Legislation

What does NIS2 mean for Dutch organizations?

Legislation
NIS2

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

The arrival of the NIS2 directive has major consequences for organizations in the Netherlands. Where cybersecurity was previously seen primarily as an IT topic, it is now becoming a legal obligation and a responsibility at the board level. In the Netherlands, the directive will be translated into the Cybersecurity Act (CBW), which will come into force on 15 August 2026. But what exactly does that mean for your organization?

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

This article was last updated on
14.07.2026
Written by
Mathijs
Oppelaar
Operational Manager & Partner

More organizations fall under NIS2

The initial NIS directive only applied to vital sectors, such as energy and telecom. NIS2 goes much further. Healthcare institutions, government bodies, IT service providers, transport companies, financial institutions, and numerous suppliers will soon fall under the new law. The goal: to strengthen the digital resilience of the entire supply chain. After all, a breach at a single supplier can have major consequences for the continuity of other parties. In concrete terms, this means that thousands of organizations in the Netherlands will soon be required to demonstrably have their information security in order.

New obligations under the Cybersecurity Act

The Cybersecurity Act (Cbw) makes NIS2 legally enforceable in the Netherlands and takes effect on August 15, 2026. This means that organizations falling under the directive are required to comply with requirements regarding:

  • Registration obligation: you must register in the entity register of the National Cyber Security Centre (NCSC). This is mandatory as of August 15.
  • Duty of care: you must take appropriate measures to manage the risks to your network and information systems.
  • Reporting obligation: you must report significant cyber incidents.
  • Management responsibility: the board is explicitly responsible for managing cyber risks and must also possess sufficient knowledge of them.

 

The government will oversee compliance through designated authorities. Those who fail to comply may face fines and corrective measures.

NIS2 and ISO 27001: a strong foundation together

Many organizations already work with ISO 27001 for information security. That is good news, as ISO 27001 aligns closely with the requirements of NIS2. An ISO 27001-certified management system (ISMS) helps you manage risks, secure policies, and demonstrate compliance.

 

With a few extra steps—such as specific reporting and notification procedures—you can largely meet the requirements of the Cybersecurity Act based on ISO 27001. Organizations that do not yet have an ISMS can use NIS2 as a catalyst to set one up in a structured way.

{{LINKCARD}}

 

Demonstrable compliance: no NIS2 certification, but compliance is required

There is no official NIS2 certification, but you must be able to demonstrate that you are compliant. This means that during an audit, your organization must be able to show how risks are managed and how security measures are implemented. One way to get started is through a NIS2 check or NIS2 audit. This provides insight into your current situation and identifies where improvements are needed to become compliant.

 

For suppliers, there is the NIS2 Supply Chain certificate (NIS2 SC)—a quality mark that shows you meet the requirements set by NIS2 organizations for their partners. This quality mark increases trust in the partnership and makes it easier to demonstrate that you handle information with care.

The practical impact of NIS2

For many organizations, the introduction of NIS2 means that cybersecurity is no longer just an "add-on" but a core component of business strategy. Executives must be aware of risks, teams must document processes, and suppliers must provide insight into their security levels. This requires a structural approach that integrates policy, technology, and people. Therefore, a NIS2 implementation is not just a regulatory requirement but an opportunity to improve processes and permanently reduce risks.

Demonstrable NIS2 compliance

The NIS2 directive is changing the cybersecurity landscape in the Netherlands. Organizations must be able to demonstrate secure operations, executives are held accountable, and supply chain partners are being critically integrated into security strategies. By starting with a NIS2 check or NIS2 assessment now, you gain insight into your organization's current status and what is needed to become compliant before the Cyber Security Act comes into effect.

 

Schedule a free, no-obligation consultation below to discover where your organization stands and how we can assist with the implementation of the Cyber Security Act in the Netherlands.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

How many people participate?

Request now

Thanks!
Oops! The form could not be submitted. Please try again.

More resources

NIS2

Cybersecurity Act effective August 15, 2026: what you need to know

thru
Henry
Kennisartikel
Information Security

NIS2 & ISO 27001: the overlap, differences and how your organization becomes compliant

thru
Mathijs
Download
Legislation

Does the Cyber Security Act (NIS2) apply to me?

thru
Mathijs
Download