The Dutch implementation of the NIS2 Directive, the Cybersecurity Act (Cyberbeveiligingswet, Cbw), has been in force since 15 August 2026. It replaces the earlier Network and Information Systems Security Act (Wet beveiliging netwerk- en informatiesystemen, Wbni) and applies to organisations designated as essential or important entities across eighteen sectors, including energy, drinking water, digital infrastructure, healthcare, transport, public administration, manufacturing, waste and postal services. It reaches more than 8,000 organisations in the Netherlands.
Three obligations define it. The first is a duty of care (zorgplicht): an entity within scope must take appropriate and proportionate technical, operational and organisational measures to manage the risks to its network and information systems, and to limit the consequences of incidents. The second is a duty to report (meldplicht): a significant incident must be notified to the competent computer security incident response team and to the sector supervisor within the statutory periods, beginning with an early warning within twenty-four hours, a fuller notification within seventy-two hours and a final report within a month. The third is registration (registratieplicht) with the National Cyber Security Centre (NCSC).
What distinguishes NIS2 from earlier cybersecurity regulation is where responsibility sits. Management bodies must approve the risk management measures and supervise their implementation, they can be held accountable for failures, and they are required to follow training. The duty of care also extends to the supply chain, which means it has to be given effect through contracts with suppliers and service providers.
Does NIS2 apply to your organisation?
NIS2 applies if your organisation operates in one of the eighteen listed sectors and meets the size threshold, or if it belongs to a category that is covered regardless of size. The Cybersecurity Act has applied since 15 August 2026, and there is no general transition period: the obligations apply now.
The Netherlands implemented the directive later than the European deadline. Many older articles still refer to “a 2025 deadline”. That date is no longer relevant. What matters is that the Dutch rules are in force and that supervisors can enforce them.
Which sectors and organisations are in scope?
The Act covers eighteen sectors, listed in two annexes. The first annex contains sectors of high criticality, such as energy, transport, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure, public administration and space. The second annex contains other critical sectors, such as postal and courier services, waste management, chemicals, food, manufacturing, digital providers and research.
Within these sectors, size determines whether you are covered. According to the NCSC, your organisation falls within scope if it meets at least one of these criteria:
- Staff: it employs 50 or more people (in full-time equivalents)
- Turnover and balance sheet: it employs fewer than 50 people, but both its annual turnover and its balance-sheet total exceed €10 million
- Group: partner and linked enterprises count towards these figures, so a small subsidiary of a large group can still be covered
Some organisations are covered regardless of their size. These include DNS service providers, providers of public electronic communications networks or services, trust service providers, top-level domain name registries and government organisations.
Within scope, the law distinguishes between essential and important entities. As a rule, larger organisations in the high-criticality sectors are essential entities; others are important entities. The distinction matters for supervision and for the maximum fine. The Dutch Authority for Digital Infrastructure (RDI) offers a self-assessment tool (NIS2-Zelfevaluatie) on regelhulpenvoorbedrijven.nl to help you establish your position. If the outcome is unclear, for example because of a group structure or mixed activities, have it assessed and record the reasoning.
What does the duty of care require?
The duty of care requires appropriate and proportionate measures to manage the risks to your network and information systems. “Proportionate” means the measures must match your size, your exposure to risk and the possible impact of an incident on society and the economy.
The directive sets a minimum baseline in Article 21(2) of the NIS2 Directive. In short, your measures must cover:
- Risk analysis: policies on risk analysis and the security of your information systems
- Incident handling: procedures for detecting, handling and recovering from incidents
- Continuity: business continuity, backups, recovery and crisis management
- Supply chain: security in your relationships with suppliers and service providers
- Development and maintenance: security when acquiring, developing and maintaining systems, including handling vulnerabilities
- Testing: procedures to assess whether your measures are effective
- Hygiene and training: basic cyber hygiene and cybersecurity training for staff
- Cryptography and access: the use of encryption, human resources security, access control and asset management, including secure authentication
The law does not prescribe one specific standard. Many organisations use an existing information security framework to structure their measures. What counts for a supervisor is whether you can show that your measures are based on a risk assessment and actually work.
How do the reporting duty and enforcement work?
A significant incident must be reported in three stages: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month. You report to the competent computer security incident response team (CSIRT) and to your sector supervisor.
The 24-hour warning is short and does not need to be complete. It mainly signals that something is happening and whether there may be malicious intent or cross-border effects. The 72-hour notification gives a first assessment of the severity and impact. The final report describes the cause, the measures taken and any cross-border consequences.
Supervision is divided by sector. Depending on your activities, your supervisor may be, for example, the Human Environment and Transport Inspectorate (ILT), De Nederlandsche Bank (DNB), the Dutch Authority for the Financial Markets (AFM), the Health and Youth Care Inspectorate (IGJ), the Netherlands Food and Consumer Product Safety Authority (NVWA) or the RDI. Supervisors have enforcement powers, which include imposing administrative fines.
NIS2 also overlaps with the General Data Protection Regulation (GDPR). If an incident involves personal data, a separate notification to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) may be required. Align your NIS2 procedure with your data breach procedure, so that one incident does not lead to two separate, uncoordinated processes.
What changes for management, staff and the company?
The most important change is that cybersecurity is no longer a matter for the IT department alone. NIS2 places responsibility with the management body, and expects the whole organisation, including staff and suppliers, to contribute.
What does NIS2 mean for employees?
NIS2 does not create new individual rights or obligations for employees directly; the obligations rest on the organisation. In practice, however, the employer must translate the duty of care into rules and training for staff.
Basic cyber hygiene and cybersecurity training are part of the minimum measures. That means your employees should, for example:
- Awareness: take part in training on phishing, passwords and secure working
- Internal reporting: know how and to whom they report a suspected incident or vulnerability, so that you can meet the 24-hour deadline
- Access: use secure authentication and only have access to the systems they need for their work
Record these rules in a policy or staff handbook. If you introduce new monitoring of employees’ systems or behaviour, check the rules on privacy and, where relevant, the role of the works council (ondernemingsraad).
What must the management body do?
The management body must approve the cybersecurity risk management measures and supervise their implementation. Its members must follow training, so that they have enough knowledge to assess risks and measures. If the organisation fails to comply, the management body can be held accountable.
In practice, this means the board can no longer simply delegate cybersecurity. Directors should:
- Decide: formally approve the risk assessment and the measures, and record that decision
- Supervise: receive regular reports on the status of the measures and on incidents
- Learn: follow training and keep that knowledge up to date
- Allocate: make sure there are enough budget, people and clear roles
Whether a director can be held personally liable for damage depends on the general rules of Dutch company law and the facts of the case. Clear decision-making and documentation help to show that the board took its role seriously.
What are the fines and other consequences?
Supervisors can impose fines of up to €10 million or 2% of worldwide annual turnover on essential entities, and up to €7 million or 1.4% on important entities, whichever is higher. These are maximum amounts; the actual fine depends on the seriousness of the breach and the circumstances.
Fines are not the only risk. A supervisor can also use other enforcement measures to make you comply. A serious incident can also lead to claims from customers or business partners, to contractual consequences with suppliers and to reputational damage. Good preparation therefore protects you in several ways.
How do you deal with suppliers and contracts?
The duty of care extends to your supply chain, so you must also manage the cybersecurity risks of your suppliers and service providers. In practice, this is done largely through contracts.
Points to address in supplier contracts include:
- Security requirements: the measures the supplier must take, in line with your own risk assessment
- Incident notification: a short deadline for the supplier to inform you of incidents, so that you can meet your own reporting deadlines
- Audit and information: your right to request information and to have compliance checked
- Subcontracting: rules on the use of subcontractors and the transfer of obligations
- Liability and termination: what happens if the supplier fails to comply, and how you can end the relationship
Review existing contracts with your most important IT and service providers first. New contracts can include standard NIS2 clauses from the outset.
What should you check as an organisation in scope?
The Act has applied since 15 August 2026 without a general transition period. These checks cover the obligations a supervisor will look at first.
- Establish with the RDI self-assessment whether you are an essential or important entity, include group companies, and record the reasoning.
- Register with the NCSC and keep the registration up to date.
- Have the management body formally approve the risk assessment and the measures, and record that decision.
- Plan training for the management body and basic cyber hygiene training for staff.
- Name the person who decides whether an incident is significant and who reports within 24 hours, 72 hours and one month.
- Align the NIS2 procedure with the 72-hour data breach notification to the Dutch Data Protection Authority under the GDPR.
What should you check as a supplier?
Customers in scope pass their duty of care on to you through contracts. Check what you are asked to sign before you agree.
- Check whether your own organisation is covered by the Act, for example as a digital or IT service provider.
- Check that the incident notification deadline you are asked to accept is achievable, given your customer’s own 24-hour deadline.
- Agree on the scope and cost of the customer’s audit and information rights.
- Check the liability and termination clauses attached to the security requirements.
- Check which obligations you must pass on to your own subcontractors.
What can we do for you with NIS2 and the Cybersecurity Act?
Our IT lawyer team assists organisations in scope and their suppliers, from the scope assessment to supervision.
- We establish whether your organisation is an essential or important entity, including in group structures.
- We draft the board resolution, the security policies and the incident and reporting procedure.
- We draft and review NIS2 clauses in supplier and customer contracts.
- We advise directors on their responsibilities and on their liability under Dutch company law.
- We assist during an investigation by the RDI or your sector supervisor and draft the objection (bezwaar) against a fine decision.
Summary
- The Cybersecurity Act, the Dutch implementation of NIS2, has applied since 15 August 2026 to more than 8,000 organisations in eighteen sectors.
- Your organisation is generally covered if it has at least 50 employees, or turnover and balance-sheet total both above €10 million; some providers are covered regardless of size.
- The core obligations are the duty of care, reporting significant incidents (24 hours, 72 hours, one month) and registration with the NCSC.
- The management body approves and supervises the measures, follows training and can be held accountable; supply chain security runs largely through contracts.
- Fines can reach €10 million or 2% of worldwide turnover for essential entities, and €7 million or 1.4% for important entities.
Frequently asked questions
What is NIS2 and how does it affect businesses in the Netherlands?
NIS2 is an EU directive on cybersecurity, implemented in the Netherlands by the Cybersecurity Act (Cyberbeveiligingswet), in force since 15 August 2026. Organisations within scope must register with the NCSC, take appropriate security measures and report significant incidents within set deadlines.
Which sectors are impacted by NIS2 in the Netherlands?
Eighteen sectors are covered, including energy, transport, banking, healthcare, drinking water, digital infrastructure, public administration, manufacturing, waste and postal services. Within those sectors, the law generally applies to organisations with at least 50 employees, or with turnover and balance-sheet total both above €10 million.
What are the consequences of non-compliance with NIS2?
Supervisors can impose fines of up to €10 million or 2% of worldwide annual turnover for essential entities, and up to €7 million or 1.4% for important entities, whichever is higher. They can also take other enforcement measures, and the management body can be held accountable.
How can organisations prepare for NIS2 compliance?
Establish whether you are in scope, register with the NCSC, have the management body approve a risk assessment and measures, train staff and directors, and prepare an incident and reporting procedure. Because the law is already in force, start with these basics now.


