By Tom Meevis, attorney at Law & More
Cybersecurity is no longer purely a technical matter. It is also a legal and governance issue that affects virtually every organisation of any size.
With the European NIS2 Directive and the Dutch Cybersecurity Act, responsibility for digital resilience shifts firmly to the management board. The Dutch Cybersecurity Act enters into force on 15 August 2026. Business owners, directors and compliance officers must therefore establish at short notice:
- whether their organisation falls within the scope of the new rules;
- which obligations follow from them;
- which measures are required;
- and how the organisation can meet those obligations.
This article sets out the main elements of NIS2 and the Dutch Cybersecurity Act: the scope, the duty of care, the notification duty, board responsibility, enforcement, and the steps organisations can take now.
What is NIS2?
NIS2 is the formal designation of Directive (EU) 2022/2555. It succeeds the first European network and information security directive, generally referred to as NIS1.
Member States were required to transpose NIS2 into national law by 17 October 2024. From 18 October 2024 NIS2 formally replaced the earlier directive.
Its aim is to raise and better align the level of cyber resilience within the European Union. This runs along two main lines. First, a broader scope: many more organisations fall within the rules than under NIS1. Second, tightened supervision and stricter enforcement, with a wider toolkit and clearer responsibilities for directors.
Where NIS1 distinguished between operators of essential services and digital service providers, NIS2 works with essential entities and important entities. That distinction is not merely terminological: among other things it determines the intensity of supervision and the level of potential fines.
Which organisations fall under NIS2?
NIS2 applies to organisations active in eighteen designated sectors, divided into sectors of high criticality and other critical sectors.
Sectors of high criticality include energy, transport, banking, financial market infrastructure, healthcare, drinking water and waste water, digital infrastructure, ICT service management for business users, public administration and space.
The other critical sectors include postal and courier services, waste management, chemicals, food, manufacturing, digital providers and research institutions.
The size threshold
Within these sectors the main rule is that an organisation falls under NIS2 where it qualifies as a medium-sized or large enterprise. The criteria are at least 50 employees, or an annual turnover or balance sheet total exceeding EUR 10 million.
There are exceptions to this main rule. Certain organisations fall within scope regardless of size, because their services are regarded as particularly critical:
- providers of public electronic communications networks and services;
- trust service providers;
- domain name registration service providers;
- top-level domain name registries;
- public sector bodies.
From 15 August 2026 the new obligations apply to over 8,000 organisations in the Netherlands. That is a considerable expansion compared with the number covered by the current Network and Information Systems Security Act.
Organisations that did not previously see themselves as part of a critical sector may therefore be caught, including medium-sized manufacturers, food producers, research institutions and digital service providers. Importantly, organisations are themselves responsible for assessing whether they fall within scope. No letter from a supervisor will arrive telling them so.
The duty of care: which measures are required?
The core of NIS2 and the Dutch Cybersecurity Act is the duty of care. Essential and important entities must take appropriate and proportionate technical, operational and organisational measures to manage the risks to their network and information systems.
The rules identify the subjects the policy must in any event address:
- risk analysis and information security policy;
- incident handling;
- business continuity, backup management and disaster recovery;
- supply chain security;
- cyber hygiene and staff training;
- vulnerability handling policy;
- multi-factor authentication;
- secured communications;
- cryptography;
- periodic assessment of the effectiveness of the measures.
The measures must be proportionate to the size of the organisation and the risks to which it is actually exposed. A smaller important entity therefore need not take the same measures as a large essential entity in a high-risk sector.
That does not make the duty of care optional. Organisations must be able to substantiate which risks they identified, which measures they took and why those measures are appropriate. Not only the measures themselves, but also the way they are weighed, recorded and periodically evaluated, is subject to supervision.
Notification duty after an incident
Alongside the duty of care, NIS2 imposes a phased notification duty for significant incidents. Where an incident has or may have a substantial impact on the continuity of services, the following deadlines apply in broad terms:
- within 24 hours, an early warning to the national computer security incident response team or the competent authority;
- within 72 hours, a formal notification with an initial assessment of the severity and impact;
- within one month at the latest, a final report describing the incident, its likely root cause, the measures taken and any cross-border effects.
These deadlines make it necessary to set up clear procedures in advance. The organisation must know when an incident is notifiable, who is authorised to notify, what information must be available, who coordinates, and how the board and the supervisor are informed.
An organisation that only tries to set up a notification process during an incident runs a considerable risk of being unable to report on time or in full.
Board responsibility
An important element of NIS2 is that responsibility for managing cyber risk is placed expressly with the management board. The board must approve the security measures, oversee their implementation, be able to assess the organisation’s cyber risks, and undergo sufficient training itself.
Cybersecurity can therefore no longer be treated as the responsibility of the IT department alone. It is a governance topic that must form part of regular decision-making and risk management.
The directive also expressly addresses the personal liability of senior management where the organisation fails to comply. Record board involvement accordingly, for instance by documenting training undertaken, board decisions, approved policy, risk assessments, reporting and oversight of implementation.
The Dutch implementation
The Dutch implementation of NIS2 has been substantially delayed. The transposition deadline of 17 October 2024 was not met.
On 8 July 2026 the European Commission decided to refer the Netherlands, together with Ireland, Spain and France, to the Court of Justice of the European Union for failing to notify transposition measures. The Netherlands was thus among the European Union’s four laggards.
The timing is striking. One day earlier, on 7 July 2026, the Senate had approved the Cybersecurity Act and the Critical Entities Resilience Act. Whether the fact that the Act was adopted before the referral was sent affects the outcome of the proceedings remains to be seen; that is for the Court to decide.
Both Acts enter into force on 15 August 2026. The Cybersecurity Act implements the NIS2 Directive; the Critical Entities Resilience Act implements the European CER Directive, aimed at the resilience of critical infrastructure. Organisations covered by the latter will be formally designated as critical entities from 15 August 2026.
On entry into force, the current Network and Information Systems Security Act (Wbni) lapses. For organisations already covered by it this means heavier obligations; for organisations coming within scope for the first time, an entirely new regime.
Registration with the NCSC
An important new obligation is registration with the National Cyber Security Centre. Essential and important entities must be entered in the national entity register. That registration is mandatory from 15 August 2026 and runs through the MijnNCSC portal, using eHerkenning for ordinary organisations and SSOnRijk for public sector bodies. Changes to the registered data must be reported within fourteen days.
Registration is not merely an administrative formality. Once registered, organisations can connect to the services of their CSIRT, which provides products and services to increase resilience as well as support in the event of an incident. Prepare the registration in good time, so that implementation does not begin only after entry into force.
Supervision and enforcement
The Cybersecurity Act provides for a differentiated supervisory regime. Essential entities are subject to proactive supervision: the supervisor may check continuously and on its own initiative, without any specific incident or signal. Important entities are subject to reactive supervision, where the supervisor in principle acts in response to an incident, a complaint or another concrete signal.
Supervision is divided across several authorities. From 15 August 2026 the Dutch Authority for Digital Infrastructure supervises organisations in nine sectors; other supervisors are designated for other sectors. Establish which supervisor is competent for your organisation.
The enforcement toolkit is broad and includes:
- a security scan or security audit;
- a binding instruction;
- an administrative enforcement order or an order subject to a penalty payment;
- publication of an infringement;
- an administrative fine;
- for essential entities: suspension of a certification, an authorisation or a board member.
For essential entities the maximum fine is at least EUR 10 million or 2% of total worldwide annual turnover, whichever is higher. For important entities it is at least EUR 7 million or 1.4% of worldwide annual turnover, again whichever is higher. The eventual level depends on the circumstances of the case, including the nature, gravity and duration of the infringement, the degree of culpability and the measures taken.
What can your organisation do now?
- Carry out a self-assessment. Establish whether the organisation is active in a designated sector and meets the size threshold.
- Determine the correct category. Establish whether the organisation qualifies as an essential or an important entity, and which supervisor is competent.
- Prepare the registration. Collect the data needed for registration with the NCSC via MijnNCSC.
- Test the duty-of-care measures. Assess existing measures on risk analysis, incident response, business continuity, supply chain security, cyber hygiene, vulnerabilities, multi-factor authentication and cryptography.
- Set up the notification process. Record who assesses whether an incident is notifiable, who notifies, and how the 24-hour, 72-hour and one-month deadlines are met.
- Involve the board demonstrably. Record which decisions the board has taken, which training has been undertaken and how oversight of implementation is exercised.
- Include the supply chain. A large share of vulnerabilities arises not within the organisation itself but at suppliers and service providers. Review your contracts on security arrangements, notification duties and audit rights.
In closing
The Cybersecurity Act and the Critical Entities Resilience Act represent a considerable tightening of cybersecurity obligations. A broader scope, concrete duty-of-care measures, tight notification deadlines, personal responsibility for directors and a substantial enforcement toolkit mean organisations cannot leave this topic aside. With entry into force on 15 August 2026, preparation time is short.
Law & More assists businesses, directors and compliance officers in determining their position under NIS2 and the Dutch Cybersecurity Act, setting up and testing the duty-of-care measures, preparing the registration with the NCSC, and embedding cybersecurity policy legally.
Would you like your organisation’s position under the new rules assessed? Please feel free to contact us for a no-obligation discussion.
Frequently asked questions
Below we answer the questions we are asked most often on this subject.
When does the Dutch Cybersecurity Act enter into force?
On 15 August 2026. The Senate approved the Cybersecurity Act and the Critical Entities Resilience Act on 7 July 2026. On entry into force, the current Network and Information Systems Security Act (Wbni) lapses.
Does my organisation fall under NIS2?
That depends on your sector and your size. NIS2 covers eighteen designated sectors and, within those sectors, as a main rule organisations with at least 50 employees or an annual turnover or balance sheet total exceeding EUR 10 million. Certain parties are covered regardless of size.
Will I be notified if my organisation is in scope?
No. Organisations are themselves responsible for assessing whether they fall under the Cybersecurity Act. Waiting risks obligations applying before the assessment has been made.
What is the difference between an essential and an important entity?
It determines the intensity of supervision and the level of potential fines. Essential entities are subject to proactive supervision, where the supervisor may check on its own initiative. Important entities are subject to reactive supervision, prompted by an incident, complaint or other signal.
What does the duty of care involve?
Taking appropriate and proportionate technical, operational and organisational measures to manage the risks to your network and information systems, covering matters such as risk analysis, incident handling, business continuity, supply chain security, cyber hygiene, vulnerabilities, multi-factor authentication and cryptography. You must be able to substantiate why the chosen measures are appropriate.
What notification deadlines apply after an incident?
An early warning within 24 hours, a formal notification within 72 hours with an initial assessment of severity and impact, and a final report within one month at the latest. Set up the notification process in advance.
Does my organisation have to register?
Yes. Registration in the national entity register is mandatory from 15 August 2026 and runs through MijnNCSC, using eHerkenning or, for public sector bodies, SSOnRijk. Changes must be reported within fourteen days. Once registered you can connect to your CSIRT’s services.
What responsibility rests with the board?
The board must approve the security measures, oversee their implementation, be able to assess the cyber risks and undergo training itself. The directive addresses the personal liability of senior management for non-compliance, so record decisions, training and oversight demonstrably.
How high are the fines?
For essential entities at least EUR 10 million or 2% of worldwide annual turnover; for important entities at least EUR 7 million or 1.4%, in each case whichever is higher. The eventual level depends on factors including the nature, gravity and duration of the infringement and the degree of culpability.
Who supervises compliance?
That varies by sector. From 15 August 2026 the Dutch Authority for Digital Infrastructure supervises organisations in nine sectors; other supervisors are designated for other sectors. Establish which supervisor is competent for your organisation.
Why has the Netherlands been referred to the Court of Justice?
For late transposition of NIS2. On 8 July 2026 the European Commission decided to refer the Netherlands, together with Ireland, Spain and France, to the Court of Justice for failing to notify transposition measures. The fact that the Cybersecurity Act was adopted one day earlier does not in itself end those proceedings.
Does this apply to my suppliers as well?
Supply chain security is one of the duty-of-care subjects. A large share of vulnerabilities arises at suppliers and service providers. Review your contracts on security arrangements, notification duties and audit rights.