Knowledge base

What ABRO and the Dutch Cybersecurity Act (NIS2) require

The ABRO and the Dutch Cybersecurity Act both set security requirements, but from a different starting point. The ABRO applies to government contracts involving risks to national security and, depending on the protection level, sets concrete security requirements. At certain levels, examinations such as the Elektronisch Veiligheidsonderzoek (EVO) and TEMPEST zoning measurements are explicitly prescribed.

The Dutch Cybersecurity Act, by contrast, places a broader duty of care on organisations that fall under it: they must take appropriate and proportionate technical, operational and organisational measures to secure their network and information systems, with the relevant physical environment playing a part as well. The Act does not explicitly prescribe an EVO; the organisation itself must determine, on the basis of risk, which measures are appropriate.

Two regimes with a different logic

Organisations sometimes mention the ABRO and the Dutch Cybersecurity Act in the same breath. That is understandable, because both touch on board-level responsibility for security. Yet they work from a different logic, and that difference determines what is asked of an organisation in concrete terms.

The ABRO is tied to a contract. It applies to assignments from the Dutch central government or the police that involve risks to national security. If carrying out the work requires access to a formal Protected Interest (Te Beschermen Belang, TBB), it is a Special Assignment and an ABRO declaration is required. The Dutch Cybersecurity Act, by contrast, applies to the organisation itself. An organisation can therefore fall under both regimes, under one of them, or under neither.

The ABRO applies per assignment

The ABRO 2026 has been rolled out in phases across the Dutch central government and the police since 1 January 2026. For a Special Assignment the contractor must hold an ABRO declaration before work begins. The National Industrial Security Office (NBIV) is the point of contact and examines whether the contractor meets the relevant ABRO requirements.

How demanding the measures are depends on the TBB level. The ABRO distinguishes TBB 4 through TBB 1, with TBB 1 the most heavily protected. For classified information these correspond among others to Departementaal Vertrouwelijk (Dep-V), Staatsgeheim Confidentieel (Stg. C), Staatsgeheim Geheim (Stg. G) and Staatsgeheim Zeer Geheim (Stg. ZG). A TBB does not always concern classified information; systems, equipment, goods and objects can constitute a TBB too. Before the procurement process the contracting authority establishes whether a TBB is involved and which security level is required.

Alongside technical measures, the ABRO sets requirements for how the security organisation is set up. The contractor nominates a security officer, draws up a security plan and carries out an annual self-inspection. The security plan must be approved by the highest governing body and endorsed by the NBIV. The annual review of the plan and measures is reported in writing with a copy to the NBIV. Changes affecting the security measures require NBIV approval.

Where the ABRO names the electronic security survey

Chapter 3 of the ABRO contains the requirements for physical security. A compartment is defined there as a designated, secured and lockable physical environment in which one or more TBBs are processed or stored. That can be a room, a floor, a building, a factory hall or an outdoor site.

Secured door with an access reader in an office environment
Under the ABRO a compartment is a designated, secured and lockable physical environment. Which electronics may be taken inside follows from a risk analysis.

Concrete restrictions apply to electronic equipment. Only equipment strictly necessary for the work may be present in a compartment; its admission must be based on a risk analysis. Non-essential electronics are kept outside the compartment. Cameras, smart devices, microphones and other equipment with recording or communication functions are not permitted.

Then comes the requirement that matters for the electronic security survey. ABRO requirement 3.3.31 stipulates that before a compartment is taken into use, and whenever resources are added or changed, an Elektronisch Veiligheidsonderzoek (EVO) and a sound attenuation measurement must have been carried out in coordination with the NBIV. Any measures are agreed with the NBIV before implementation. According to the ABRO table, this requirement applies to TBB 2 and TBB 1.

The ABRO defines an EVO as an investigation into the potential presence of unwanted equipment in a compartment. The ABRO ties the examination to events rather than to a standard periodic interval: taking a compartment into use, and adding or changing resources.

What that means for when you engage us

Our sweep is not a formal accreditation. We sit earlier in the process: before a room is formally assessed, we map what is present, which technical risks are relevant and what has to be explainable about cabling, equipment and fittings.

That gives you time to resolve findings, take measures or substantiate choices before they become part of a formal process. You do not walk into the assessment blind.

We do not make statements on behalf of the NBIV. What we do deliver is a methodically substantiated picture, with a threat profile and scope established in advance, explicit examination criteria and a clear description of findings, limitations and residual risk. That removes a good deal of uncertainty from a process that is often complex and tense. We surface sticking points early and help you go through accreditation more efficiently and better prepared.

The Cybersecurity Act asks a different question

The Dutch Cybersecurity Act has been in force since 15 August 2026 and implements the European NIS2 Directive in the Netherlands. Organisations that fall under it are subject to a registration duty, a duty of care and a duty to report significant incidents, among other obligations.

For our practice the duty of care is the relevant part. It asks organisations to take appropriate and proportionate measures against risks to their network and information systems. Digital security is not the only thing that counts: the physical environment in which those systems are located is part of the risk assessment as well.

Unlike the ABRO, the Cybersecurity Act prescribes no EVO or sweep. The organisation itself must substantiate which risks are relevant, which measures fit them and how their effectiveness is assessed. In practice, organisations have their physical resilience tested by red teams, for example; the Cybersecurity Act does not require such a test, but it does ask organisations to map their own risks and take appropriate measures.

That same risk-driven reasoning can be applied to counter-espionage and to other ways in which sensitive information can leave a room. Where the threat picture gives cause, it is logical to examine not only whether someone can enter a building, but also whether sensitive information can be intercepted from within the secured environment. That is precisely where technical counter-espionage examination can add value.

What the Cybersecurity Act does not prescribe

The Cybersecurity Act does not oblige you to have a room examined for eavesdropping devices at regular intervals, but it does ask you to manage risks demonstrably.

If sensitive information about critical systems, incidents, vulnerabilities or operations is routinely discussed in a particular room, that room can become part of your risk picture too. A technical examination can then substantiate which risks were actually examined there and which uncertainties remain. That is the difference between being able to name a measure and being able to explain why you took it.

Where the ABRO and the Cybersecurity Act meet

For organisations dealing with both frameworks, the two lines ultimately converge on the same question: can you substantiate why your security measures are appropriate, and on what that judgement is based?

A good examination report helps there. It records not only an outcome but also the threat profile, the scope, the methodology applied, the findings and the limits of the examination.

Such a report can therefore serve in more than one accountability line: as technical substantiation within an ABRO process and as a record of a risk-driven security measure under the Cybersecurity Act.

A report stating only that a room is ‘clean’ does not provide that substantiation. That is why we record in advance what is being examined for, and let those starting points return in the reporting.

Not a tick-box, but substantiation

What the two regimes have in common ultimately matters more than what separates them: security measures have to be defensible.

The ABRO achieves that in places through concrete requirements and protection levels. The Cybersecurity Act places more responsibility on the organisation to choose appropriate and proportionate measures on the basis of risk.

Our work sits exactly between the two: making visible which technical risks are relevant, examining what can demonstrably be established, and recording what your security choices are based on.

What you cannot infer from this

This page describes how we read the two frameworks. It is not legal advice. Whether the ABRO applies to your assignment, and at which level, is established by the contracting authority; the NBIV is the point of contact for what that means in practice. Whether your organisation falls under the Dutch Cybersecurity Act, and which measures are appropriate and proportionate in your case, is for you to determine, in consultation with your own advisers and the supervisory authority for your sector.

Sources

  1. Ministry of Justice and Security. Algemene Beveiligingseisen voor Rijksoverheidsopdrachten 2026 (ABRO). The Hague, 2026. Chapter 1 (security organisation and subcontracting) and chapter 3 (physical security, requirements 3.3.27 to 3.3.33).
  2. National Cyber Security Centre. “Cyberbeveiligingswet (NIS2).” Accessed 18 August 2026.
  3. National Cyber Security Centre. Infosheet Cyberbeveiligingswet: zorgplicht. September 2025 version.
  4. European Parliament and Council. Directive (EU) 2022/2555 (NIS2). Official Journal of the European Union, 27 December 2022.
  5. “Inbreken tegen betaling populair door nieuwe beveiligingswetten.” NOS Nieuwsuur, 15 August 2026. On the rise of physical red teaming following the new security legislation.

Frequently asked questions

Does the Cybersecurity Act require a sweep?

No. The Cybersecurity Act prescribes no sweep, frequency or specific examination method. It requires you to take appropriate and proportionate measures on the basis of a risk analysis. That includes the physical environment of the network and information systems to be protected. Whether technical examination is an appropriate measure in your situation follows from your own risk assessment.

My assignment concerns Departementaal Vertrouwelijk material. Does requirement 3.3.31 apply?

No. In the ABRO 2026, requirement 3.3.31 applies to TBB 2 (Staatsgeheim Geheim) and TBB 1 (Staatsgeheim Zeer Geheim), not to TBB 4/Dep-V or TBB 3/Staatsgeheim Confidentieel. At Dep-V level an EVO is therefore not mandatory under this specific requirement. Technical examination can of course still follow from the threat picture or your own risk assessment.

Does the electronic security survey have to be repeated periodically?

For requirement 3.3.31 the ABRO names no fixed interval. The EVO is tied to concrete moments: before a compartment is taken into use, and whenever resources are added or changed. Whether additional periodic examination is sensible follows from the threat picture, changes in the environment and your own risk assessment.

Does the ABRO apply to my subcontractors as well?

Yes, when they carry out work that brings them into contact with a Protected Interest. Subcontracting must be approved in advance and the applicable ABRO requirements are passed on contractually; the main contractor remains responsible for compliance by its subcontractors. How this is arranged for your assignment is agreed with the contracting authority and the NBIV.

Read more about our ABRO support.

Written by · Published , revised