Standards & frameworks
NCSC (beveiligingsadviezen)
The Dutch National Cyber Security Centre is part of the Ministry of Justice and Security and serves central government and providers of essential services, as well as organisations covered by the Dutch cybersecurity act. On advisories.ncsc.nl it publishes security advisories about vulnerabilities in software and equipment. An advisory carries a reference of the form NCSC-year-number with a version, a publication date, a revision history, a description of the problem and its possible consequences, a table per affected component listing CVE ID, CVSS and impact, a list of affected products, and a section on remedies. CSAF has been the source format since May 2024; a PDF version and an RSS feed are also available.
Go to the publisher’s websiteWhich products consult this source
LEO — Direct consultation
The source is consulted directly while the work is being done.
BEVER — Direct consultation
The source is consulted directly while the work is being done.
IRMA — Direct consultation
The source is consulted directly while the work is being done.
Availability depends on your organisation’s configuration and access rights.
What this source does not give you
This is security information, not a legal source. An advisory states what is vulnerable, how serious that is and what the supplier is doing about it — not whether a notification duty applies, who is liable, or what a data-processing agreement says about it. Nor does an advisory replace your own risk assessment: whether a vulnerability affects you depends on your configuration, and the NCSC does not issue advisories for every product.
Frequently asked questions
- Why is a security source among sources that are otherwise legal?
- Because the legal question almost always rests on a factual one. Whether a duty of care was breached, whether a notification was timely, whether a measure was reasonable: that starts with what exactly was vulnerable, how serious it was and when it became known. The NCSC supplies that factual layer with a reference and a date; the legal interpretation comes from the legislation and case law consulted alongside it.
- What does an advisory's classification mean?
- Every advisory carries a priority. It is based on two separate elements: the likelihood that a vulnerability is actually exploited, and the damage if that happens. Both are expressed as low, medium or high. A high CVSS score is therefore not automatically an emergency, and conversely a moderate score can still demand immediate action when a vulnerability is being actively exploited.
- Do advisories include CVE numbers and CVSS scores?
- Yes. An advisory contains a table per affected component listing the CVE ID, the CVSS score and the impact, plus a consolidated list of all CVEs with their scores and an enumeration of affected products and versions. That makes an advisory usable as a citation: you can refer to a specific vulnerability by number instead of speaking of a breach in general terms.
- Can I process the advisories in machine-readable form?
- Yes. Since May 2024 the advisories' source format has been CSAF, the Common Security Advisory Framework, and advisories are available in that format alongside the HTML and PDF versions and an RSS feed. For vulnerability management that is the difference between reading along by hand and linking an advisory automatically to your own software inventory.
- Does an NCSC advisory apply to my organisation too?
- The advisories are public and anyone can read them, but the NCSC's remit covers central government, providers of essential services and organisations under the Dutch cybersecurity act. An advisory is moreover never a judgment about your situation: it describes a vulnerability in a product, not whether you run it, in which configuration and with what residual risk. That translation remains the work of your own operations and risk process.