Home / FAQ

Frequently asked questions

Everything about RealCob, GDPR and NIS2 in one place. Question not listed? Get in touch.

We are already ISO certified. Isn’t that enough?

No, that is a common misconception. ISO 27001 covers information security and only partly overlaps with the GDPR. The GDPR sets its own requirements – from the processing register to data subject rights – that you must arrange and be able to demonstrate separately. RealCob checks those obligations alongside your existing ISO setup.

What is RealCob and what is it used for?

RealCob is software that helps organizations comply with GDPR and NIS2 regulations by automating compliance processes and identifying risks.

Who is RealCob for?

RealCob is suitable for SMEs, large companies, IT managers, DPOs, and consultants who need to comply with privacy and cybersecurity legislation—with or without a legal department.

What is the difference between GDPR and NIS2, and how does RealCob help?

The GDPR focuses on personal data protection, while NIS2 sets requirements for network and information security. RealCob audits both areas and provides specific advice per department.

What makes RealCob different from other compliance software?

RealCob is fully Dutch-language, easy to use, includes automated reporting, and requires no legal knowledge. Unique features include certification and AO/IB integration.

How quickly can I start using RealCob?

Within 3 hours to 1 day, you can complete a full GDPR and NIS2 check and start improving your compliance.

Is RealCob suitable for international companies?

Yes. RealCob supports multiple European languages and complies with international standards, making it ideal for multinationals with multiple locations.

What are the costs of RealCob?

RealCob offers various versions (Basic, Business, Corporate, Custom) starting from €950 per year, depending on company size and required features. Volume discounts apply.

Do I need legal or technical knowledge to use RealCob?

No. The software is designed for any employee to use, with clear explanations. For advanced needs, extra modules are available.

Can RealCob help during an audit or data breach?

Yes. RealCob automatically creates reports and documentation for use in audits or for accountability to data protection authorities.

What if I need support while using the software?

RealCob offers support on weekdays via email, and optionally via phone, live chat, or webinars. Instructions and training are included in the software.

What is the GDPR and why is it important?

The GDPR is an EU regulation that requires companies to handle personal data with care. It aims to protect individuals’ privacy and promote transparency in data processing.

What are the key requirements under the GDPR?

Organizations must process data securely, inform users transparently, obtain consent when needed, sign processor agreements, and report data breaches.

What is NIS2 and who does it apply to?

NIS2 is an EU directive that raises cybersecurity standards for organizations offering essential or important services. In the Netherlands, NIS2 has been implemented in the Cyberbeveiligingswet (Cbw), in force since 15 August 2026: registration duty, duty of care, 24-hour incident reporting and board-level accountability.

What is the difference between GDPR and NIS2?

The GDPR focuses on data privacy. NIS2 goes further, setting strict requirements for IT infrastructure and incident management, especially in critical sectors.

Does NIS2 apply to me as an SME?

Formally only if you operate in a designated sector and meet certain thresholds. But in practice, even SMEs must prove they work with NIS2-compliant suppliers.

What are the consequences of non-compliance with GDPR or NIS2?

Fines can be severe—up to €20 million. There’s also reputational damage, legal risk, and loss of trust from clients and regulators.

Which sectors fall under NIS2?

Energy, healthcare, transport, digital infrastructure, public administration, financial services, and others defined as vital or important by the EU.

Do I need to appoint a Data Protection Officer (DPO)?

Yes, if you’re a public institution or process sensitive data on a large scale. In other cases, it’s highly recommended.

What technical measures does NIS2 require?

Network segmentation, encryption, incident response plans, real-time monitoring, patch management, and more—depending on your sector and risk level.

How can I prepare my organization for NIS2?

Start with a risk assessment, map your processes, evaluate your suppliers, and use tools like RealCob to automate and maintain compliance.

Try free for 30 days