Patient portal with online booking and e-consult
−38% phone calls at the front desk
Security & compliance
The Dutch NIS2 act has been in force since August 15, 2026, with no transition period. We make websites, apps and software provably secure: quick scan, hardening, MFA, backups and a penetration test through a certified partner.
— What we do
Since August 15, 2026 the Cyberbeveiligingswet, the Dutch implementation of NIS2, has been in force. Around 8,000 organizations fall under it directly, but the real impact is in the supply chain: tens of thousands of SME suppliers have to prove to their customers that their security is in order. Two thirds of Dutch SMEs still have no security policy. Half do not use MFA.
We start with a quick scan against the 10 duty-of-care measures: risk analysis, incident handling, backups, access management, encryption, suppliers, patching and more. You get a report your board can read and that answers your customer’s questionnaire. Then we fix things: hardening of servers and applications, MFA and SSO, logging and an incident playbook for the 24-hour reporting duty.
For software products the Cyber Resilience Act comes on top: SBOM, vulnerability management and an update process. Because we build software ourselves, we know how to set that up without slowing down development. Honest about the boundary: certified penetration tests are carried out by a partner. We fix what they find.
— Components
Assessment against the 10 duty-of-care measures of the Dutch NIS2 act, with a report that answers your customers’ questionnaire.
Web application, API or mobile app tested by a certified partner. We prepare, fix the findings and arrange the retest.
OWASP ASVS as the yardstick: headers, sessions, input, dependencies, WAF and server configuration. Every item fixed and documented.
A cookie banner that actually complies, data processing agreements, a DPIA where needed and data minimization in the design. No fines for carelessness.
SBOM in CycloneDX, vulnerability management, secure updates and a reporting procedure. Mandatory for products with digital elements.
Entra ID or Keycloak for 1 login across all your systems, with MFA for everyone. The measure with the biggest effect per euro.
Encrypted backups, tested recovery times and a playbook that fits the 24-hour reporting duty. Who calls whom, and what you say.
Phishing simulations and staff training through a specialized partner. Technology does not help if someone hands over the password.
Delivered
— How we work
Week 1: interviews, configuration review and a scan of your public attack surface. Assessed against the 10 duty-of-care measures and OWASP.
Findings ranked by severity and effort, in language the board understands. With a schedule: what this week, what this quarter.
Servers, applications, access and backups put in order. Every measure is recorded as evidence for customers, insurers and regulators.
A certified partner tests what we hardened. We fix the findings, the partner tests again. You get both reports.
Security policy, incident playbook and supplier assessment. Then periodic review, because last year’s audit proves nothing.
— Why RABZI
We build websites, apps and software ourselves. A finding is not a ticket for someone else, but a fix we ship.
We do not run certified penetration tests ourselves. A certified partner does, and we make sure the findings disappear.
You get evidence in the form procurement teams and insurers ask for: measure, date, owner, status.
NIS2, the Cyber Resilience Act, GDPR and NCSC guidelines are our checklist. Not loose tips, but a system you can demonstrate.
Quick scan, hardening and CRA readiness each have a fixed price. You know up front what you get and what it costs.
— Pricing
Fixed prices, excl. VAT. Extra work only after approval.
One clear goal, sharply executed. The entry level you keep building on.
More scope, more result. The level we recommend once multiple systems or teams are involved.
For platforms, multiple brands or markets, and projects where nothing is standard.
— Work
−38% phone calls at the front desk
12 min average onboarding (was 3 days)
99.98% uptime in the first 9 months
— Frequently asked questions
A NIS2 quick scan or security audit of a website or application starts at RABZI from €1,250 excl. VAT. Growth (from €4,950) includes hardening, policies and MFA/SSO setup. Flagship (from €12,500) adds a penetration test through a certified partner, remediation of the findings and CRA documentation. Every step has a fixed price, so security never becomes an open-ended project.
Directly only if you operate in a designated sector and exceed the threshold of 50 employees or €10 million in revenue. Indirectly it applies to many more companies: organizations covered by the law must assess their suppliers. If you supply software, IT services, logistics or components to such an organization, you will receive their questionnaire. A quick scan gives you a substantiated answer.
In a penetration test an ethical hacker tries, under controlled conditions, to break into your application, API or app, and reports what worked. We have pentests carried out by a certified partner, because independence matters here. Expect €3,000 to €15,000 depending on scope. We prepare, fix the findings and arrange the retest.
The CRA applies to products with digital elements: software, apps, IoT and related services you bring to market. Since September 11, 2026 the reporting duty for actively exploited vulnerabilities applies; the full obligations follow on December 11, 2027. Think security by design, an SBOM, vulnerability management and updates throughout the product’s lifetime. If you build software for customers, it affects you.
At minimum: a cookie banner that genuinely asks for consent before anything is measured, a privacy statement that is accurate, data processing agreements with your suppliers and security that matches the sensitivity of the data. If you process special categories of data, for example in healthcare, a DPIA is required. We handle the technical part and work with your legal counsel on the rest.
Yes. We start with an audit of the code, the hosting and the access, and deliver a report with concrete measures. What we can fix, we fix. What is structurally wrong, we name honestly, including whether a rebuild is cheaper than a repair. For ongoing management there is our Care plan.
Also for your industry
Related services
— Knowledge
Reply < 1 business day · Available for new projects
Request a NIS2 quick scan or send us your customer’s questionnaire. Within 1 business day we reply with an approach and a fixed price.