NIS2 and the Dutch Cybersecurity Act: what must your organisation do?

Colleagues in a meeting room studying a network diagram projected on a screen

The Dutch Cybersecurity Act (Cyberbeveiligingswet, Cbw), which implements the NIS2 Directive, entered into force on 15 August 2026. It applies to medium-sized and large organisations in eighteen designated sectors, and to a number of critical providers regardless of size; in the Netherlands, the government estimates that it covers around 8,000 organisations, many of which were not subject to any cybersecurity regulation before.

Three obligations sit at its core. An organisation within scope must take appropriate and proportionate measures to manage the risks to its network and information systems and to limit the consequences of incidents. That duty of care (zorgplicht) expressly extends to the security of its supply chain. It must report a significant incident, starting with an early warning within 24 hours, a fuller notification within 72 hours and a final report within one month. And it must register with the National Cyber Security Centre (NCSC).

What is new for many boards is where responsibility sits. Management must approve the risk management measures, supervise their implementation and follow training on the subject, and can be held accountable if the obligations are not met. That responsibility cannot be delegated to an IT department or an external provider.

Below we explain how to determine whether your organisation falls within scope and in which category, what the duty of care requires in practice, how the reporting clock runs from the moment an incident is detected, and which steps to take first.

What is NIS2?

NIS2 is Directive (EU) 2022/2555, the second European directive on network and information security. It replaces the first directive, generally referred to as NIS1, and aims to raise and align the level of cyber resilience across the European Union.

Member States had to transpose NIS2 into national law by 17 October 2024. From 18 October 2024 NIS2 formally replaced the earlier directive.

NIS2 works along two main lines. First, a much broader scope: many more organisations fall within the rules than under NIS1. Second, stricter supervision and enforcement, with a wider set of tools and clearer responsibilities for directors.

Where NIS1 distinguished between operators of essential services and digital service providers, NIS2 distinguishes between essential entities (essentiële entiteiten) and important entities (belangrijke entiteiten). That distinction is not just a matter of terms: it determines, among other things, how intensive supervision is and how high fines can be.

Which organisations fall under NIS2?

NIS2 applies to organisations active in eighteen designated sectors that are at least medium-sized, plus certain providers that fall within scope whatever their size. You must assess this yourself; no supervisor will tell you.

Which sectors are covered?

The eighteen sectors are divided into sectors of high criticality (Annex I of the directive) and other critical sectors (Annex II).

  • Sectors of high criticality: energy, transport, banking, financial market infrastructure, health care, drinking water, waste water, digital infrastructure, ICT service management for business users, public administration and space.
  • Other critical sectors: postal and courier services, waste management, chemicals, food, manufacturing, digital providers, and research organisations.

Within each sector, the directive specifies which types of organisation are covered. In manufacturing, for example, it concerns producers of medical devices, computers and electronics, electrical equipment, machinery and vehicles, not all manufacturers.

What is the size threshold?

The main rule is that an organisation in a designated sector falls under NIS2 if it is at least a medium-sized enterprise under the European definition (Recommendation 2003/361/EC). In practice this means 50 or more employees, or an annual turnover and an annual balance sheet total that both exceed €10 million.

The calculation is not always simple. Under the European definition, staff numbers and financial figures of partner and linked enterprises must in principle be included. A subsidiary with 30 employees can therefore fall within scope if it belongs to a larger group.

Certain organisations fall within scope regardless of size, because their services are regarded as particularly critical. These include:

  • providers of public electronic communications networks and services;
  • trust service providers;
  • domain name registration service providers;
  • top-level domain name registries and DNS service providers;
  • public administration bodies, which in the Netherlands include ministries, provinces, municipalities and their joint arrangements.

From 15 August 2026 the new obligations apply to around 8,000 organisations in the Netherlands. That is a considerable expansion compared with the number covered by the previous Network and Information Systems Security Act (Wet beveiliging netwerk- en informatiesystemen, Wbni).

Organisations that never saw themselves as part of a critical sector may therefore be caught, including medium-sized manufacturers, food producers, research institutions and digital service providers. Organisations are themselves responsible for assessing whether they fall within scope. No letter from a supervisor will arrive telling them so. The Dutch government offers a step-by-step self-assessment tool through the NCTV and NCSC websites.

What does the duty of care require?

The duty of care requires essential and important entities to take appropriate and proportionate technical, operational and organisational measures to manage the risks to their network and information systems. The measures must cover at least a fixed list of subjects, set out in Article 21 of the directive.

The policy must in any event address:

  • risk analysis and information security policy;
  • incident handling;
  • business continuity, backup management and disaster recovery;
  • supply chain security;
  • security in the acquisition, development and maintenance of systems, including vulnerability handling;
  • cyber hygiene and staff training;
  • multi-factor authentication and secured communications;
  • cryptography and, where appropriate, encryption;
  • human resources security, access control and asset management;
  • periodic assessment of the effectiveness of the measures.

The measures must be proportionate to the size of the organisation and the risks it actually faces. A smaller important entity therefore does not need the same measures as a large essential entity in a high-risk sector.

That does not make the duty of care optional. You must be able to show which risks you identified, which measures you took and why those measures are appropriate. The supervisor looks not only at the measures themselves, but also at how they were weighed, recorded and evaluated over time.

How does supply chain security work in practice?

Supply chain security means that you assess the cybersecurity of your direct suppliers and service providers and make agreements with them. Many incidents start at a supplier rather than within the organisation itself.

In practice, this means reviewing your contracts. Useful clauses cover minimum security requirements, a duty for the supplier to report incidents to you promptly, audit rights, subcontracting, and cooperation during an incident. Suppliers that do not fall under NIS2 themselves will often be asked by their customers to meet these requirements contractually.

What must you do after an incident?

After a significant incident you must report in three phases: an early warning within 24 hours, a notification within 72 hours, and a final report within one month. The deadlines run from the moment you become aware of the incident.

An incident is significant if it has caused or can cause severe operational disruption of the services or financial loss for the organisation, or if it has affected or can affect other persons by causing considerable material or non-material damage. For significant incidents the following deadlines apply (Article 23 of the directive):

  • within 24 hours: an early warning to the competent computer security incident response team (CSIRT) or authority, stating whether the incident may have been caused by unlawful or malicious acts and whether it may have a cross-border impact;
  • within 72 hours: a notification that updates the early warning and gives an initial assessment of the severity and impact, and where available the indicators of compromise;
  • within one month at the latest: a final report describing the incident, its likely root cause, the measures taken and any cross-border effects.

These deadlines make it necessary to set up clear procedures in advance. You must know when an incident is notifiable, who is authorised to notify, which information must be available, who coordinates, and how the board and the supervisor are informed.

An organisation that only sets up a notification process during an incident runs a considerable risk of not reporting on time or in full. If personal data are involved, remember that a separate notification to the Dutch Data Protection Authority may be required under the GDPR, within 72 hours.

What responsibility rests with the board?

Under Article 20 of the directive, the management body must approve the cybersecurity risk management measures, oversee their implementation and can be held liable for infringements. Members of the management body must also follow training.

Cybersecurity is therefore no longer a matter for the IT department alone. It is a governance topic that belongs in regular decision-making and risk management. The board must be able to assess the organisation’s cyber risks itself.

The directive also expressly addresses the liability of the management body where the organisation fails to comply. Record board involvement in a way that can be shown, for example by documenting training undertaken, board decisions, approved policy, risk assessments, reports and oversight of implementation. For directors of Dutch companies, this also matters for the general standard of proper performance of duties under Article 2:9 of the Dutch Civil Code.

How has the Netherlands implemented NIS2?

The Netherlands implemented NIS2 late, through the Cybersecurity Act and the Critical Entities Resilience Act (Wet weerbaarheid kritieke entiteiten, Wwke). Both entered into force on 15 August 2026.

The transposition deadline of 17 October 2024 was not met. On 8 July 2026 the European Commission decided to refer the Netherlands, together with Ireland, Spain and France, to the Court of Justice of the European Union for failing to notify transposition measures. The Netherlands was thus among the four Member States that were furthest behind.

The timing is striking. One day earlier, on 7 July 2026, the Senate (Eerste Kamer) had approved the Cybersecurity Act and the Critical Entities Resilience Act. Whether the adoption of the Act before the referral affects the outcome of the proceedings remains to be seen; that is for the Court to decide.

The Cybersecurity Act implements the NIS2 Directive. The Critical Entities Resilience Act implements the European CER Directive (Directive (EU) 2022/2557), which aims at the physical and overall resilience of critical infrastructure. Around 500 organisations are covered by the latter; they are formally designated as critical entities by the responsible minister.

On entry into force, the Wbni lapsed. For organisations already covered by it, this means heavier obligations; for organisations coming within scope for the first time, an entirely new regime.

How do you register with the NCSC?

Essential and important entities must register in the national entity register through the Mijn.NCSC.nl portal. Registration is mandatory from 15 August 2026, and changes must be reported within two weeks.

Access to the portal requires eHerkenning at level 3 or higher for ordinary organisations; public sector bodies use SSOnRijk. Changes to the registered data, for example after a merger or a change in IP ranges, must be reported within two weeks. A supervisor can enforce the registration obligation with a fine or an order subject to a penalty payment.

Registration is more than an administrative formality. Once registered, organisations can connect to the services of their CSIRT, which provides products and services to increase resilience and support in the event of an incident. Prepare the registration in good time, so that implementation does not begin only after the obligations already apply.

How are supervision and enforcement organised?

Essential entities are subject to proactive supervision; important entities to reactive supervision. Supervision is divided among several sector supervisors.

In proactive supervision, the supervisor may check on its own initiative, without any specific incident or signal, for example by requesting information or making a site visit. In reactive supervision, the supervisor in principle acts afterwards, in response to an incident, a complaint or another concrete signal. Both categories must meet the same basic obligations.

The Dutch Authority for Digital Infrastructure (Rijksinspectie Digitale Infrastructuur, RDI) supervises organisations in nine sectors: energy, digital infrastructure, ICT service management, public administration, space, postal and courier services, manufacturing, digital providers and research. Other supervisors are designated for the other sectors. Find out which supervisor is competent for your organisation.

The enforcement toolkit is broad and includes:

  • a security scan or security audit;
  • a binding instruction;
  • an administrative enforcement order or an order subject to a penalty payment;
  • publication of an infringement;
  • an administrative fine;
  • for essential entities: suspension of a certification or authorisation, or a temporary ban on a board member exercising management functions.

Under Article 34 of the directive, the maximum fine for essential entities is at least €10 million or 2% of total worldwide annual turnover, whichever is higher. For important entities it is at least €7 million or 1.4% of worldwide annual turnover, again whichever is higher. The actual fine depends on the circumstances of the case, including the nature, gravity and duration of the infringement, the degree of culpability and the measures taken.

What can your organisation do now?

Start with a self-assessment and work from there to the measures, the notification process and board involvement. The obligations already apply, so there is no transition period to rely on.

  • Carry out a self-assessment: establish whether the organisation is active in a designated sector and meets the size threshold, taking group companies into account.
  • Determine the category: establish whether the organisation is an essential or an important entity, and which supervisor is competent.
  • Register: collect the necessary data and register with the NCSC through Mijn.NCSC.nl.
  • Test the duty-of-care measures: assess existing measures on risk analysis, incident response, business continuity, supply chain security, cyber hygiene, vulnerabilities, multi-factor authentication and cryptography.
  • Set up the notification process: record who assesses whether an incident is notifiable, who notifies, and how the 24-hour, 72-hour and one-month deadlines are met.
  • Involve the board in a way you can show: record which decisions the board has taken, which training has been followed and how oversight of implementation works.
  • Include the supply chain: review your contracts on security requirements, notification duties and audit rights.

In summary

  • The Dutch Cybersecurity Act implements NIS2 and has applied since 15 August 2026, to around 8,000 organisations in eighteen sectors.
  • As a rule, medium-sized and large organisations in those sectors are covered; some providers are covered whatever their size. You must assess this yourself.
  • The core obligations are the duty of care, the phased notification of significant incidents (24 hours, 72 hours, one month) and registration with the NCSC.
  • The board must approve and oversee the measures, follow training and can be held accountable.
  • Fines can reach at least €10 million or 2% of worldwide turnover for essential entities, and at least €7 million or 1.4% for important entities.

The Cybersecurity Act and the Critical Entities Resilience Act mean a considerable tightening of cybersecurity obligations. A broader scope, concrete measures, tight notification deadlines, board responsibility and a broad enforcement toolkit mean that organisations cannot leave this topic aside.

Frequently asked questions

Below we answer the questions we are asked most often on this subject.

When did the Dutch Cybersecurity Act enter into force?

On 15 August 2026. The Senate approved the Cybersecurity Act and the Critical Entities Resilience Act on 7 July 2026. On entry into force, the previous Network and Information Systems Security Act (Wbni) lapsed.

Does my organisation fall under NIS2?

That depends on your sector and size. NIS2 covers eighteen designated sectors and, within those sectors, as a rule organisations with 50 or more employees, or with an annual turnover and balance sheet total that both exceed €10 million. Figures of group companies must in principle be included. Certain providers are covered regardless of size.

Will I be notified if my organisation is in scope?

No. Organisations are themselves responsible for assessing whether they fall under the Cybersecurity Act. The obligations already apply, so waiting means you may already be in breach.

What is the difference between an essential and an important entity?

It determines the intensity of supervision and the level of possible fines. Essential entities are subject to proactive supervision, where the supervisor may check on its own initiative. Important entities are subject to reactive supervision, usually after an incident, complaint or other signal. The basic obligations are the same.

What does the duty of care involve?

Taking appropriate and proportionate technical, operational and organisational measures to manage the risks to your network and information systems, covering matters such as risk analysis, incident handling, business continuity, supply chain security, cyber hygiene, vulnerability handling, multi-factor authentication and cryptography. You must be able to show why the chosen measures are appropriate.

What notification deadlines apply after an incident?

For a significant incident: an early warning within 24 hours, a notification within 72 hours with an initial assessment of severity and impact, and a final report within one month at the latest. The deadlines run from the moment you become aware of the incident, so set up the process in advance.

Does my organisation have to register?

Yes. Registration in the national entity register is mandatory from 15 August 2026 and runs through Mijn.NCSC.nl, using eHerkenning (level 3 or higher) or, for public sector bodies, SSOnRijk. Changes must be reported within two weeks. Once registered, you can connect to your CSIRT’s services.

What responsibility rests with the board?

The board must approve the security measures, oversee their implementation, be able to assess the cyber risks and follow training itself. The directive provides that the management body can be held liable for infringements, so record decisions, training and oversight in a way you can show.

How high are the fines?

For essential entities the maximum is at least €10 million or 2% of worldwide annual turnover; for important entities at least €7 million or 1.4%, in each case whichever is higher. The actual fine depends on factors such as the nature, gravity and duration of the infringement and the degree of culpability.

Who supervises compliance?

That depends on the sector. The Dutch Authority for Digital Infrastructure (RDI) supervises nine sectors, including energy, digital infrastructure, ICT service management, public administration and manufacturing. Other supervisors are designated for the other sectors.

Why has the Netherlands been referred to the Court of Justice?

For late transposition of NIS2. On 8 July 2026 the European Commission decided to refer the Netherlands, together with Ireland, Spain and France, to the Court of Justice for failing to notify transposition measures. The fact that the Cybersecurity Act was adopted one day earlier does not in itself end those proceedings.

Does this apply to my suppliers as well?

Supply chain security is part of the duty of care. Many vulnerabilities arise at suppliers and service providers. Review your contracts on security requirements, notification duties and audit rights. Suppliers that are not covered themselves will often have to meet these requirements under their contracts.

Law & More assists businesses, directors and compliance officers in determining their position under NIS2 and the Dutch Cybersecurity Act, reviewing the duty-of-care measures and supplier contracts, preparing the registration with the NCSC, and embedding cybersecurity in governance. Unsure where you stand? Tell us about your situation. We will let you know your options within one working day.

Need Legal Assistance?

Have you received a letter, a writ of summons or a judgment? Send us the documents. We will check which deadlines apply and what your options are.

This article provides general information and is not a substitute for advice on your specific situation.

Related articles

The WHOA allows a Dutch company in financial difficulty to impose a restructuring plan on

The European AI Act introduced major changes on 2 February 2025, making certain AI practices

A hashtag can be registered as a trade mark, and many have been. What the

Paying for bespoke software does not make you the rightholder. Employer copyright, assignment, licence, source

The right of access in article 15 of the General Data Protection Regulation, known in

An employer that wants to employ someone from outside the EU, the EEA or Switzerland

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.