Legislation

When does NIS2 take effect? Deadlines & legislation explained

NIS2
News
Legislation

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

The NIS2 Directive and the Cyber Security Act bring major changes for organizations in the Netherlands. Where the first NIS directive mainly applied to vital sectors, NIS2 expands the scope considerably. But what is the NIS2 effective date, when does the Cybersecurity Act actually take effect and what does that mean for your organization?

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

This article was last updated on
27.08.2026
Written by
Mathijs
Oppelaar
Operational Manager & Partner

NIS2 and the Cyber Security Act: when is it mandatory?

The European NIS2 Directive has been in effect since early 2023, but each EU country must transpose the rules into its own national legislation. In the Netherlands, this is being done through the Cyber Security Act (CBW). The effective date of the Cyber Security Act has now been finalized: August 15, 2026. This means that organizations in the Netherlands must have completed their NIS2 implementation to be NIS2-compliant.

The time to act is now

The entry into force of the Cyber Security Act is a fact, and the requirements for NIS2 compliance demand time and attention. The directive emphasizes structural risk management, executive accountability, and supply chain collaboration. Whether you work for a municipality, healthcare institution, IT service provider, or SME: there is a good chance that your organization will soon fall under the law or will need to comply with NIS2 requirements as a supplier to NIS2-regulated organizations.

{{LINKCARD}}

What has changed since the NIS2/Cyber Security Act came into effect?

The introduction of the Cyber Security Act makes cybersecurity a legal obligation. Key changes include:

 

  • Executive accountability: executives are personally responsible for cybersecurity.
  • Reporting obligation: serious incidents must be reported within 24 hours.
  • Supply chain management: supply chain partners must be able to demonstrate that they work securely.
  • Policy obligation: organizations must document and maintain their security measures.

 

With the Cybersecurity Act these requirements are legally binding in the Netherlands. Since the act came into effect, the regulator can impose fines on organizations that do not comply with the law (NIS compliance).

The role of ISO 27001 in NIS2 implementation

Many organizations already work with ISO 27001. This is a major advantage, as this standard aligns closely with the requirements of NIS2. A well-implemented ISMS (Information Security Management System) assists with risk management, internal audits, policy, and reporting – all of which are also required under NIS2. A NIS2 consultant can help determine, based on ISO 27001, which additional measures are necessary to become fully compliant with the Cybersecurity Act. This allows you to build on existing processes and avoid duplication of effort.

NIS2 Supply Chain quality mark: demonstrable reliability

In addition to legal compliance, there is also a need for practical proof. The NIS2 Supply Chain certificate (NIS2 SC) is a quality mark for suppliers working with organizations that fall under NIS2. With this NIS2 quality mark, you demonstrate that your organization meets the key requirements regarding information security and NIS2 cybersecurity.

What you can do now: start with a NIS2 GAP analysis

The Cyber Security Act is now a reality, and implementation takes time. By starting with a NIS2 GAP analysis, you will quickly know where your organization stands and what steps are needed for Cbw compliance. The Cyber Security Act comes into effect on August 15, 2026 . There is no more time to wait to start your NIS2 implementation. The sooner you begin, the sooner you will meet the requirements of NIS2 and supply chain responsibility.

 

Our consultants conduct NIS2 audits and assessments, helping organizations across the Netherlands with NIS2 implementation: from initial baseline measurements to full compliance journeys. Want to know if your organization meets the requirements of the upcoming Cyber Security Act? Schedule a free, no-obligation introductory meeting with Kilian below.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

How many people participate?

Request now

Thanks!
Oops! The form could not be submitted. Please try again.

More resources

Legislation

Cybersecurity Act (NIS2) incident reporting procedure: the step-by-step plan as a download

by
Mathijs
Download
Join our team

Employee Spotlight: from consultant to marketing manager

by
Jurre
Blog
Legislation

What is the difference between NIS and NIS2?

by
Mathijs
Kennisartikel