August 15, 2026. Article 21 requires essential and important entities to conduct a documented risk analysis as the basis for their duty of care. Without an up-to-date risk analysis, your security policy does not legally exist, resulting in administrative liability and penalties. OneXillium systematically maps out your risks and compliance gaps.

A legal foundation as a starting point. We don’t just assess technical risks; we assess them directly against the requirements of Article 21 of the Cbw, ensuring that your risk analysis is legally sound.
Proven methodology. We combine the international CIS18 standard with a maturity model based on ISO/NEN, ensuring that the results are objective and comparable.
From risk to a concrete action plan. You won’t receive a theoretical list of risks, but rather a prioritized advisory report with concrete improvement measures to help you fulfill your duty of care.
Verifiable to regulatory authorities. The final report serves as evidence for regulatory authorities, auditors, and cyber insurers that you are fulfilling your legal obligation.
Supply chain risks included. We also take supplier and supply chain risks into account, which is a specific area of focus under the Cbw.
Trusted by
OneXillium - logo-officegrip-300
OneXillium - logo-edge-300
OneXillium - logo-sprague-europe-300
OneXillium - logo-amari-holdings-bv-300
OneXillium - logo-alert-group-300
OneXillium - logo-side-window-300
OneXillium - logo-vb-airsuspension
OneXillium - logo-tck-sports-300
Certifications
OneXillium - ISO/CCV Certifications

Schedule a no-obligation consultation

The Benefits for Your Organization

Demonstrate compliance with the duty of care

A documented risk analysis is the legal basis for Article 21 of the Cbw. Without this foundation, your security policy does not legally exist, and you run the risk of penalties of up to €10 million or 2% of your global annual revenue. 

Avoid Administrative Liability

Under Article 24 of the Working Conditions Act (Cbw), directors bear ultimate personal responsibility for the duty of care. An up-to-date risk analysis demonstrates that the board has fulfilled its legal obligation and limits the risk of personal liability in cases of gross negligence. 

Strategic insight, not just a random list

You’ll receive a prioritized analysis based on impact and likelihood, including specific improvement measures. This allows you to make informed decisions about investments and policies rather than taking ad hoc measures. 

From Legal Obligation to Concrete Action Plan

Our Approach
Risk Assessment Based on Article 21 of the Cbw

We are bringing you current security measures into assess and assess these to the ten categories of duty of care from Article 21 of the Cbw, supplemented by a maturity model based on ISO/NEN. 

Advisory Report with Priorities and Rationale

Based on the CIS18 framework identify we missing measures and translate we these into a concrete advisory report: risk priorities, practical recommendations and the rationale you’ll need to toward regulatory authorities, auditors and cyber insurers. 

OneXillium - onexillium-26-min-1-11sun
OneXillium - Example 7

Frequently Asked Questions About Cbw Risk Analysis

Our specialists have compiled a list of frequently asked questions for you. If your question isn't listed here, please contact us.

ISO 27001 certification is not legally required under the Cbw, but it does provide a strong foundation. Many measures outlined in the standard, such as access control and incident response, align with the duty of care. However, it is not automatically sufficient. The Cbw also sets requirements that fall outside the scope of ISO 27001, such as strict reporting deadlines for incidents and direct administrative responsibility. We therefore assess whether your existing risk analysis and policies already cover these CBW-specific elements, or whether targeted additions are needed.

The Cbw does not prescribe a fixed timeframe, but it does require that your risk analysis remain up to date. In practice, this essentially means: reviewing it at least once a year, and immediately in the event of significant changes such as new systems, suppliers, or threats. Regulators do not merely check whether a risk analysis was ever prepared, but also whether it is updated periodically.

Regulators may impose fines of up to €10 million or 2% of global annual revenue. In addition, under Article 24 of the Cbw, the board of directors bears personal ultimate responsibility, which may result in director liability in cases of gross negligence.

For critical and important entities as defined in the NIS2 Directive: these include, among others, digital infrastructure providers, energy and water utilities, healthcare providers, government agencies, financial institutions, and certain ICT service providers above a certain threshold.

In practice, these two terms are often used interchangeably. The law refers to a “risk analysis”: the process of identifying threats and vulnerabilities. A “gap analysis” focuses on the difference between your current situation and the requirements of the Cbw. We combine both: we identify risks and pinpoint exactly where you are not yet compliant.

Yes. Article 21(3)(a) of the Cbw requires essential and important entities to have a risk analysis policy as part of their duty of care. Without this risk analysis, you cannot demonstrate that you are in compliance with the law.

Stay on Top of Your Duty of Care Before Things Go Wrong
Avoid penalties and administrative liability. Our Cbw risk analysis identifies your risks and compliance gaps and provides a concrete action plan. Ready to get started? Fill out the form, and we’ll contact you shortly.

Accept advertising cookies to view this content.

Accept advertising cookies

Would you like to learn more about Managed Services?

Let our specialists help you

Does this sound familiar in your situation? Would you like to learn more about how to optimize, make more sustainable, and secure your business processes related to printing and scanning? Get in touch and let our specialists help you set up these processes to be future-proof.