
NIS2 and the Dutch Cybersecurity Act: 5 FAQs
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript

Does the Dutch Cybersecurity Act apply to my organization?
That depends on your sector and your size. The Dutch Cybersecurity Act (Cbw) covers eighteen sectors, from energy and healthcare to waste, food and manufacturing. Within those sectors, it applies once you have 50 employees or more. Or when your annual turnover and your balance sheet total both exceed 10 million euros. For some organizations, size does not matter at all, such as DNS providers and public authorities.
If in doubt, take the official NIS2 self-assessment by the RDI (in Dutch) or our free NIS2 check. If your organization is part of a group, use the figures for the whole group. And if you provide managed ICT services, the act may apply to you directly.
If the act does not apply to you, you will often still run into it through your customers. They also have to manage the risks at their direct suppliers. So a regulator will not come knocking, but your customer will, with a questionnaire. You can see what that looks like in this example of a NIS2 questionnaire for suppliers.
What do you actually need to do under the Cybersecurity Act?
If the act applies to you, you have four obligations. They have applied since 15 August 2026, without a transition period. If you wait until the regulator asks, you are already behind.
- Register with the NCSC. This tells the government that the act applies to you. Read how to register with the NCSC.
- The duty of care. You take appropriate measures against the risks to your network and information systems. The act lists at least ten, from risk analysis to business continuity and the security of your supply chain.
- The reporting obligation. You report a significant incident in three steps. You send an early warning within 24 hours, the notification follows within 72 hours and the final report no later than a month after that. See the reporting deadlines from 24 hours to one month.
- The obligations for directors. The board approves the measures, keeps its own knowledge up to date and completes training for that purpose. Read the obligations for directors on one page.
Where do you start? By knowing where you stand today. A gap analysis compares your current measures with the requirements of the act. That gives you an action list instead of a pile of questions.
Is ISO 27001 enough for NIS2?
No, ISO 27001 on its own does not mean you meet the requirements of the act. It is a good foundation, though, because ISO 27001 and the duty of care largely ask for the same things. The government itself uses ISO 27001 and NEN 7510 as a starting point, and you may keep using your own framework. But according to the frequently asked questions of the RDI (in Dutch), a certificate is no proof that you meet the duty of care.
There are a few things ISO 27001 does not arrange for you, such as the registration, the reporting deadlines and the training for directors. Scope matters too: does your certificate cover all systems of the service for which the act applies to you? That is why we use ISO 27001 as the foundation and embed the additional requirements of the act in that same management system. You can read how that works in our free whitepaper ISO 27001 vs NIS2.
{{LINKCARD}}
Who supervises the Cybersecurity Act?
That differs per sector. The Dutch Authority for Digital Infrastructure (RDI) supervises energy, digital infrastructure, ICT service management, government and manufacturing, among others. The Human Environment and Transport Inspectorate (ILT) covers transport, drinking water, waste and chemicals, among others. Healthcare falls under the Health and Youth Care Inspectorate (IGJ), and some regulators cover a single sector, such as De Nederlandsche Bank (DNB) for banking.
If your financial institution also falls under DORA, those rules take precedence. You report an incident in one go via the NCSC reporting portal, to both the CSIRT and your regulator. You can find out which regulator covers your sector in the overview of regulators by the NCSC (in Dutch).
When does the regulator carry out supervision?
That depends on the type of organization. An essential entity is subject to proactive supervision. The regulator may then request information, have an audit carried out or inspect, even without a specific reason. An important entity is subject to reactive supervision. The regulator then only steps in when there are indications that you are breaking the law, for example after an incident. Large organizations in the most critical sectors are essential entities.
Supervision has been in place since 15 August 2026. In the first year, the RDI mainly wants to get to know the sectors, through letters, meetings and mandatory questionnaires. No fine-free period has been announced anywhere, and the RDI can already enforce the registration. Fines can reach 10 million euros or 2% of worldwide annual turnover for an essential entity. For an important entity, the maximum is 7 million euros or 1.4%, and the higher amount always applies.
Want to know where your organization stands?
No two organizations start from the same position. One is already ISO 27001 certified, another does not yet know whether the act applies. Schedule a free, no-obligation consultation with Kilian, and together we will look at the logical first step for you. You can find more background on our page about NIS2 and the Dutch Cybersecurity Act.



.avif)

















