Information Security

What is NIS2?

Information Security
Legislation
Implementation

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

At the end of 2024, the NIS2 directive will be active. This directive will set stricter requirements for the information security of organizations. But what is the NIS2 exactly? Who must comply and how can you comply? What are the consequences if you do not comply with this? In this blog, we answer all these questions.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

This article was last updated on
14.07.2026
Written by
Mathijs
Oppelaar
Operational Manager & Partner

What is NIS2?

NIS2 is a European cybersecurity directive and the successor to the first NIS directive from 2016, which was implemented in the Netherlands at the time via the Security of Network and Information Systems Act (Wbni). NIS2 has a much greater impact: more sectors, more organizations, and stricter requirements.

A directive is not a law in itself. NIS2 is a mandate from the EU to its member states to transpose its content into national legislation. In the Netherlands, this is the Cybersecurity Act (Cbw), which replaces the Wbni.

When does NIS2 come into effect?

The European NIS2 directive itself has been in force since January 2023. Each member state had to translate the directive into national legislation; in the Netherlands, this was done via the Cybersecurity Act. That legislative process took longer than planned. On July 7, 2026 the Senate approved the Cybersecurity Act. The act will enter into force on August 15, 2026 , without a transition period. The latter is important. There is no grace period of six months or longer. The obligations apply immediately as of August 15.

Who must comply with the Cybersecurity Act?

The act applies to organizations from 18 sectors, including energy, drinking water, digital infrastructure, healthcare, government, and transport. According to the national government, more than 8,000 organizations new obligations will apply in the Netherlands from August 15, 2026. But it doesn't stop there. Tens of thousands of suppliers to these organizations will also face new requirements.

Within the mentioned sectors, a distinction is made between two types of organizations:

  • Essential entities: including utility companies (energy, water), financial institutions, government services, hospitals, and transport and communication services.
  • Important entities: companies that provide critical services to essential entities and organizations that manage important infrastructure.

The size of your organization also plays a role:

  • Large organizations: at least 250 employees, or an annual turnover of more than 50 million euros and a balance sheet total of more than 43 million euros.
  • Medium-sized organizations: at least 50 employees, or an annual turnover and balance sheet total of more than 10 million euros.

Micro and small businesses are generally not covered by the Cybersecurity Act. Exception: certain micro and small businesses in specific sectors, such as trust service providers, top-level domain name registries (.nl/.com/.org), providers of public electronic communications networks, and certain healthcare providers.

Are you unsure whether your organization is covered? The NCTV has an overview (in Dutch) of which organizations fall under the Cyber Security Act.

What does the Cyber Security Act entail?

The act centers on five obligations:

  1. Registration requirement: you register your organization in the entity register of the National Cyber Security Centre (NCSC) via mijn.ncsc.nl (in Dutch). This is mandatory as of August 15, 2026.
  2. Duty of care: you take appropriate measures to manage risks to your network and information systems, prevent incidents, and limit their impact.
  3. Reporting obligation: you report significant incidents to your CSIRT and the competent supervisory authority within the legal timeframe via the reporting portal.
  4. Management responsibility: the board is ultimately responsible for managing cyber risks and must complete appropriate training for this purpose.
  5. Supervision and enforcement: supervisory authorities actively monitor whether organizations are complying with their obligations.

In practice, the duty of care is implemented through concrete measures. Consider:

  • A risk analysis of cyber threats to your organization.
  • An incident response and reporting process.
  • Business continuity: backup management, emergency provisions, and crisis management.
  • Supply chain security, including supplier assessments.
  • Security in system acquisition, development, and maintenance.
  • Cryptography and encryption policy.
  • Physical security: access policy, personnel, and asset management.
  • Multi-factor authentication or similar solutions for access and communication.

How can you comply with the Cybersecurity Act?

With less than two months until the effective date, here is what you can start with now:

  1. Determine whether you fall under the scope of the law directly: directly, or indirectly through the supply chain as a supplier to an organization that does.
  2. Prepare your NCSC registration: This takes more time than expected; do not wait until August 15th for this.
  3. Map out your current situation, for example, with a gap analysis, to see which measures are still missing.
  4. Set up an incident management plan and continuity plan, or document what you already have in place.
  5. Follow the ISO 27001 framework as a guide for your management system: the standard already covers a large part of the duty of care.
  6. Regularly evaluate whether your measures are still effective.

{{LINKCARD}}

What are the consequences of non-compliance?

Failure to comply with the Cyber Security Act can have various consequences, increasing in severity:

  • Warning upon a first finding of non-compliance.
  • Reprimand in the event of persistent non-compliance.
  • Fines: for essential entities up to 10 million euros or 2% of the total global annual turnover (whichever is higher); for important entities up to 7 million euros or 1.4% of the total global annual turnover.
  • Corrective measures, such as a mandatory security audit or temporarily restricting activities.
  • In serious cases: personal liability for directors, potentially including a temporary ban on holding a management position.

If your organization falls victim to a hack that results in confidential information being leaked, the consequences of that incident will be in addition to any sanctions imposed under the Cyber Security Act.

Are you compliant with the Cyber Security Act if you are ISO 27001 or NEN 7510 certified?

Not automatically. ISO 27001 and NEN 7510 cover a large part of the duty of care, but the Cyber Security Act sets additional requirements that are not included in these standards. Examples include the statutory obligation to report within a fixed timeframe and mandatory registration with the NCSC.

  • ISO 27001 is an international standard for information security management systems. The general requirements for policy and management systems align closely with the requirements of NIS2.
  • NEN 7510 is the Dutch standard for information security in the healthcare sector, with specific requirements for the protection of personal data.

Do you already have one of these certifications? Then you have a solid foundation. With a few additional measures—particularly regarding reporting procedures, supply chain management, and executive accountability—you can build that into demonstrable Cyber Security Act compliance.

Need help?

Do you want to know if your organization falls under the Cyber Security Act and what steps are still needed before August 15, 2026? Our consultants can help you with a gap analysis, setting up your management system, and the path to demonstrable compliance.

Schedule a free, no-obligation consultation below.

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum by sit amet, consectetur adipiscing elit, sed do eusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Dis aute irure door in reprehenderit in voluptate velit se cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

How many people participate?

Request now

Thanks!
Oops! The form could not be submitted. Please try again.

More resources

NIS2

Cybersecurity Act effective August 15, 2026: what you need to know

thru
Henry
Kennisartikel
Information Security

NIS2 & ISO 27001: the overlap, differences and how your organization becomes compliant

thru
Mathijs
Download
Legislation

Does the Cyber Security Act (NIS2) apply to me?

thru
Mathijs
Download