The Dutch Cybersecurity Act takes effect in 10 days
Your customer sent a security questionnaire. Now what?
Ketenpas is the security passport for Dutch suppliers. You describe the state of your security once, then share it with every customer who asks. No more spreadsheets, no more two days of work per questionnaire.
39 questions · about ten minutes · no account needed
Sound familiar?
Every customer, a different list
Sixty to two hundred questions, in their own format, with a deadline. And the next customer sends something completely different.
Nobody who knows the answer
You have no CISO. The questions are about patch policy and log retention. Your IT provider bills by the hour.
Saying no is not an option
Not filling it in means losing the contract. Your customer carries a duty of care and passes it straight on to you.
Is there one on your desk right now? The guide explains what to do with a customer’s security questionnaire.
Why this landed on your desk
The Cyberbeveiligingswet, the Dutch implementation of the European NIS2 directive, takes effect on 15 August 2026. Large organisations in healthcare, energy, transport and government, among others, must then demonstrably assess the security of their entire supply chain. Their directors are personally liable for it.
They solve that by questioning their suppliers. An estimated 50,000 to 100,000 Dutch companies face these requirements without falling under the law themselves. You are probably one of them. Read whether you have to meet NIS2 as a supplier.
How Ketenpas works
- 1
Take the scan
39 questions in plain language, covering the ten measures the law prescribes. You get a score straight away, plus a list of what is still missing.
- 2
Work through the gaps
Each point tells you what to do and how much work it is. Heaviest and easiest first, so you see results immediately.
- 3
Share your Ketenpas
One shareable page and PDF that you send to every customer instead of filling in their spreadsheet.
The ten topics your customer asks about
Exactly the measures from article 21 of the NIS2 directive. Every customer questionnaire you receive is a variation on these.
- a
Risk analysis and security policy
Your customer wants to see that security is a deliberate choice, not an accident.
- b
Incident handling
If something goes wrong at your end, your customer wants to hear it fast, and to know that you know what you are doing.
- c
Business continuity and backups
With ransomware, your backup is the difference between two days and two months of standstill.
- d
Supply chain security
You are someone's supplier too, and your own suppliers are your risk.
- e
Procurement, development and maintenance
Unpatched software is by far the most used front door in attacks.
- f
Testing effectiveness
Having taken measures is not enough; you have to show that they work.
- g
Cyber hygiene and training
Most incidents start with an employee clicking something.
- h
Cryptography and encryption
A stolen laptop is a data breach the moment the disk is not encrypted.
- i
Personnel, access control and assets
Old accounts of people who have left are a classic way in.
- j
Multi-factor authentication and secure communication
This is the first question on virtually every security questionnaire you will get.
What it costs
The scan is free and stays free. You only pay once a customer questionnaire is on your desk and you would rather not fill it in by hand.
Free
€0
The scan, your score, and one passport to share.
Pro
€39 per month
Have customer questionnaires answered, record your evidence, unlimited passports.
Plus
€99 per month
Multiple entities, your own branding on the passport, an API.
Amounts are per month, excluding VAT. You can cancel monthly. See exactly what each plan includes.
Want to understand where this comes from first?
- Do I have to meet NIS2 as a supplier?
Usually you do not fall under it yourself. But your customer does, and passes the requirements on to you through the contract.
- My customer sent a security questionnaire. Now what?
What such a list is, why it landed on your desk, and how to answer it without losing two days to it.
- When does the Dutch Cybersecurity Act take effect?
The law applies from 15 August 2026. What that means for your customers, and what it means for you through them.
- Which sectors fall under the Dutch Cybersecurity Act?
Eighteen sectors, split into essential and important, with a size threshold. And whoever falls under it questions their suppliers.
- The Dutch Cybersecurity Act is coming. Where do I start as a supplier?
Four steps you can take this month, in order of effect. Most of them cost attention rather than budget.
- What are the ten NIS2 duty of care measures?
Article 21(2) lists ten topics. Every security questionnaire you receive is a translation of them.
- What does NIS2 ask for in risk analysis and security policy?
A policy adopted by the board, a risk assessment from the past year, one responsible person, and a view of your critical systems.
- How does the 24-hour report for a cyber incident work?
The law works with a first report within 24 hours. Your customers pass that deadline on to you in their contracts, and you only make it with a prepared procedure.
- What requirements apply to backups and business continuity?
Automatic backups, at least one copy out of reach of the network, a yearly restore test and a plan to keep working without IT.
- Do I have to assess my own suppliers too?
Yes. The same supply chain duty of care your customer puts on you applies a link further down to you as well.
- What does a customer expect from my patch policy and maintenance?
Updates on a fixed rhythm, an up-to-date inventory, periodic vulnerability scanning, and no more systems without support.
- How do I show that my security actually works?
Not whether measures exist, but whether they do what they are meant to do. Test yearly, record it, and discuss the outcome with the board.
- Is security training mandatory for staff and directors?
For organisations under the law, director training is even an explicit obligation. For everyone: most incidents start with a click.
- What encryption does NIS2 expect from a supplier?
Encrypted laptops and phones, encrypted connections, and encrypted backups. It usually does not have to get more exotic than that.
- What belongs in access control under NIS2?
Access based on what someone needs, withdrawn the same day when they leave, checked yearly, and knowing which equipment sits with whom.
- Is MFA mandatory under NIS2?
The law names multi-factor authentication explicitly. It is the first question on virtually every security questionnaire, and the cheapest one to answer well.
Know where you stand within ten minutes
The scan is free and you do not need an account. Your answers stay in your own browser; we do not store them.
Start the scan