Your CMDB is in good shape. Every laptop, server and licence is recorded, linked to an owner and a lifecycle. The conclusion seems obvious: on asset inventory, your organisation is covered. Once operational technology counts towards your Cbw scope, the conclusion no longer holds.
The Cyberbeveiligingswet (Cbw), the Dutch implementation of NIS2, was passed by the Senate on 7 July 2026 and enters into force on 15 August 2026. The registration obligation applies from that same date. What many organisations have not yet worked through: the Cbw duty of care under article 21 cannot be split into an IT part and an OT part. The law looks at the entity as a whole.
Demonstrable operation under the Cbw, not policy on paper
Article 21 requires measures that demonstrably work. A procedure sitting in a document management system is not evidence. A log showing that monitoring runs day and night is.
To make this auditable, auditors assess controls on a maturity scale from Level 1 through Level 5. Two controls are decisive here:
4.2 monitoring and logging (Cbw art. 21.3.b, Cbb art. 8.3 through 8.6)
12.2 Asset inventory (Cbw art. 21.3.i, Cbb art. 16.4)
At Level 1, monitoring and logging amounts to the absence of structured log management. For asset inventory, Level 1 means no inventory is available and visibility into the environment is missing. Level 3 requires a largely complete inventory and approach. Level 4 demands a complete and current picture.
Note the word complete. That is where the problem sits.
These controls apply to your full Cbw scope
Control 12.2 does not ask for a complete IT inventory. It asks for a complete inventory. If your production network holds five hundred PLCs, HMIs, sensors and engineering workstations that appear in no register, the inventory is demonstrably incomplete. However well the office side is organised.
The same applies to control 4.2. If your central monitoring sees every Windows endpoint but nothing of the Modbus or OPC UA traffic on the production floor, log management is not structured across the full environment.
This does not mean an organisation without OT visibility automatically lands at Level 1. That would be inaccurate where the IT side is genuinely well run. What happens instead is a ceiling effect: the score is bounded by the weakest part of the scope. The larger and more critical the OT environment relative to the rest of the organisation, the lower that ceiling sits.
For a manufacturer or a water authority, that ceiling is realistically a 2. Even with an exemplary IT operation.
Why this weighs more heavily in OT-intensive sectors
In an office organisation with a handful of smart building systems, the OT component is small and the ceiling effect stays limited. For readers wondering how this plays out for building services, there is more context in our piece on BMS cybersecurity.
In manufacturing, energy, water and transport the balance is different. The majority of business-critical technology sits in the OT layer. A logistics operator with automated warehouse systems, a drinking water company with SCADA-controlled pumping stations, a factory running a Siemens S7 estate: for these organisations, operational technology represents the largest share of actual risk surface. Around 90% of OT networks contain outdated assets, which makes the inventory problem particularly persistent in these sectors.
For sector-specific context: OT cybersecurity for manufacturing, cybersecurity for municipalities, OT security for transport and logistics and critical infrastructure cybersecurity.
These environments are often decades old, with equipment that cannot carry an agent and networks where an active scan brings a real risk of disruption. Conventional IT tooling is not usable here. That is precisely why the OT side was never included in the inventory at many organisations.
What is achievable
Continuous, passive OT monitoring produces the kind of ongoing operational evidence the duty of care calls for. By reading from a SPAN port or TAP, all network traffic is analysed without a single packet entering the production network. No agents, no active scans, no risk of disrupting running processes.
That speaks directly to controls 12.2 and 4.2:
- A current asset inventory. Every communicating device becomes visible, including type, protocol and firmware version. Not as a snapshot, but continuously updated. What a good inventory actually looks like is set out in OT asset visibility.
- Demonstrable 24×7 monitoring. Continuous recording of what happens on the OT network, including anomalous behaviour, with a history that serves as evidence.
Nautilus 24×7 monitoring supplies the underlying evidence your organisation and its auditor can draw on when assessing maturity. The Nautilus OT solution is hosted entirely within the EU and delivers first asset visibility within hours of activation. What Nautilus does not provide is a maturity score or a certification. Neither exists under the Cbw. The judgement on your maturity level rests with your organisation and with your auditor or supervisory authority.
The date is fixed
The Cbw takes effect on 15 August 2026. Organisations taking the duty of care seriously would do well to establish now how large the OT portion of their scope really is. That question often proves harder to answer than expected, and that fact is informative in itself.
Want to know where you stand? The free NIS2 compliance check gives a first indication in two minutes. Prefer to talk through your OT scope directly? Get in touch with one of our specialists.