The Dutch implementation of the NIS2 Directive, the Cybersecurity Act (Cyberbeveiligingswet, Cbw), has been in force since 15 August 2026. It replaces the earlier Network and Information Systems Security Act (Wet beveiliging netwerk- en informatiesystemen, Wbni) and applies to organisations designated as essential or important entities across eighteen sectors, including energy, drinking water, digital infrastructure, healthcare, transport, public administration, manufacturing, waste and postal services. It reaches an estimated eight thousand organisations in the Netherlands.
Three obligations define it. The first is a duty of care (zorgplicht): an entity within scope must take appropriate and proportionate technical, operational and organisational measures to manage the risks to its network and information systems, and to limit the consequences of incidents. The second is a duty to report (meldplicht): a significant incident must be notified to the competent computer security incident response team and to the sector supervisor within the statutory periods, beginning with an early warning within twenty-four hours, a fuller notification within seventy-two hours and a final report within a month. The third is registration (registratieplicht) with the National Cyber Security Centre (NCSC).
What distinguishes NIS2 from earlier cybersecurity regulation is where responsibility sits. Management bodies must approve the risk management measures and supervise their implementation, they can be held accountable for failures, and they are required to follow training. The duty of care also extends to the supply chain, which means it has to be given effect through contracts with suppliers and service providers.
This article explains how to establish whether your organisation falls within scope, what the duty of care requires in practice, how the reporting deadlines run, and what to arrange first.
Table of Contents
- Does NIS2 apply to your organisation?
- What changes for management, staff and the company?
- How do you become NIS2 compliant, step by step?
- How do you manage NIS2 in practice?
NIS2 at a glance
| Topic | What applies in the Netherlands |
| Legislation | The Cybersecurity Act (Cyberbeveiligingswet), implementing Directive (EU) 2022/2555 (NIS2), in force since 15 August 2026. |
| Who is covered | Organisations in eighteen sectors with at least 50 employees, or with fewer employees but an annual turnover and balance-sheet total both above €10 million. Some providers, such as DNS service providers and government organisations, are covered regardless of size. |
| Core obligations | Duty of care, duty to report significant incidents (24 hours, 72 hours, one month) and registration with the NCSC. |
| Fines | Up to €10 million or 2% of worldwide annual turnover for essential entities, and up to €7 million or 1.4% for important entities, whichever is higher. |
| Responsibility | The management body approves the measures, supervises their implementation, follows training and can be held accountable. |
Does NIS2 apply to your organisation?
NIS2 applies if your organisation operates in one of the eighteen listed sectors and meets the size threshold, or if it belongs to a category that is covered regardless of size. The Cybersecurity Act has applied since 15 August 2026, and there is no general transition period: the obligations apply now.
The Netherlands implemented the directive later than the European deadline. Many older articles still refer to “a 2025 deadline”. That date is no longer relevant. What matters is that the Dutch rules are in force and that supervisors can enforce them. Only a limited group, such as higher education institutions, has been given a longer period to comply.
Which sectors and organisations are in scope?
The Act covers eighteen sectors, listed in two annexes. The first annex contains sectors of high criticality, such as energy, transport, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure, public administration and space. The second annex contains other critical sectors, such as postal and courier services, waste management, chemicals, food, manufacturing, digital providers and research.
Within these sectors, size determines whether you are covered. According to the NCSC, your organisation falls within scope if it meets at least one of these criteria:
- Staff: it employs 50 or more people (in full-time equivalents)
- Turnover and balance sheet: it employs fewer than 50 people, but both its annual turnover and its balance-sheet total exceed €10 million
- Group: partner and linked enterprises count towards these figures, so a small subsidiary of a large group can still be covered
Some organisations are covered regardless of their size. These include DNS service providers, providers of public electronic communications networks or services, trust service providers, top-level domain name registries and government organisations.
Within scope, the law distinguishes between essential and important entities. As a rule, larger organisations in the high-criticality sectors are essential entities; others are important entities. The distinction matters for supervision and for the maximum fine. The Dutch Authority for Digital Infrastructure (RDI) offers a self-assessment tool (NIS2-Zelfevaluatie) on regelhulpenvoorbedrijven.nl to help you establish your position. If the outcome is unclear, for example because of a group structure or mixed activities, have it assessed and record the reasoning.
What does the duty of care require?
The duty of care requires appropriate and proportionate measures to manage the risks to your network and information systems. “Proportionate” means the measures must match your size, your exposure to risk and the possible impact of an incident on society and the economy.
The directive sets a minimum baseline in Article 21(2) of the NIS2 Directive. In short, your measures must cover:
- Risk analysis: policies on risk analysis and the security of your information systems
- Incident handling: procedures for detecting, handling and recovering from incidents
- Continuity: business continuity, backups, recovery and crisis management
- Supply chain: security in your relationships with suppliers and service providers
- Development and maintenance: security when acquiring, developing and maintaining systems, including handling vulnerabilities
- Testing: procedures to assess whether your measures are effective
- Hygiene and training: basic cyber hygiene and cybersecurity training for staff
- Cryptography and access: the use of encryption, human resources security, access control and asset management, including secure authentication
The law does not prescribe one specific standard. Many organisations use an existing information security framework to structure their measures. What counts for a supervisor is whether you can show that your measures are based on a risk assessment and actually work.
How do the reporting duty and enforcement work?
A significant incident must be reported in three stages: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month. You report to the competent computer security incident response team (CSIRT) and to your sector supervisor.
The 24-hour warning is short and does not need to be complete. It mainly signals that something is happening and whether there may be malicious intent or cross-border effects. The 72-hour notification gives a first assessment of the severity and impact. The final report describes the cause, the measures taken and any cross-border consequences.
Supervision is divided by sector. Depending on your activities, your supervisor may be, for example, the Human Environment and Transport Inspectorate (ILT), De Nederlandsche Bank (DNB), the Dutch Authority for the Financial Markets (AFM), the Health and Youth Care Inspectorate (IGJ), the Netherlands Food and Consumer Product Safety Authority (NVWA) or the RDI. Supervisors have enforcement powers, which include imposing administrative fines.
What changes for management, staff and the company?
The most important change is that cybersecurity is no longer a matter for the IT department alone. NIS2 places responsibility with the management body, and expects the whole organisation, including staff and suppliers, to contribute.
This does not mean that every employee gets new statutory duties. The obligations rest on the organisation. But the organisation can only meet them if people know what is expected of them, which is why training and clear internal rules are part of the duty of care.
What does NIS2 mean for employees?
NIS2 does not create new individual rights or obligations for employees directly; the obligations rest on the organisation. In practice, however, the employer must translate the duty of care into rules and training for staff.
Basic cyber hygiene and cybersecurity training are part of the minimum measures. That means your employees should, for example:
- Awareness: take part in training on phishing, passwords and secure working
- Internal reporting: know how and to whom they report a suspected incident or vulnerability, so that you can meet the 24-hour deadline
- Access: use secure authentication and only have access to the systems they need for their work
Record these rules in a policy or staff handbook. If you introduce new monitoring of employees’ systems or behaviour, check the rules on privacy and, where relevant, the role of the works council (ondernemingsraad).
What must the management body do?
The management body must approve the cybersecurity risk management measures and supervise their implementation. Its members must follow training, so that they have enough knowledge to assess risks and measures. If the organisation fails to comply, the management body can be held accountable.
In practice, this means the board can no longer simply delegate cybersecurity. Directors should:
- Decide: formally approve the risk assessment and the measures, and record that decision
- Supervise: receive regular reports on the status of the measures and on incidents
- Learn: follow training and keep that knowledge up to date
- Allocate: make sure there are enough budget, people and clear roles
Whether a director can be held personally liable for damage depends on the general rules of Dutch company law and the facts of the case. Clear decision-making and documentation help to show that the board took its role seriously.
What are the fines and other consequences?
Supervisors can impose fines of up to €10 million or 2% of worldwide annual turnover on essential entities, and up to €7 million or 1.4% on important entities, whichever is higher. These are maximum amounts; the actual fine depends on the seriousness of the breach and the circumstances.
Fines are not the only risk. A supervisor can also use other enforcement measures to make you comply. A serious incident can also lead to claims from customers or business partners, to contractual consequences with suppliers and to reputational damage. Good preparation therefore protects you in several ways.
How do you become NIS2 compliant, step by step?
Start by establishing whether and how the law applies to you, then register, set up governance and take the measures that follow from your risk assessment. Because the law is already in force, it makes sense to address the basic obligations first and then improve step by step.
The steps below give a practical order. They are not a legal requirement in themselves, but they follow the structure of the obligations.
Step 1: establish scope and register
First determine whether your organisation is covered and whether it is an essential or important entity. Use the RDI self-assessment tool and check your sector, your size and any group relationships.
Points to record in this step:
- Sector: which of your activities fall within one of the eighteen sectors
- Size: your number of employees, turnover and balance-sheet total, including partner and linked enterprises
- Classification: whether you are an essential or important entity, and which supervisor is competent
- Registration: registering with the NCSC and keeping that registration up to date
Step 2: set up governance and assess risks
Next, organise responsibility and carry out a risk assessment. The management body approves the assessment and the measures, so involve it from the start.
Practical steps include:
- Roles: appoint someone responsible for cybersecurity and define who reports to the board
- Inventory: map your critical processes, systems, data and suppliers
- Risk assessment: identify threats and vulnerabilities and assess their likely impact
- Training: plan training for the management body and for staff
Step 3: prepare for incidents and reporting
Finally, make sure you can detect an incident, handle it and report it on time. The 24-hour deadline leaves no room to work out the procedure during a crisis.
Make sure you have:
- Incident response plan: who does what when an incident occurs, including external experts
- Reporting procedure: who decides whether an incident is significant, and who reports to the CSIRT and the supervisor
- Templates: prepared formats for the early warning, the notification and the final report
- Testing: regular exercises and checks that your backups and recovery actually work
Keep a record of incidents, decisions and reports. That record helps you meet the reporting duty and shows a supervisor how you handled the situation.
How do you manage NIS2 in practice?
NIS2 compliance is not a one-off project. Threats, systems and suppliers change, so your risk assessment and measures must be reviewed regularly. The practical questions below often determine whether compliance works in daily operations.
How do you deal with suppliers and contracts?
The duty of care extends to your supply chain, so you must also manage the cybersecurity risks of your suppliers and service providers. In practice, this is done largely through contracts.
Points to address in supplier contracts include:
- Security requirements: the measures the supplier must take, in line with your own risk assessment
- Incident notification: a short deadline for the supplier to inform you of incidents, so that you can meet your own reporting deadlines
- Audit and information: your right to request information and to have compliance checked
- Subcontracting: rules on the use of subcontractors and the transfer of obligations
- Liability and termination: what happens if the supplier fails to comply, and how you can end the relationship
Review existing contracts with your most important IT and service providers first. New contracts can include standard NIS2 clauses from the outset.
How do you keep compliance up to date?
Plan regular reviews of your risk assessment and measures, and update them after incidents, major changes in your systems or new guidance from your supervisor. Test whether your measures are effective, for example through internal audits, exercises or technical tests.
Practical steps include:
- Review cycle: set a fixed moment, for example once a year, for the board to review the risk assessment
- Lessons learned: analyse every incident and adjust your measures where needed
- Documentation: keep your policies, decisions and test results up to date, so that you can show a supervisor what you have done
- Monitoring: follow guidance from the NCSC and your sector supervisor
What about budget, staff and personal data?
Compliance requires investment in people, processes and technology. The law does not set an amount: the measures must be proportionate to your size and risks. Make the budget part of the board’s decision on the risk assessment, so that the link between risks and measures is clear.
Many organisations also need specialist knowledge they do not have in-house. External support can help, but responsibility remains with your organisation and its management body.
NIS2 also overlaps with the General Data Protection Regulation (GDPR). If an incident involves personal data, a separate notification to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) may be required. Align your NIS2 procedure with your data breach procedure, so that one incident does not lead to two separate, uncoordinated processes.
An illustrative example: a medium-sized logistics company with 80 employees discovers ransomware on its planning system on a Friday evening. Its incident plan names the person who decides whether the incident is significant. That person sends an early warning within 24 hours, follows it with a notification within 72 hours and, because customer data may be affected, also assesses whether a data breach notification is needed. The final report follows within a month.
Frequently asked questions
What is NIS2 and how does it affect businesses in the Netherlands?
NIS2 is an EU directive on cybersecurity, implemented in the Netherlands by the Cybersecurity Act (Cyberbeveiligingswet), in force since 15 August 2026. Organisations within scope must register with the NCSC, take appropriate security measures and report significant incidents within set deadlines.
Which sectors are impacted by NIS2 in the Netherlands?
Eighteen sectors are covered, including energy, transport, banking, healthcare, drinking water, digital infrastructure, public administration, manufacturing, waste and postal services. Within those sectors, the law generally applies to organisations with at least 50 employees, or with turnover and balance-sheet total both above €10 million.
What are the consequences of non-compliance with NIS2?
Supervisors can impose fines of up to €10 million or 2% of worldwide annual turnover for essential entities, and up to €7 million or 1.4% for important entities, whichever is higher. They can also take other enforcement measures, and the management body can be held accountable.
How can organisations prepare for NIS2 compliance?
Establish whether you are in scope, register with the NCSC, have the management body approve a risk assessment and measures, train staff and directors, and prepare an incident and reporting procedure. Because the law is already in force, start with these basics now.
In summary
- The Cybersecurity Act, the Dutch implementation of NIS2, has applied since 15 August 2026 to an estimated eight thousand organisations in eighteen sectors.
- Your organisation is generally covered if it has at least 50 employees, or turnover and balance-sheet total both above €10 million; some providers are covered regardless of size.
- The core obligations are the duty of care, reporting significant incidents (24 hours, 72 hours, one month) and registration with the NCSC.
- The management body approves and supervises the measures, follows training and can be held accountable; supply chain security runs largely through contracts.
- Fines can reach €10 million or 2% of worldwide turnover for essential entities, and €7 million or 1.4% for important entities.
Unsure where you stand? Tell us about your situation. We will let you know your options within one working day.
How Law & More can help you with this is explained on our IT lawyer page.


