CBW Risk Analysis
Demonstrate that you are fulfilling your duty of care and avoid penalties of up to €10 million.
The Cybersecurity Act (Cbw) transposes the European NIS2 Directive into Dutch law and has been in effect since August 15, 2026. Article 21 requires essential and important entities to conduct a documented risk analysis as the basis for their duty of care. Without an up-to-date risk analysis, your security policy does not legally exist, resulting in administrative liability and penalties. OneXillium systematically maps out your risks and compliance gaps.

Schedule a no-obligation consultation
The Benefits for Your Organization
From Legal Obligation to Concrete Action Plan

Frequently Asked Questions About Cbw Risk Analysis
Our specialists have compiled a list of frequently asked questions for you. If your question isn't listed here, please contact us.
ISO 27001 certification is not legally required under the Cbw, but it does provide a strong foundation. Many measures outlined in the standard, such as access control and incident response, align with the duty of care. However, it is not automatically sufficient. The Cbw also sets requirements that fall outside the scope of ISO 27001, such as strict reporting deadlines for incidents and direct administrative responsibility. We therefore assess whether your existing risk analysis and policies already cover these CBW-specific elements, or whether targeted additions are needed.
The Cbw does not prescribe a fixed timeframe, but it does require that your risk analysis remain up to date. In practice, this essentially means: reviewing it at least once a year, and immediately in the event of significant changes such as new systems, suppliers, or threats. Regulators do not merely check whether a risk analysis was ever prepared, but also whether it is updated periodically.
Regulators may impose fines of up to €10 million or 2% of global annual revenue. In addition, under Article 24 of the Cbw, the board of directors bears personal ultimate responsibility, which may result in director liability in cases of gross negligence.
For critical and important entities as defined in the NIS2 Directive: these include, among others, digital infrastructure providers, energy and water utilities, healthcare providers, government agencies, financial institutions, and certain ICT service providers above a certain threshold.
In practice, these two terms are often used interchangeably. The law refers to a “risk analysis”: the process of identifying threats and vulnerabilities. A “gap analysis” focuses on the difference between your current situation and the requirements of the Cbw. We combine both: we identify risks and pinpoint exactly where you are not yet compliant.
Yes. Article 21(3)(a) of the Cbw requires essential and important entities to have a risk analysis policy as part of their duty of care. Without this risk analysis, you cannot demonstrate that you are in compliance with the law.
Would you like to learn more about Managed Services?
Does this sound familiar in your situation? Would you like to learn more about how to optimize, make more sustainable, and secure your business processes related to printing and scanning? Get in touch and let our specialists help you set up these processes to be future-proof.







