Security & compliance

NIS2 and cybersecurity for SMEs: security you can prove.

The Dutch NIS2 act has been in force since August 15, 2026, with no transition period. We make websites, apps and software provably secure: quick scan, hardening, MFA, backups and a penetration test through a certified partner.

What we do

Cybersecurity for SMEs: from duty of care to evidence

Since August 15, 2026 the Cyberbeveiligingswet, the Dutch implementation of NIS2, has been in force. Around 8,000 organizations fall under it directly, but the real impact is in the supply chain: tens of thousands of SME suppliers have to prove to their customers that their security is in order. Two thirds of Dutch SMEs still have no security policy. Half do not use MFA.

We start with a quick scan against the 10 duty-of-care measures: risk analysis, incident handling, backups, access management, encryption, suppliers, patching and more. You get a report your board can read and that answers your customer’s questionnaire. Then we fix things: hardening of servers and applications, MFA and SSO, logging and an incident playbook for the 24-hour reporting duty.

For software products the Cyber Resilience Act comes on top: SBOM, vulnerability management and an update process. Because we build software ourselves, we know how to set that up without slowing down development. Honest about the boundary: certified penetration tests are carried out by a partner. We fix what they find.

Deploy Plate 13 · SECURITY & COMPLIANCE
  • 1–6 weeks from quick scan to hardening
  • 10 duty-of-care measures assessed
  • 24 hour reporting duty: playbook ready
  • ASVS OWASP standard as the yardstick

Components

8 components

What you get.

01

NIS2 quick scan & supplier readiness

Assessment against the 10 duty-of-care measures of the Dutch NIS2 act, with a report that answers your customers’ questionnaire.

02

Penetration testing via certified partner

Web application, API or mobile app tested by a certified partner. We prepare, fix the findings and arrange the retest.

03

Security audit & hardening

OWASP ASVS as the yardstick: headers, sessions, input, dependencies, WAF and server configuration. Every item fixed and documented.

04

GDPR compliance for websites & apps

A cookie banner that actually complies, data processing agreements, a DPIA where needed and data minimization in the design. No fines for carelessness.

05

Cyber Resilience Act for software

SBOM in CycloneDX, vulnerability management, secure updates and a reporting procedure. Mandatory for products with digital elements.

06

MFA, SSO & identity

Entra ID or Keycloak for 1 login across all your systems, with MFA for everyone. The measure with the biggest effect per euro.

07

Backup, DR & incident plan

Encrypted backups, tested recovery times and a playbook that fits the 24-hour reporting duty. Who calls whom, and what you say.

08

Security awareness (partner)

Phishing simulations and staff training through a specialized partner. Technology does not help if someone hands over the password.

Delivered

  • NIS2 quick scan report
  • Risk analysis & register of measures
  • Hardening report (OWASP ASVS)
  • MFA/SSO setup
  • Backup & recovery plan
  • Incident playbook (24-hour reporting duty)
  • Security policy & supplier assessment
  • Pentest report & retest (partner)
  • SBOM & CRA documentation
  • GDPR processing register & cookie policy

How we work

→ Process

How an engagement runs.

  1. 01

    Quick scan

    Week 1: interviews, configuration review and a scan of your public attack surface. Assessed against the 10 duty-of-care measures and OWASP.

  2. 02

    Report & priorities

    Findings ranked by severity and effort, in language the board understands. With a schedule: what this week, what this quarter.

  3. 03

    Hardening

    Servers, applications, access and backups put in order. Every measure is recorded as evidence for customers, insurers and regulators.

  4. 04

    Pentest & retest

    A certified partner tests what we hardened. We fix the findings, the partner tests again. You get both reports.

  5. 05

    Policy & assurance

    Security policy, incident playbook and supplier assessment. Then periodic review, because last year’s audit proves nothing.

Why RABZI

Why RABZI for this work.

01

We fix what we find

We build websites, apps and software ourselves. A finding is not a ticket for someone else, but a fix we ship.

02

Honest about the boundary

We do not run certified penetration tests ourselves. A certified partner does, and we make sure the findings disappear.

03

Reports your customer accepts

You get evidence in the form procurement teams and insurers ask for: measure, date, owner, status.

04

Designed around the law

NIS2, the Cyber Resilience Act, GDPR and NCSC guidelines are our checklist. Not loose tips, but a system you can demonstrate.

05

Fixed price, fixed scope

Quick scan, hardening and CRA readiness each have a fixed price. You know up front what you get and what it costs.

Pricing

→ Pricing

Pricing for security & compliance.

Fixed prices, excl. VAT. Extra work only after approval.

Launch from€1,250

One clear goal, sharply executed. The entry level you keep building on.

  • NIS2 quick scan or security audit
  • Risk overview
  • Priority list
  • Board presentation
  • Recommendations
Request a quote
Flagship from€12,500

For platforms, multiple brands or markets, and projects where nothing is standard.

  • Penetration test via certified partner
  • Remediation
  • CRA readiness
  • Incident response plan
  • Annual retest
Request a quote

Work

→ All work

Relevant work

Portal · −38% · WCAG AA · NEN 7510 · 61% Plate 01 · PORTAL

Illustrative casePhysiotherapy group (4 practices), Gelderland · 2026

Patient portal with online booking and e-consult

−38% phone calls at the front desk

Onboarding · 12 min · −71% · DORA · 14 wks Plate 02 · ONBOARDING

Illustrative caseFintech scale-up, Amsterdam · 2026

Digital KYC onboarding with iDIN and AML screening

12 min average onboarding (was 3 days)

Deploy · 99.98% · −41% · 0 · 8 wks Plate 03 · DEPLOY

Illustrative caseSaaS scale-up, Utrecht · 2025

Cloud migration to EU hosting with CI/CD and monitoring

99.98% uptime in the first 9 months

Frequently asked questions

Questions about security & compliance.

01How much does a NIS2 quick scan or security audit cost?

A NIS2 quick scan or security audit of a website or application starts at RABZI from €1,250 excl. VAT. Growth (from €4,950) includes hardening, policies and MFA/SSO setup. Flagship (from €12,500) adds a penetration test through a certified partner, remediation of the findings and CRA documentation. Every step has a fixed price, so security never becomes an open-ended project.

02Does NIS2 apply to my SME?

Directly only if you operate in a designated sector and exceed the threshold of 50 employees or €10 million in revenue. Indirectly it applies to many more companies: organizations covered by the law must assess their suppliers. If you supply software, IT services, logistics or components to such an organization, you will receive their questionnaire. A quick scan gives you a substantiated answer.

03What is a penetration test and what does it cost?

In a penetration test an ethical hacker tries, under controlled conditions, to break into your application, API or app, and reports what worked. We have pentests carried out by a certified partner, because independence matters here. Expect €3,000 to €15,000 depending on scope. We prepare, fix the findings and arrange the retest.

04What is the Cyber Resilience Act and do I need to comply?

The CRA applies to products with digital elements: software, apps, IoT and related services you bring to market. Since September 11, 2026 the reporting duty for actively exploited vulnerabilities applies; the full obligations follow on December 11, 2027. Think security by design, an SBOM, vulnerability management and updates throughout the product’s lifetime. If you build software for customers, it affects you.

05What does GDPR compliance mean for my website?

At minimum: a cookie banner that genuinely asks for consent before anything is measured, a privacy statement that is accurate, data processing agreements with your suppliers and security that matches the sensitivity of the data. If you process special categories of data, for example in healthcare, a DPIA is required. We handle the technical part and work with your legal counsel on the rest.

06Can you secure a website you did not build?

Yes. We start with an audit of the code, the hosting and the access, and deliver a report with concrete measures. What we can fix, we fix. What is structurally wrong, we name honestly, including whether a rebuild is cheaper than a repair. For ongoing management there is our Care plan.

Related services

Knowledge

→ All articles

Keep reading

Reply < 1 business day · Available for new projects

Make your security something you can prove.

Request a NIS2 quick scan or send us your customer’s questionnaire. Within 1 business day we reply with an approach and a fixed price.

info@rabzi.nl · ...