Legislation

Why is NIS2 important for organizations in the Netherlands?

NIS2
Legislation

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Cyber threats are increasing every day. From ransomware to data breaches: the impact on organizations is significant. The NIS2 directive is the European response to this growing threat. In the Netherlands, this will be translated into the Cybersecurity Act (cbw), which is will be in effect on 15 August 2026. But why is NIS2 so important? And what does it mean for your organization in concrete terms?

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

This article was last updated on
14.07.2026
Written by
Kilian
Houthuijzen
Commercial Manager & Partner

Stronger digital resilience

The first NIS directive laid the foundation for European cooperation in the field of cybersecurity. However, that approach proved too limited. Only vital sectors were covered by the legislation, while other organizations were also falling victim to cyberattacks.

 

With NIS2, that is changing. The directive significantly expands the obligations and ensures that many more organizations must actively demonstrate that their information security is in order. The goal is clear: to strengthen the digital resilience of the Netherlands. Not just for large institutions, but throughout the entire supply chain – from suppliers to service providers.

Who is affected by NIS2?

The new directive does not only apply to government agencies or energy companies. Organizations in sectors such as healthcare, ICT, education, transport, financial services, food, and waste management are also covered. In addition, NIS2 explicitly focuses on suppliers to these organizations. Do you provide services or software to a party subject to NIS2? Then the requirements indirectly apply to you as well.

 

The directive distinguishes between:

 

  • Essential entities – for example, government organizations, telecom, energy, or healthcare.
  • Important entities – such as ICT service providers, manufacturing companies, data centers, and transport companies.

 

For both groups, the requirement is the same: you must demonstrate that you have taken measures to mitigate cyber risks and are capable of handling incidents effectively.

The Cyber Security Act (Cbw)

In the Netherlands, NIS2 has been transposed into national legislation: the Cyber Security Act (Cbw). The effective date is August 15, 2026, once the legislation has been formally passed by parliament. The Cbw defines which organizations fall under the law, who is responsible for oversight (such as the Radiocommunications Agency and sectoral regulators), and what sanctions may be imposed. Fines can be substantial, but the primary goal is awareness and prevention.

No certification, but NIS2 compliance is required

There is no such thing as an official NIS2 certification. However, organizations must be compliant, meaning they must be able to demonstrate that they meet the requirements of the directive and the national law.

 

In practical terms, this means:

 

  • Systematically mapping risks and documenting control measures.
  • Ensuring governance and accountability within the board.
  • Reporting incidents to the competent authority within 24 hours.
  • Establishing supply chain agreements with vendors regarding security and reporting.
  • Regularly assessing whether policies and measures remain effective.

 

An ISO 27001 certification is a huge help in this regard. The ISO standard provides a practical framework (ISMS) that already covers many NIS2 requirements. You can then build on that foundation to address the specific obligations of NIS2.

{{LINKCARD}}

Why you need to start now

The implementation of the Cyber Security Act is fast approaching, and it takes time to get processes, responsibilities, and systems in order. In practice, waiting until the law comes into effect often means starting too late. With a NIS2 GAP analysis you gain insight into your current status and immediately see which steps are needed to achieve compliance. This allows you to take measures in time and avoid surprises during future audits or inspections.

Start your NIS2 compliance journey

NIS2 is important because it strengthens the digital resilience of the Netherlands—not just for large organizations, but for the entire supply chain. The directive requires structural attention to information security, governance, and risk management. By working on NIS2 compliance now, you not only increase your security but also boost the trust of your customers and partners.

 

Schedule a free, no-obligation consultation below.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

How many people participate?

Request now

Thanks!
Oops! The form could not be submitted. Please try again.

More resources

NIS2

Cybersecurity Act effective August 15, 2026: what you need to know

thru
Henry
Kennisartikel
Information Security

NIS2 & ISO 27001: the overlap, differences and how your organization becomes compliant

thru
Mathijs
Download
Legislation

Does the Cyber Security Act (NIS2) apply to me?

thru
Mathijs
Download