
When does NIS2 take effect? Deadlines & legislation explained
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript
Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript

NIS2 and the Cyber Security Act: when is it mandatory?
The European NIS2 Directive has been in effect since early 2023, but each EU country must transpose the rules into its own national legislation. In the Netherlands, this is being done through the Cyber Security Act (CBW). The effective date of the Cyber Security Act has now been finalized: August 15, 2026. This means that organizations in the Netherlands must have completed their NIS2 implementation to be NIS2-compliant.
The time to act is now
The entry into force of the Cyber Security Act is a fact, and the requirements for NIS2 compliance demand time and attention. The directive emphasizes structural risk management, executive accountability, and supply chain collaboration. Whether you work for a municipality, healthcare institution, IT service provider, or SME: there is a good chance that your organization will soon fall under the law or will need to comply with NIS2 requirements as a supplier to NIS2-regulated organizations.
{{LINKCARD}}
What has changed since the NIS2/Cyber Security Act came into effect?
The introduction of the Cyber Security Act makes cybersecurity a legal obligation. Key changes include:
- Executive accountability: executives are personally responsible for cybersecurity.
- Reporting obligation: serious incidents must be reported within 24 hours.
- Supply chain management: supply chain partners must be able to demonstrate that they work securely.
- Policy obligation: organizations must document and maintain their security measures.
With the Cybersecurity Act these requirements are legally binding in the Netherlands. Since the act came into effect, the regulator can impose fines on organizations that do not comply with the law (NIS compliance).
The role of ISO 27001 in NIS2 implementation
Many organizations already work with ISO 27001. This is a major advantage, as this standard aligns closely with the requirements of NIS2. A well-implemented ISMS (Information Security Management System) assists with risk management, internal audits, policy, and reporting – all of which are also required under NIS2. A NIS2 consultant can help determine, based on ISO 27001, which additional measures are necessary to become fully compliant with the Cybersecurity Act. This allows you to build on existing processes and avoid duplication of effort.
NIS2 Supply Chain quality mark: demonstrable reliability
In addition to legal compliance, there is also a need for practical proof. The NIS2 Supply Chain certificate (NIS2 SC) is a quality mark for suppliers working with organizations that fall under NIS2. With this NIS2 quality mark, you demonstrate that your organization meets the key requirements regarding information security and NIS2 cybersecurity.
What you can do now: start with a NIS2 GAP analysis
The Cyber Security Act is now a reality, and implementation takes time. By starting with a NIS2 GAP analysis, you will quickly know where your organization stands and what steps are needed for Cbw compliance. The Cyber Security Act comes into effect on August 15, 2026 . There is no more time to wait to start your NIS2 implementation. The sooner you begin, the sooner you will meet the requirements of NIS2 and supply chain responsibility.
Our consultants conduct NIS2 audits and assessments, helping organizations across the Netherlands with NIS2 implementation: from initial baseline measurements to full compliance journeys. Want to know if your organization meets the requirements of the upcoming Cyber Security Act? Schedule a free, no-obligation introductory meeting with Kilian below.

%202.png)
.jpg)


















