NIS2 & Cybersecurity Act
Are you ready for the NIS2 rules?
The new European cyber rules are arriving in the Netherlands through the Cybersecurity Act. We explain in plain language what it means, and help you get ready.
What is the Cybersecurity Act?
NIS2 is a European directive meant to raise the digital resilience of organisations. The Netherlands turns that directive into national law: the Cybersecurity Act (Cbw).
The exact start date is not final yet; the law is expected during 2026. Waiting is unwise, because the measures take time to put in place.
The law affects far more organisations than before, including SMEs, and places responsibility squarely with the management board.
Does it apply to you?
The Cbw may apply to you if one or more of these points fit your situation:
- You operate in a sector covered by NIS2, such as digital services, IT management or their supply chain.
- You have 50 or more employees, or more than €10 million in turnover or balance sheet total.
- You supply services or software to an organisation that is itself covered by NIS2.
- You handle sensitive data of customers or clients.
Not sure, or just outside scope? Larger clients increasingly ask for demonstrable security anyway. Preparing pays off either way.
What do you have to do?
Risk management
Take appropriate technical and organisational measures to protect your systems and data.
Reporting duty
Report significant incidents to the supervisor within the set deadlines.
Board accountability
Management approves the measures and oversees them. Responsibility sits at the top.
Supply chain
The security of your suppliers and software also falls under your duty of care.
Take the NIS2 self-check
Seven questions, about a minute. You get an immediate indication of where you stand.
-
1. We know what sensitive data we hold and where it lives.
-
2. We use two-factor authentication (2FA) on email and key systems.
-
3. Our backups are regularly tested for recovery.
-
4. Our staff are trained to recognise phishing.
-
5. We have a plan for when an incident happens: who does what.
-
6. We assess our suppliers and software on security.
-
7. Management is involved in cybersecurity decisions.
Our free NIS2 scan
A level-headed baseline. In half an hour you know where you stand.
Take the free NIS2 scan- A short baseline of your current security
- Insight into whether and how NIS2/Cbw affects you
- The three most important areas to improve
- A clear next step, with no strings attached
About 30 minutes, on site or online. No obligations.
Frequently asked questions
When exactly does the Cbw take effect?
The exact date is not final yet; the law is expected during 2026. Waiting is unwise, because the measures take time to put in place.
We are small. Are we in scope?
Perhaps not directly. But if you supply a larger organisation, they increasingly ask for demonstrable security. Preparing pays off either way.
What happens if you do not comply?
NIS2 carries hefty fines for entities in scope. More importantly: an incident without preparation costs you clients and reputation.
Is this the same as GDPR?
No, but they overlap. GDPR is about personal data, NIS2 about the security and continuity of your systems. Often you tackle them together.
This information and the self-check are a tool and do not constitute legal advice or a formal assessment.
Shall we meet?
No sales pitch. Just a conversation about where you stand and what makes sense for your business.