NIS2

Cybersecurity Act (NIS2) registration obligation: how to register with the NCSC

Implementation
Legislation
Required

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

The Cyber Security Act takes effect on August 15, 2026. Does it apply to you? If so, registering with the NCSC is one of your four obligations, alongside the duty of care, the reporting obligation, and management accountability. While the other three primarily concern how you manage cyber risks, the registration obligation is more concrete: it is the entry requirement that gets you started. In this article, you will learn what the registration obligation entails, what you need to register, what the form looks like, and what happens if you do not complete it on time.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

This article was last updated on
17.08.2026
Written by
Kilian
Houthuijzen
Commercial Manager & Partner

What does the registration obligation under the Cyber Security Act (NIS2) entail?

All essential and important entities under the Cyber Security Act must submit their organizational details for the national entity register. In the Netherlands, this is done via mijn.ncsc.nl. This register gives the EU visibility into which organizations are subject to the law, and once you are registered, the NCSC can reach you with relevant threat intelligence. Not sure if your organization falls under the law? Take our NIS2 Quickscan first before proceeding; it will save you some research.


{{LINKCARD}}

When do you register with the NCSC?

The registration obligation applies from the moment the law becomes applicable to your organization. In principle, this was August 15, 2026, the day the Cyber Security Act came into effect. If you are not yet in the register but fall under the law, you are behind schedule, and registration should be your first priority. You may also become subject to the law at a later date, for example, if your organization grows, your activities change, or you enter a different sector following an acquisition. From that moment on, the registration obligation applies to you.

 

Keep in mind that the preparation takes longer than the form itself. Requesting eHerkenning at the correct level can easily take a few days, and that is not something you want to discover on the day you intend to register. Organizations not subject to NIS2 are also welcome to register. You will then gain access to faster communication with the NCSC, personalized support, and an information partner. Definitely worth it!

What do you need for your NIS2 registration?

eHerkenning at level EH2+

eHerkenning is a secure and reliable login method that allows entrepreneurs and organizations to handle online business with the government and other services. You can think of it as a kind of DigiD for businesses. For MijnNCSC, you need eHerkenning at reliability level EH2+ (the reliability level for business logins), linked to your organization's Chamber of Commerce (KvK) number, plus authorization to register on behalf of the organization.

If you work for an affiliated central government organization, you use Government Single Sign-On. This must be authorized once in advance.

 

The information you need to provide

You will soon be entering organization, contact, and network details, including public IP addresses or IP ranges, domain names, and AS numbers. This information is often spread across different colleagues, such as the CISO or network administrator, and sometimes with your hosting provider. Gather this beforehand so you can complete the registration in one go.

 

Who should complete the registration

Have the registration completed by someone with decision-making authority, preferably with knowledge of cybersecurity. In many organizations, this is the CISO or IT manager; in smaller organizations, it is the owner or compliance officer.

How to complete your NIS2 registration with MijnNCSC, step by step

After logging in, you will go through five screens. With everything at hand, you will be finished in about ten minutes.

 

  1. Go to mijn.ncsc.nl and log in. You do this using eHerkenning at level EH2+, linked to your organization's Chamber of Commerce (KvK) number and with authorization to act on behalf of the organization. Government employees log in using Government Single Sign-On.
  2. Enter your organization details. The basic details of your organization, such as name, Chamber of Commerce (KvK) number, and address.
  3. Enter the additional organization details. Here, you specify which sector and subsector under the law you fall under, and in which EU member states you provide the services covered by the law. This information helps determine whether you are classified as an important or essential entity.
  4. Enter your contact details. The NCSC must be able to reach you in the event of a threat or incident. Therefore, ensure you provide a contact person, email address, and phone number that remain accessible even if the person who filled out the form is unavailable.
  5. Enter your network details. Public IP addresses or IP ranges, domain names, and AS numbers. This is the section where most organizations get stuck, as this information is usually held by a different colleague than the person filling out the form.
  6. Review the summary and submit. You will receive an overview of everything you have entered. Once submitted, you are registered.

If something changes later, for example after a merger or a change in your IP ranges, please report it within 14 days via MijnNCSC.

In which EU country do you register if you are active in multiple member states?

This is where things often go wrong, as every organization has a principal place of business, leading to the assumption that you register there. The law only uses the principal place of business for one specific group of providers.

 

Digital service providers register at their principal place of business

This concerns a fixed list: providers of DNS services, TLD registries, domain name registration services, cloud computing services, data center services, content delivery networks, managed service providers, managed security service providers, online marketplaces, online search engines, and social networking service platforms.

 

They register once, so that the same provider does not have to do so in every member state. Your principal place of business is the member state where you predominantly make decisions regarding your cybersecurity measures. If that cannot be determined, the member state where your cybersecurity operations are carried out counts, and otherwise, the member state where your largest establishment in terms of personnel is located.

 

All other organizations must register in each member state where they are established.

Note the difference between being established and being active, as this is where the confusion lies. A Dutch organization with only a Dutch office that also serves customers in Belgium and Germany registers exclusively in the Netherlands. If you have an office in Belgium that is subject to local law, you must register in both the Netherlands and Belgium.

 

Two exceptions to keep in mind

If you provide public electronic communications networks or services, you fall under the jurisdiction of the member state where you provide those services. If your organization is based outside the EU but provides services within the EU, you must appoint a representative in one of the member states where you are active and fall under the jurisdiction of that member state.

 

If you are unsure about your situation, this is a good time to consult with us before you start the registration process.

NIS2 fines: what happens if you don't register or register late?

The registration requirement is a legal obligation and is strictly enforced. Failure to register or incorrect registration can lead to fines or administrative enforcement orders. Under the NIS2 directive, these can reach up to 10 million euros or 2% of your total global annual turnover for essential entities, and up to 7 million euros or 1.4% for important entities. Reason enough not to leave this until the last week.

Registration is one step; compliance is a journey

Once you are registered, the work isn't over. Registration is an administrative step, but the duty of care and reporting obligations require you to demonstrate that you are managing risks and are capable of reporting incidents. Many organizations use registration as a starting point to map out the rest of their Cyber Security Act journey, for example with a gap analysis: where do you stand now, and what is still needed to demonstrably comply?

Need help with your Cyber Security Act journey?

You handle the registration yourself using your own eHerkenning and organizational details. But the questions that follow—what is expected of you and how to prove it—are exactly what we help companies with at Fendix. From an initial gap analysis to full guidance toward compliance. Want to know where your organization stands? Schedule a free, no-obligation consultation below.

From registration to NIS2 compliance: what else is involved?

Registration gets you on the books, but then the work the law is actually about begins. The duty of care requires you to manage your risks, and the reporting obligation requires you to report incidents within the specified timeframes. Both revolve around accountability: can you show that you are taking action?

 

Many organizations therefore use registration as a starting point before mapping out the rest of their Cyber Security Act journey, for example with a gap analysis. Where do you stand now, and what is still needed to demonstrably comply? Compliance is not a one-off sprint, so it helps to know what pace you can sustain.

Help with your Cyber Security Act journey

The starting gun has fired: the law is in effect. You handle the registration yourself, using your own eHerkenning and organization details. The questions that follow—what is expected of you and how to demonstrate compliance—are exactly what we help companies with at Fendix. From an initial gap analysis to full guidance toward compliance.

 

Want to know where your organization stands? Schedule a no-obligation, free consultation below.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

How many people participate?

Request now

Thanks!
Oops! The form could not be submitted. Please try again.

More resources

Legislation

When does NIS2 take effect? Deadlines & legislation explained

by
Mathijs
Kennisartikel
Quality Management

ISO 9001:2026: what is changing and what does it mean for your certificate?

by
Mathijs
Kennisartikel
NIS2

Download our NIS2 checklist!

by
Ruben
Download