Wemso Group

Cybersecurity regulation

NIS2 in the Netherlands: What the Cybersecurity Act Means for Businesses

The Dutch Cybersecurity Act entered into force on 15 August 2026. This guide explains which organisations can fall within scope and what the law requires.

Published 5 min read

In brief

The Dutch Cybersecurity Act, which implements NIS2 in the Netherlands, entered into force on 15 August 2026. Organisations within scope must register, manage cybersecurity risks, report significant incidents and ensure board-level responsibility. Scope depends mainly on sector, organisation size and specific statutory exceptions.

Key facts

  • The Cybersecurity Act implements the EU NIS2 Directive in the Netherlands and replaces the previous Security of Networks and Information Systems Act.
  • The Dutch government states that the law introduces obligations for more than 8,000 organisations across 18 sectors.
  • The main requirements include registration, a duty of care, incident reporting, board responsibility, supervision and enforcement.

What is NIS2 and how is it implemented in the Netherlands?

Directive (EU) 2022/2555, known as NIS2, establishes a common EU framework for cybersecurity risk management and incident reporting in critical sectors.

The Netherlands implemented the directive through the Cybersecurity Act. The Dutch law entered into force on 15 August 2026 and replaced the previous Security of Networks and Information Systems Act.

When did the Dutch Cybersecurity Act enter into force?

The Cybersecurity Act entered into force on 15 August 2026. From that date, organisations within its scope became subject to the applicable registration, duty-of-care and reporting requirements.

Which sectors are covered by NIS2 in the Netherlands?

The Netherlands Enterprise Agency lists the following sectors from Annexes I and II of the NIS2 Directive:

  • Energy, transport, banking and financial market infrastructure
  • Healthcare, drinking water and wastewater
  • Digital infrastructure and B2B ICT service management
  • Public administration and space activities
  • Digital providers and postal or courier services
  • Waste management
  • Manufacturing, production and distribution of chemicals
  • Production, processing and distribution of food
  • Research and manufacturing

Does NIS2 apply to every business in a covered sector?

No. As a general rule, the directive applies to public or private entities in the listed sectors that qualify as medium-sized enterprises or exceed the ceilings for medium-sized enterprises.

The Netherlands Enterprise Agency describes a medium-sized organisation as having at least 50 employees, or annual turnover and a balance sheet total above €10 million. It describes a large organisation as having more than 250 employees, or net turnover above €50 million and a balance sheet total above €43 million.

Certain organisations can fall within scope regardless of size. These include the following categories identified by the Netherlands Enterprise Agency:

  • Trust service providers
  • Top-level domain name registries
  • Domain name registration service providers
  • Providers of public electronic communications networks
  • Providers of publicly available electronic communications services

Government organisations in covered sectors are also automatically included, and a minister can designate a micro or small company when its services are vital to the Dutch economy or society.

What are the main obligations under the Dutch Cybersecurity Act?

The Dutch government identifies the following main obligations for organisations within scope:

  • Registration in the entity register through the National Cyber Security Centre.
  • A duty of care requiring measures to manage risks to network and information systems and to prevent incidents or limit their impact.
  • A duty to report significant incidents within the statutory deadlines.
  • Board-level responsibility for cybersecurity risk management and appropriate training for directors.
  • Supervision and enforcement by the responsible authorities.

What does the NIS2 duty of care cover?

The National Cyber Security Centre states that the Cybersecurity Act contains ten minimum duty-of-care measures. Risk management is the basis for determining which measures are appropriate.

  • Risk analysis and information-system security policies
  • Incident response
  • Business continuity, backup management, recovery and crisis management
  • Supply-chain security, including relationships with direct suppliers and service providers
  • Basic cyber hygiene and cybersecurity training
  • Security in the acquisition, development and maintenance of network and information systems, including vulnerability handling
  • Personnel security, access policies and asset management
  • Where appropriate, multi-factor or continuous authentication and secure communications
  • Policies and procedures for cryptography and, where appropriate, encryption
  • Policies and procedures for assessing the effectiveness of cybersecurity risk-management measures

What are the NIS2 incident-reporting deadlines in the Netherlands?

The reporting duty concerns significant incidents. The National Cyber Security Centre describes a three-stage process starting from the moment the organisation becomes aware of the incident:

  • 24 hoursfor an early warning, including whether malicious activity is suspected and whether cross-border consequences are possible.
  • 72 hoursfor an incident notification that updates the warning and provides an initial assessment of severity and impact.
  • 1 monthafter the incident notification for a final report describing the incident, its cause and the measures taken.

If the incident is still ongoing after one month, a progress report is submitted at that point and the final report follows within one month after the incident has been handled. Sector-specific rules can provide a different reporting route or shorter deadlines.

Does NIS2 include supply-chain security?

Yes. The duty of care expressly includes supply-chain security and the security-related aspects of relationships between an organisation and its direct suppliers or service providers.