NIS2 in the Netherlands: what the Cyberbeveiligingswet has required since 15 August 2026

Compliance9 min read·
K

Kees van der Vlies

Partner | IT Auditor

Also available in:Nederlands

NIS2 is no longer a European prospect in the Netherlands. On 15 August 2026 the Cyberbeveiligingswet entered into force, together with the decree that fills in its details. The act transposes Directive (EU) 2022/2555 into Dutch law and repeals the previous Network and Information Systems Security Act, the Wbni. An estimated eight thousand organisations across eighteen sectors have had a registration duty, a duty of care and a reporting duty since that date. With no transition period: the obligations applied from day one.

Why it matters that NIS2 is a directive

NIS2 is a directive, not a regulation. A directive binds member states to a result and leaves them the form. Organisations are therefore not governed by NIS2 itself but by the national law that follows from it. In the Netherlands that law is the Cyberbeveiligingswet. If you are preparing, read the act rather than the directive.

The difference becomes obvious when you put NIS2 next to DORA. DORA is a regulation and has applied directly and identically across all member states since 17 January 2025. NIS2 leaves room for national variation in thresholds, reporting channels and supervision. For organisations with entities in several member states that is not an academic point: your obligations in the Netherlands and in Germany can differ in detail.

NIS2 replaced the original NIS directive from 2016. The transposition deadline was 17 October 2024. The Netherlands missed it, which left many organisations with the impression that the law would stay away for a while yet. Since August 2026 that impression is wrong.

Do you fall under it? You decide that yourself

The biggest change compared with the old Wbni is not in the measures but in how you come into scope. Under the Wbni you were designated. Under the Cyberbeveiligingswet you are an essential or important entity by operation of law, based on your sector and your size. No letter arrives. Waiting for one means being late.

The main rule: you operate in one of the sectors listed in the annexes to the act, and you are medium sized or larger, meaning more than fifty employees or more than ten million euro in annual turnover. Exceptions run in both directions. Smaller organisations can still be designated, for example on the basis of a national criticality assessment or because they were already providers of an essential service under the Wbni. Higher education institutions follow their own route, with thirty six months after designation to meet the duty of care and the management obligations.

There is a third route into the law, and it appears in none of the annexes: your customer's contract. The duty of care includes supply chain security, so entities pass requirements down to their suppliers. A software vendor with fifteen employees falls outside the act and still receives a questionnaire, an audit right and reporting deadlines at contract renewal. Anyone heading that way is better off getting their own supplier management in order first.

Essential or important: the difference is in the supervision

Both categories carry the same duty of care and the same reporting deadlines. What differs is how supervision works and what a regulator may deploy. For essential entities supervision is proactive: a regulator can turn up on its own initiative, without an incident or a signal. For important entities supervision is reactive, so only once there is cause.

That difference carries through to the enforcement toolkit. Against essential entities a regulator can use heavier instruments, up to suspending a licence or certification and suspending a board member. The fine ceilings differ too: 10 million euro or 2 percent of worldwide annual turnover against 7 million euro or 1.4 percent, with the higher amount applying in both cases.

One nuance about those fines gets lost in most summaries. The high ceilings apply to the duty of care and the reporting duty. Breach the registration duty and the maximum is 1 million euro, even for an essential entity. An individual board member can be fined up to 25,000 euro in their own right.

The three obligations

Registration. You register your organisation in the national entity register held by the NCSC, using eHerkenning at level EH2+ or SSOnRijk. You provide name and address, contact details, the sectors you operate in and the member states where you provide services. Changes to those details go in within two weeks. This is the cheapest obligation in the entire act and also the most visible one: a regulator wanting to know whether you have done anything looks here first.

Duty of care. The act lists ten categories of measures: risk analysis and information security policy, incident handling, business continuity and crisis management, supply chain security, secure acquisition, development and maintenance including vulnerability handling, assessing the effectiveness of measures, cyber hygiene and training, cryptography, personnel security and access control, and multi-factor authentication with secure communications. The act asks for measures that are appropriate and proportionate, so matched to your size and risk profile. That is not a free pass. It means you have to be able to explain why your choices fit your risks, which calls for a documented gap analysis rather than a general sense that things are fine.

Reporting duty. The deadlines are tiered. Within 24 hours of becoming aware of a significant incident you submit an early warning. Within 72 hours the incident notification follows, with an initial assessment of nature, severity and impact; for trust service providers that deadline is 24 hours. A final report is due no later than one month after that notification. If the incident is still running, you submit a progress report at that point and the final report within one month of resolution. An intermediate report is only required if the CSIRT or the competent authority asks for one. You report to both the CSIRT and the competent authority, for which a central reporting portal is available. What counts as significant is not set out in the act itself but in sector specific ministerial regulations containing thresholds, and those differ per sector. Check what applies to your sector before you design your incident process.

What is expected of board members

The act places two things with the board. The board approves the measures and supervises their implementation. Board members also have to follow training so they can assess cyber risks. That training does come with a deferred deadline: two years after entry into force, so by 15 August 2028 at the latest. It is the only meaningful postponed obligation in the act, and it is not a reason to postpone the rest.

Who supervises

The Dutch Authority for Digital Infrastructure, the RDI, supervises digital infrastructure, energy, government, digital providers, managed ICT services, space, and postal and courier services among others. Alongside it, the Human Environment and Transport Inspectorate covers transport, water, waste and chemicals, De Nederlandsche Bank covers banking, the AFM covers financial market infrastructure, the healthcare inspectorate IGJ covers health, the NVWA covers food and the ANVS covers nuclear. For research and higher education no supervisor had been appointed as of mid August 2026.

No grace period has been announced. The RDI has said it wants to use the first year mainly to get to know the sectors under its supervision, while calling the registration duty a legal obligation that can be actively enforced. Do not plan around leniency.

Where implementations go wrong

Four patterns keep coming back in the organisations we speak to.

The scoping decision is not written down. At some point someone concluded the organisation was out of scope, but the reasoning exists nowhere. Under self-identification that is a problem, because the burden of proof sits with you. Document the analysis, including when the conclusion is that you fall outside the act, and revisit it when your sector classification or your size changes.

The duty of care is treated as equal to the certificate. An ISO 27001 certification covers much of the ten categories, but the scope of the certificate is often narrower than the service the duty of care applies to. Compare those two scopes before concluding you are done.

The reporting process has never been rehearsed. Twenty four hours sounds generous until the clock starts during a crisis in which nobody knows who is allowed to decide that a report goes out. Decide in advance who makes that call, and rehearse it once.

Supply chain requirements only apply to new contracts. Most critical suppliers sit in running contracts with multi year terms. Without a renewal moment nothing happens, and supply chain security stays on paper.

Where to start

If you have done nothing yet: determine and document your scope, register if you are in scope, and put the ten categories next to what you already have. That comparison shows within a day or two where the work is. We run that analysis as part of our compliance services and deliver a gap analysis with reasoning you can put in front of a regulator.

For the Dutch act in detail, including the sector classification and the supervisory structure, the Cyberbeveiligingswet is the place to read on. If you would rather have a step by step plan than an explanation of the framework, see NIS2 compliance in 2026.

Frequently asked questions

When did NIS2 start to apply in the Netherlands?+

The NIS2 directive had to be transposed into national law by 17 October 2024. The Netherlands did so through the Cyberbeveiligingswet, which entered into force on 15 August 2026 together with the accompanying decree. The registration duty, the duty of care and the reporting duty have applied since that date. There is no general transition period.

Will I be notified if my organisation falls under the law?+

No. The Cyberbeveiligingswet works through self-identification: you are an essential or important entity by operation of law, based on your sector and your size. You register yourself in the national entity register held by the NCSC, using eHerkenning level EH2+ or SSOnRijk. Changes to your registration details must be submitted within two weeks.

Is an ISO 27001 certificate enough to meet the duty of care?+

Not by itself. The overlap is substantial and a working management system saves a lot of effort. But the duty of care applies to the service you provide, while the scope of an ISO 27001 certificate is often narrower. The reporting duty, the registration duty and the management obligations sit outside the certification entirely.

How high are the fines?+

For breaches of the duty of care or the reporting duty, essential entities face up to 10 million euro or 2 percent of worldwide annual turnover, and important entities up to 7 million euro or 1.4 percent, whichever is higher. For other breaches, including the registration duty, the maximum is 1 million euro. An individual board member can be fined up to 25,000 euro.

How does this relate to the Wet weerbaarheid kritieke entiteiten?+

The Cyberbeveiligingswet covers digital resilience and works through self-identification. The Wet weerbaarheid kritieke entiteiten implements the European CER directive, covers physical resilience and works through designation by the responsible minister. Both took effect on 15 August 2026. An organisation designated as a critical entity automatically qualifies as an essential entity under the Cyberbeveiligingswet.

Need help with compliance?

Need to comply with ISO 27001, ISO 42001, NEN 7510, NIS2 or DORA, or do you need a SOC 2 report? We guide you through the entire process: from gap analysis to implementation.

Explore Compliance Services

About the author

K
Kees van der Vlies

Partner | IT Auditor

Back to knowledge base

Have a question?

Get in touch for advice on IT audit, compliance and information security.

Contact us
NIS2 in the Netherlands: the Cyberbeveiligingswet explained · Secure Audit