NIS2 and the Dutch Cybersecurity Act: will your SMB have to act?
The Dutch Cybersecurity Act (NIS2) is coming. Find out whether your business falls under it, what is expected of you, and seven steps you can take now.
By Limburg Cyber Group
New cybersecurity legislation is on its way, and it affects far more businesses than you might expect. The European NIS2 directive is being translated into the Dutch Cybersecurity Act (Cyberbeveiligingswet, Cbw), expected to take effect in 2026. An estimated 8,000 Dutch organisations will fall directly under it.
The big question for SMB owners is simple: does this concern me? This article lays it out plainly, without the scare stories.
What is NIS2, in short?
NIS2 is European legislation that requires organisations to have their digital resilience in order. It comes down to three things: taking measures to prevent incidents, reporting incidents to the supervisory authority, and being able to demonstrate that you have things under control. Directors are held personally accountable.
So it is not a technical checklist your IT supplier quietly ticks off. It is a responsibility that sits with management.
Does my business fall under it?
The law distinguishes between essential and important entities, based on your sector and your size. Broadly, it concerns organisations with more than 50 employees or more than 10 million euros in turnover operating in a designated sector, such as energy, transport, healthcare, digital infrastructure, food, and certain business services.
Not sure whether your sector is included? That is understandable, because the scope is not always crystal clear. The interactive NIS2 scan on our website helps you get a sense of it in a few minutes.
Even if it does not apply directly, it can still reach you
This is the part that often gets missed. NIS2 requires organisations to look at their supply chain as well. Do you provide services or software to a company that does fall under the law? Then there is a good chance they will start asking you for guarantees about your security.
For many smaller businesses, think of an accountancy firm or a software studio, cybersecurity becomes a condition for continuing to do business, not because the law demands it directly, but because your clients do.
The checklist: 7 things to arrange now
Whether you fall under the law directly or through your clients, these are the things that matter regardless:
- Map your risks. Which data and systems are critical, and what happens if they go down or leak?
- Sort out access management. Who has access to what, and is two-factor authentication (MFA) enabled everywhere?
- Ensure working backups. Not just making them, but periodically testing that you can actually restore them.
- Keep software up to date. Outdated software remains the most common way in for attackers.
- Create an incident plan. Who does what when things go wrong, and how and when do you report an incident?
- Train your people. Most incidents start with an employee, not with technology.
- Document it. Can you demonstrate in six months that you took these steps? With NIS2, documentation is not an afterthought.
What you should definitely not do
Do not panic and buy an expensive package you do not understand. NIS2 is not about buying as much software as possible, but about being able to demonstrably manage your risks. For most SMBs that means a few months of focused work, not a complete overhaul.
Getting started
Want to know where you stand? Start with the free NIS2 self-scan, or book a no-obligation conversation. Together we take an honest look at what your business actually needs, and what can wait.
Read more
GDPR and NIS2: where they overlap and where they differ
GDPR and NIS2 look alike, but protect different things. Here is how to understand the overlap, the differences, and why you may face both at once.
ISO 27001 vs NIS2: what is the difference and do you need both?
ISO 27001 and NIS2 are often mentioned in one breath, but they are not the same. The difference explained clearly, and how they actually reinforce each other.
NIS2 and director liability: why this is a boardroom topic
Under NIS2, directors are personally responsible for cybersecurity. What that means concretely and how the board can demonstrably take up its role.