How NIS2-ready are Dutch SME suppliers? Data from the CBS Cybersecurity Monitor 2025
Since NIS2 took effect, more and more CSRD- and NIS2-obligated buyers are asking their critical suppliers for a cybersecurity assessment — Art. 21(2)(d) requires it. But how realistic is that request? How far along is the average Dutch SME with the baseline measures NIS2 expects? This article is specifically about the Netherlands: the data below covers Dutch businesses, which matters if you're sourcing from Dutch suppliers or benchmarking a Dutch subsidiary.
Statistics Netherlands (CBS) publishes the Cybersecurity Monitor annually — now in its ninth edition — based on a representative sample of Dutch businesses with 2 to 250 employees. This article summarises the figures most relevant to supplier assessment, with a source for every number.
The gap between large and small
The clearest pattern in the 2025 Cybersecurity Monitor is the gap by company size. Among large businesses (250+ employees), 86% have implemented ten or more of the twelve measures surveyed. Among micro-businesses (2-10 employees) that figure is just 13% — and 40% of this group has three or fewer measures in place.
That gap varies sharply by sector: in financial services, more than half of businesses have a comprehensive set of measures, versus just 7% in hospitality.
For buyers assessing suppliers across different sectors, this has a concrete implication: assuming "small suppliers are probably fine" is not statistically defensible. The spread within the SME segment is wide enough that a structured, per-supplier assessment carries more weight than a sector-wide assumption.
The figures by NIS2-relevant theme
NIS2 Art. 21 works with ten CY assessment areas (see our NIS2 supply chain assessment step-by-step guide for the full list). The CBS figures don't measure NIS2 compliance directly, but the underlying measures map closely onto several CY themes:
Risk management (comparable to CY1) — only 29% of Dutch SMEs carry out a formal risk analysis of critical business assets.
Cyber hygiene and training (comparable to CY7) — fewer than 9% of Dutch SMEs require mandatory ICT security training for staff.
Access management (comparable to CY9) — on average, 61% of Dutch SMEs (2-250 employees) use multi-factor authentication; among businesses with 10-50 employees this rises to 79%, versus 97% for large businesses.
Cryptography (comparable to CY8) — data encryption is used by roughly a third of micro-businesses, versus 91% of large businesses.
Business continuity (comparable to CY3) — 66% keep a backup at a different physical location; 71% have a formal password policy.
Baseline measures such as antivirus software are, by contrast, widely covered: 85% of all businesses use it regardless of size — there's barely a gap here.
One in five small SMEs takes no measures at all
A further signal comes from the Alert Online campaign run by the Dutch Ministry of Economic Affairs (via the Digital Trust Center, September 2025): among small SMEs (fewer than 10 employees), 1 in 5 takes no security measures whatsoever — not "insufficient," but zero.
At the same time, the 2025 Cybersecurity Monitor reports that the share of businesses affected by a cyber incident in 2024 fell to its lowest level in nine years (4%) — though phishing and spoofing, at 23%, remains by far the most common threat, and the incident rate among large businesses (16%) is actually higher, consistent with their larger attack surface and visibility as a target.
What does this mean for suppliers and buyers?
For suppliers: if a client asks for a NIS2 assessment, these figures suggest you're certainly not the only one without every basic measure in place — but that doesn't make the request less relevant. The themes where Dutch SMEs score weakest on average (risk analysis, mandatory training) are exactly the ones a half-page policy document can meaningfully improve.
For buyers: this spread is precisely why suppliers shouldn't be assessed on trust, but with a structured questionnaire across the same ten CY themes. Use our free supplier assessment scorecard for a quick first read, or the full NIS2 supply chain assessment for an audit-ready review.
Methodology & sources
The figures in this article come from the CBS Cybersecurity Monitor 2025 (ninth edition), based on a sample of Dutch businesses with 2 to 250 employees, published by Statistics Netherlands (CBS) in collaboration with the National Cyber Security Centre (NCSC). Additional figures on small SMEs (<10 employees) come from the Alert Online 2025 campaign run by the Ministry of Economic Affairs via the Digital Trust Center.
The CBS figures measure general cybersecurity measures, not NIS2 compliance as such — the mapping onto the ten CY assessment areas in this article is verified.supply's own interpretation, not an official classification by CBS or the NCSC. Use these figures as context, not as a substitute for your own supplier assessment.
Frequently asked questions
- How many Dutch SMEs have their cybersecurity in order?
- According to the CBS Cybersecurity Monitor 2025, only 13% of micro-businesses (2-10 employees) have implemented ten or more of the twelve measures surveyed, versus 86% of large businesses (250+ employees). 40% of micro-businesses have three or fewer measures in place.
- What is the source of these NIS2-related figures?
- The figures come from the CBS Cybersecurity Monitor 2025 (Statistics Netherlands, ninth edition) and the Ministry of Economic Affairs' Alert Online 2025 campaign. CBS measures general cybersecurity measures among Dutch businesses, not NIS2 compliance directly.
- How many SMEs use multi-factor authentication?
- On average, 61% of Dutch SMEs (2-250 employees), according to the CBS Cybersecurity Monitor 2025. Among businesses with 10-50 employees this rises to 79%, versus 97% for large businesses (250+ employees).
- Why should I assess suppliers individually instead of relying on their sector or size?
- The CBS figures show wide variation: more than half of financial services businesses have a comprehensive set of measures, versus just 7% in hospitality. Assuming based on sector or company size is therefore unreliable — a structured, per-supplier assessment, for example with our free scorecard, gives a more reliable picture.
Read also
Build your VS profile (formerly VSME) once
Create an account and get started today.
No password needed — we email you a login link.